5Incident response
- 5.1Containing and investigating security incidents
Understand collecting evidence on incident scope (forensic images/artifacts), observing/analyzing alerts (SCC, Google SecOps), analyzing scope with tools (Logs Explorer, Log Analytics, BigQuery, Cloud Logging, Cloud Monitoring), collaborating with teams, isolating affected services/processes, forensic analysis (Hash, IP, URL, binaries via GTI), and root cause analysis (SCC, Google SecOps SIEM).
- 5.2Response playbooks and case management
Understand determining response steps for automation, prioritizing high-value enrichments by threat profile, evaluating integrations for playbooks, designing new processes for new attack patterns, recommending new orchestrations/automation playbooks based on gaps (Google SecOps SOAR), notifying analysts/stakeholders, and the case management lifecycle (assigning response stages, escalation workflows, assessing handoff effectiveness).

