Skip to content
GCP-PSOE
Detection engineering
medium
Question 7 of 42

A team wants a low-prevalence hunting rule to act as a secondary indicator during investigations instead of immediately creating alerts. What should the rule produce?

AA detection event rather than a detection alert
BA SOAR case with critical priority
CA parser extension warning
DA Cloud Monitoring metric only

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion