🔍

Google Cloud Professional Security Operations Engineer PSOE — Question 22

Topic 1 · Question 22 of 38

Topic 1 · Question 22

You use Google Security Operations (SecOps) curated detections and YARA-L rules to detect suspicious activity on Windows endpoints. Your source telemetry uses EDR and Windows Events logs. Your rules match on the principal.user.userid UDM field. You need to ingest an additional log source for this field to match all possible log entries from your EDR and Windows Event logs. What should you do?