Which optional field is required for a multi-event YARA-L rule?
Select one that applies, and then click Submit.
- Events
- Match
- Outcome
- Options
Home » Google Cloud SecOps Technical Credential Answers » Page 8
Google Cloud SecOps Technical Credential Answers
This assessment will test your knowledge of the SecOps (Chronical and Mandiant) products. You must achieve a score of 80% or higher to receive the technical credential.
All answers to pass this certification are only in our .PDF file, you can buy and download here:
Questions:
Select two that apply, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What three components make up the Chronicle Entity Context Graph (ECG)?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Data from Chronicle can be transparently copied out into what data warehouse for further analytics?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
The UDM is designed to contain models for what two types of data?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What is the primary job of the Indexing service?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What are the two primary functions of the Partner Application Programming Interfaces (APIs)?
Select one that applies, and then click Submit.
What are the required sections of a YARA-L rule?
Select one that applies, and then click Submit.
Which optional field is required for a multi-event YARA-L rule?
Select one that applies, and then click Submit.
In YARA-L, what is the equivalent of #var > 0?
Select one that applies, and then click Submit.
For what kind of field will the nocase operator cause an error?
Select one that applies, and then click Submit.
What are the special operators that can act on a repeated field value in YARA-L?
Select one that applies, and then click Submit.
What is the maximum time range for a match section of a multi-event rule in YARA-L?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What string function can be used to decode encoded command lines, especially in PowerShell?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What are the extract functions used in Google's Configuration-based Normalization?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Mandiant Threat Intelligence malware profiles include malware detections written in what language?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Mandiant Attack Surface Management (ASM) discovers technologies using what method?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
In Attack Surface Management, what is a seed?
Select one that applies, and then click Submit.
Select three that apply, and then click Submit.
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What collection scan settings can be supplied if custom input types are required?
Select one that applies, and then click Submit.
What are the main types of actors used in Mandiant Security Validation?
Select two that apply, and then click Submit.
What happens to an Actor in a protected Theater after the conclusion of each test?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Select three that apply, and then click Submit.
Select two that apply, and then click Submit.
How do you Sync integrations between your Director and Third party integrations?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
What is the scope of selecting the "All Environments" button when creating a playbook?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Who typically has sufficient rights to turn off the "simulator" mode?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Where can you check all the Active System Modules?
Select one that applies, and then click Submit.
How can a manual action within a playbook be identified?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
Where can you find the execution log of an Alert?
Select one that applies, and then click Submit.
Select one that applies, and then click Submit.
By vmartinez
Which optional field is required for a multi-event YARA-L rule?
Select one that applies, and then click Submit.
By vmartinez
What are the required sections of a YARA-L rule?
Select one that applies, and then click Submit.
By vmartinez
What are the two primary functions of the Partner Application Programming Interfaces (APIs)?
Select one that applies, and then click Submit.
By vmartinez
Which Chronicle Security Information and Event Management (SIEM) search method allows for a “grep” like functionality?
Select one that applies, and then click Submit.
By vmartinez
What is the primary job of the Indexing service?
Select one that applies, and then click Submit.
By vmartinez
Chronicle Security Information and Event Management (SIEM) applies the schema at what point to ensure maximum performance and increase the number of pivots that can be done on data?
Select one that applies, and then click Submit.