Your organization's Google Security Operations (SecOps) tenant is ingesting a vendor's firewall logs in
its default JSON format using the Google-provided parser for that log. The vendor recently released a
patch that introduces a new field and renames an existing field in the logs. The parser does not
recognize these two fields and they remain available only in the raw logs, while the rest of the log is
parsed normally. You need to resolve this logging issue as soon as possible while minimizing the
overall change management impact. What should you do?
Your Google Security Operations (SecOps) case queue contains a case with IP address entities. You
need to determine whether the entities are internal or external assets and ensure that internal IP
address entities are marked accordingly upon ingestion into Google SecOps SOAR. What should you
do?
Your Google Security Operations (SecOps) case queue contains a case with IP address entities. You
need to determine whether the entities are internal or external assets and ensure that internal IP
address entities are marked accordingly upon ingestion into Google SecOps SOAR. What should you
do?
You are part of a cybersecurity team at a large multinational corporation that uses Google Security
Operations (SecOps). You have been tasked with identifying unknown command and control nodes
(C2s) that are potentially active in your organization's environment. You need to generate a list of
potential matches for the unknown C2s within the next 24 hours. What should you do?
You are managing the integration of Security Command Center (SCC) with downstream tooling. You need topull security findings from SCC and import those findings as part of Google Security Operations (SecOps)SOAR actions. You need to configure the connection between SCC and Google SecOps.