Google Cloud Professional Security Operations Engineer PSOE — Question 19
Topic 1 · Question 19 of 38
Topic 1 · Question 19
You are conducting a proactive threat hunt in Google Security Operations (SecOps). You observe multiple login events with the same principal.user.userid field that originate from different countries within a short time window. You need to validate whether the account has been compromised. What should you do?