You are managing the integration of Security Command Center (SCC) with downstream tooling. You need topull security findings from SCC and import those findings as part of Google Security Operations (SecOps)SOAR actions. You need to configure the connection between SCC and Google SecOps.
You are responsible for monitoring the ingestion of critical Windows server logs to Google Security
Operations (SecOps) by using the Bindplane agent. You want to receive an immediate notification
when no logs have been ingested for over 30 minutes. You want to use the most efficient notification
solution. What should you do?
Your organization has recently acquired Company A, which has its own SOC and security tooling. You
have already configured ingestion of Company As security telemetry and migrated their detection
rules to Google Security Operations (SecOps). You now need to enable Company A's analysts to work
their cases in Google SecOps. You need to ensure that Company A's analysts:
do not have access to any case data originating from outside of Company A.
are able to re-purpose playbooks previously developed by your organization's employees.
You need to minimize effort to implement your solution. What is the first step you should take?
You are a security operations engineer in an enterprise that uses Google Security Operations (SecOps). Youneed to improve your detection coverage and reduce the false positive detection ratio as quickly as possible.What should you do?
You are part of a cybersecurity team at a large multinational corporation that uses Google Security
Operations (SecOps). You have been tasked with identifying unknown command and control nodes
(C2s) that are potentially active in your organization's environment. You need to generate a list of
potential matches for the unknown C2s within the next 24 hours. What should you do?