
Answer-first summary for fast verification
Answer: Create an egress firewall policy with Threat Intelligence as the destination. Attach this policy to all Virtual Private Cloud networks with internet connectivity.
Option D is the correct answer because it directly addresses the requirement to alert on suspicious outbound traffic targeting known malicious domains using Google's Threat Intelligence capabilities. Security Command Center Premium integrates with firewall policies that can use Threat Intelligence lists to detect and block traffic to known malicious destinations, and it will automatically generate alerts when such traffic is detected. This approach leverages the existing SCC Premium investment and provides immediate protection without requiring additional log forwarding or analysis tools. Option B (Chronicle SIEM) is less optimal as it involves additional complexity and cost by forwarding logs to another system, when SCC Premium already has the capability to handle this use case. Option A (DNS logging) doesn't specifically address malicious domain detection, and Option C (Cloud IDS) is more focused on intrusion detection rather than specifically targeting known malicious domains for outbound traffic.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
Your organization uses Security Command Center Premium as a central tool for security threat detection and alerting. You need to configure alerts for suspicious outbound traffic directed towards known malicious domains. What should you do?
A
Create a DNS Server Policy in Cloud DNS and turn on logs. Attach this policy to all Virtual Private Cloud networks with internet connectivity.
B
Forward all logs to Chronicle Security Information and Event Management. Create an alert for suspicious egress traffic to the internet.
C
Create a Cloud Intrusion Detection endpoint. Connect this endpoint to all Virtual Private Cloud networks with internet connectivity.
D
Create an egress firewall policy with Threat Intelligence as the destination. Attach this policy to all Virtual Private Cloud networks with internet connectivity.
No comments yet.