🔍

Google Cloud Professional Security Operations Engineer PSOE — Question 19

Topic 1 · Question 19 of 38

Topic 1 · Question 19

You are conducting a proactive threat hunt in Google Security Operations (SecOps). You observe multiple login events with the same principal.user.userid field that originate from different countries within a short time window. You need to validate whether the account has been compromised. What should you do?