🔍

Google Cloud Professional Security Operations Engineer PSOE — Question 29

Topic 1 · Question 29 of 38

Topic 1 · Question 29

You are planning log onboarding for a Google Security Operations (SecOps) SIEM deployment in a cloud-heavy enterprise environment. The detection engineering team is requesting log sources that support visibility into: User identity behavior - Lateral movement - Privilege escalation attempts - You need to determine which telemetry sources are ingested first. Which log source should you prioritize?