Question 245 of 318
Single answerDuring a routine security review, your team discovered a suspicious login attempt to impersonate a highly privileged but regularly used service account by an unknown IP address. You need to effectively investigate in order to respond to this potential security incident. What should you do?
AEnable Cloud Audit Logs for the resources that the service account interacts with. Review the logs for further evidence of unauthorized activity.
BReview Cloud Audit Logs for activity related to the service account. Focus on the time period of the suspicious login attempt.
CRun a vulnerability scan to identify potentially exploitable weaknesses in systems that use the service account.
✓DCheck Event Threat Detection in Security Command Center for any related alerts. Cross-reference your findings with Cloud Audit Logs.
✓
Correct Answer: D
Check Event Threat Detection in Security Command Center for any related alerts. Cross-reference your findings with Cloud Audit Logs.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.