New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam Security-Operations-Engineer Question # 18 Topic 2 Discussion

Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam Security-Operations-Engineer Question # 18 Topic 2 Discussion

Security-Operations-Engineer Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

You are responsible for identifying suspicious activity and security events in your organization's environment. You discover that some detection rules are generating false positives when the principal.ip field contains one or more IP addresses in the 192.168.2.0/24 subnet. You want to improve these detection rules using the principal.ip repeated field. What should you add to the YARA-L detection rules?


A.

net.ip_in_range_cidr(all $e.principal.ip, "192.168.2.0/24")


B.

net.ip_in_range_cidr(any $e.principal.ip, "192.168.2.0/24")


C.

not net.ip_in_range_cidr(all $e.principal.ip, "192.168.2.0/24")


D.

not net.ip_in_range_cidr(any $e.principal.ip, "192.168.2.0/24")


Get Premium Security-Operations-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.