Professional Cloud Security EngineerManaging operationsEasy
A security engineer is responsible for monitoring a critical production environment on Google Cloud. They need to ensure that any unusual access patterns, such as a user logging in from an unfamiliar country or an unusual number of failed login attempts, are immediately detected. Which Google Cloud service should be configured to provide real-time alerts for these types of suspicious activities?
- ASecurity Health Analytics (SHA)
- BCloud Audit Logs with BigQuery export
- CCloud Monitoring with custom metrics
- DEvent Threat Detection (ETD)
Show answer & explanationAnswer & explanation
Correct answer: D. Event Threat Detection (ETD)
Event Threat Detection (ETD) is specifically designed to identify high-severity threats in Cloud Logging data, including unusual access patterns and brute-force attempts, and generate findings in Security Command Center for real-time alerting.
Why the other options are wrong
- A. Security Health Analytics focuses on security misconfigurations and vulnerabilities, not real-time threat detection from log patterns.
- B. While Cloud Audit Logs provide the data, and BigQuery can store it, ETD is the service that performs the real-time threat analysis and alerting.
- C. Cloud Monitoring can alert on metrics, but ETD is purpose-built for threat detection from log data.
Event Threat Detection (ETD)
A Google Cloud service that automatically detects high-severity threats in Cloud Logging data, such as unusual access patterns, brute-force attempts, and cryptomining, and generates findings in Security Command Center.
- Analyzes Cloud Logging data for threat indicators.
- Generates findings in Security Command Center.
- Helps detect various types of security threats in real-time.
Memory trick: ETD is like a vigilant guard, always watching logs for danger.