Professional Cloud Security EngineerManaging operationsMedium
A security team needs to monitor for unusual API calls and potential insider threats within their Google Cloud organization. They want to identify any API calls made from unexpected geographical locations or by service accounts that typically do not perform administrative actions. The solution should provide high-fidelity alerts without requiring extensive manual rule creation. Which Google Cloud service should they leverage?
- AEvent Threat Detection (ETD) within Security Command Center.
- BCloud Monitoring with custom log-based metrics and alerting.
- CSecurity Health Analytics (SHA) with custom modules.
- DCloud Logging with advanced log filters and exports to BigQuery.
Show answer & explanationAnswer & explanation
Correct answer: A. Event Threat Detection (ETD) within Security Command Center.
Event Threat Detection (ETD) is specifically designed to identify suspicious activities, including unusual API calls from unexpected locations or by atypical service accounts, using Google's threat intelligence and machine learning, thus providing high-fidelity alerts without extensive manual rule creation.
Why the other options are wrong
- B. While Cloud Monitoring can alert, creating custom log-based metrics for complex 'unusual API calls' and 'unexpected geographical locations' would require extensive manual rule creation and maintenance, which the question aims to avoid.
- C. SHA focuses on misconfigurations and compliance posture, not on detecting real-time anomalous API calls or insider threats.
- D. Cloud Logging provides the raw logs and filtering, but it doesn't automatically detect 'unusual' patterns or 'unexpected' locations without significant custom development and intelligence, which ETD provides out-of-the-box.
Event Threat Detection (ETD) for Anomalies
A Security Command Center service that automatically detects suspicious and anomalous activities, like unusual API calls or access from unexpected locations, leveraging Google's threat intelligence and machine learning.
- Detects anomalous behavior in logs.
- Identifies insider threats and compromised accounts.
- Uses Google's threat intelligence and ML.
- Generates high-fidelity findings in Security Command Center.
Memory trick: ETD spots the unexpected API calls, like a security camera watching for strange movements.