1Platform operations
- 1.1Enhancing detection/response and tool integration
Understand prioritizing telemetry sources (Security Command Center [SCC], Google SecOps, Google Threat Intelligence [GTI], Cloud IDS), integrating multiple tools to enhance detection, justifying tools with overlapping capabilities, evaluating coverage gaps of existing tools, and evaluating automation/cloud tools to enhance detection/response processes.
- 1.2Configuring access and auditing
Understand user/service account authentication to security tools (SCC, Google SecOps), authorizing feature access and data access via IAM roles/permissions, configuring/analyzing audit logs (Cloud Audit Logs, data access logs), configuring API access for automation (service accounts, API keys, SCC/SecOps/GTI), and provisioning identities with Workforce Identity Federation.

