Which Google SecOps capability reduces operator toil and MTTR?
- Telemetry Collection
- Analytics & Detection
- Alert Triage & Automated Response
- Applied Threat Intel & ML
Home » Google Cloud SecOps Technical Credential Assessment Answers » Page 6
Google Cloud SecOps Technical Credential Assessment Answers
This assessment will test your knowledge of the SecOps (Chronical and Mandiant) products. You must achieve a score of 80% or higher to receive the technical credential.
50 questions
Questions:
When data is ingested into Google SecOps, when is the raw data discarded?
Which of the following data sources can be configured as a Direct ingestion data source?
Chronicle SIEM had a Legacy RBAC system that was replaced with what GCP technology?
When using the SOAR interface in Google SecOps which view is applied to all cases automatically?
The rule language in Google SecOps was designed for what purpose?
What three components make up the Google SecOps Entity Context Graph (ECG).
Which Google SecOps capability reduces operator toil and MTTR?
What API must be enabled with a project to allow it to bind to Google SecOps?
What authentication methods are currently supported for a Google SecOps tenant?
How many regions can an MSSP tenant support?
How many Google SecOps tenants can be bound to a single GCP project?
There are two methods that can be used to manage Google SecOps parsers (CBNs), what are they?
The Google SecOps search interface provides two methods to search data. What are they?
What is the name of the API that enables users to create and manage rules?
By vmartinez
Which Google SecOps capability reduces operator toil and MTTR?
By vmartinez
What three components make up the Google SecOps Entity Context Graph (ECG).
By vmartinez
In the SecOps Technical Overview & Architecture what programming interface allows you to connect to the APIs without constructing your own tooling?
By vmartinez
The rule language in Google SecOps was designed for what purpose?
By vmartinez
Simulating a case in Google SecOps is a powerful way to develop and test various objects SOAR, most notably Playbooks. Which of the following actions CANNOT be taken by the analyst using a simulation?
By vmartinez
Google SecOps supports delivering connectors, actions and API connectivity to 3rd party products in a bundle. What is this bundle called?