You are receiving security alerts from multiple connectors in your Google Security Operations (SecOps) instance. You need to identify which IP address entities are internal to your network and label each entity with its specific network name. This network name will be used as the trigger for the playbook. What should you do?
- AConfigure each network in the Google SecOps SOAR settings. (correct answer)
- BEnrich the IP address entities as the initial step of the playbook.
- CModify the entity attribute in the alert overview.
- DCreate an outcome variable in the rule to assign the network name.
Reveal answer & explanationHide answer
The correct answer is A. Option A: Configure each network in the Google SecOps SOAR settings.
Explanation
Google Security Operations provides cloud-scale SIEM, threat detection, investigation, and SOAR capabilities for security teams. This option keeps traffic private / properly secured as required. The other options (B, C, D) are less suitable because they add operational overhead, cost, or complexity, or they do not fully satisfy the stated requirement.