Professional Cloud Security EngineerManaging operationsEasy

A security engineer is responsible for monitoring a critical production environment on Google Cloud. They need to ensure that any unusual access patterns, such as a user logging in from an unfamiliar country or an unusual number of failed login attempts, are immediately detected. Which Google Cloud service should be configured to provide real-time alerts for these types of suspicious activities?

  1. ASecurity Health Analytics (SHA)
  2. BCloud Audit Logs with BigQuery export
  3. CCloud Monitoring with custom metrics
  4. DEvent Threat Detection (ETD)
Show answer & explanation

Correct answer: D. Event Threat Detection (ETD)

Event Threat Detection (ETD) is specifically designed to identify high-severity threats in Cloud Logging data, including unusual access patterns and brute-force attempts, and generate findings in Security Command Center for real-time alerting.

Why the other options are wrong

  • A. Security Health Analytics focuses on security misconfigurations and vulnerabilities, not real-time threat detection from log patterns.
  • B. While Cloud Audit Logs provide the data, and BigQuery can store it, ETD is the service that performs the real-time threat analysis and alerting.
  • C. Cloud Monitoring can alert on metrics, but ETD is purpose-built for threat detection from log data.

Event Threat Detection (ETD)

A Google Cloud service that automatically detects high-severity threats in Cloud Logging data, such as unusual access patterns, brute-force attempts, and cryptomining, and generates findings in Security Command Center.

  • Analyzes Cloud Logging data for threat indicators.
  • Generates findings in Security Command Center.
  • Helps detect various types of security threats in real-time.

Memory trick: ETD is like a vigilant guard, always watching logs for danger.

More Managing operations questions