What's changed: Created Professional Security Operations Engineer Chapter 5 (Domain 5 "Incident response": evidence collection/forensic images-artifacts/alert observation (SCC-SecOps)/scope analysis (Logs Explorer-Log Analytics-BigQuery-Cloud Logging-Cloud Monitoring)/isolating affected services/forensic analysis (Hash-IP-URL-binaries via GTI)/root cause analysis (SecOps SIEM); SOAR playbooks/response steps for automation/high-value enrichment priority/integrations/new process design/new playbook recommendations/notifications/case management lifecycle (response stages-escalation-handoffs)).
5.1Containing and investigating security incidents
Understand collecting evidence on incident scope (forensic images/artifacts), observing/analyzing alerts (SCC, Google SecOps), analyzing scope with tools (Logs Explorer, Log Analytics, BigQuery, Cloud Logging, Cloud Monitoring), collaborating with teams, isolating affected services/processes, forensic analysis (Hash, IP, URL, binaries via GTI), and root cause analysis (SCC, Google SecOps SIEM).
Incident response aims to "minimize damage and find the cause." Prioritize containment, and investigate while preserving evidence.
5.1.1Containment and evidence collection
On detecting an incident, first stop the spread: isolate affected services/processes (separate, disable, cut network) to prevent attack propagation. In parallel, collect evidence: preserve forensic images of memory/disk and artifacts (logs, processes, connections) without tampering (for later analysis and legal needs). Observe/analyze alerts in SCC and Google SecOps, and analyze scope (how far the compromise reached) with Logs Explorer/Log Analytics/BigQuery/Cloud Logging/Cloud Monitoring. Map "stop the spread = isolate affected services" and "preserve for later analysis = forensic images/artifacts."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

