SecOps on Google Distributed Cloud (GDC) for Tier 3 Analysts by Google
3h 36mIntermediate2025-12-16
Authors

Google Cloud
Course details
Explore the workflows and methodologies that support Tier 3 analysts on Google Distributed Cloud, including advanced incident response and ad hoc strategies. The course covers vulnerability management, scanning techniques, penetration testing, and threat modeling frameworks. It also examines security engineering through a “secure by design” lens and provides practical guidance on managing Splunk, from configuration to troubleshooting. Designed for analysts deepening their cloud security expertise, this course helps to strengthen strategic decision‑making and overall effectiveness in maintaining secure systems.
Concepts
Course Overview
- Course 3 overview
Vulnerability Management for Tier 3 Analysts
- Module overview
- Advanced incident response for Tier 3 analysts
- Ad hoc incident response
- Using an incident management plan for ad hoc incident response
- Tools for advanced incident response
- Endpoint detection and response (EDR) tools
- Security information and event management (SIEM) tools
- Vulnerability scanners
- Threat intelligence tools
- Intrusion detection and prevention systems (IDPS) tools
- Digital forensic tools
- Advanced incident response tools at Cymbal Federal
- Metrics for evaluating incident response
Vulnerability Management for Tier 3 Analysts
- Module overview
- Introduction to vulnerability management
- Vulnerability management systems (VMS)
- The vulnerability management lifecycle
- Vulnerability management on GDC
- Techniques for vulnerability management
- Vulnerability assessment
- Vulnerability scanning
- Penetration testing
- Tools for penetration testing
- Best practices for a vulnerability management program
- Vulnerability management reports
- Module summary
Threat Modeling
- Module overview
- The modern threat landscape
- Introduction to threat modeling
- The threat modeling process
- Threat modeling frameworks
- Threat modeling frameworks at Cymbal Federal
- Threat intelligence feeds
- Introduction to modeling techniques
- Spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege (STRIDE)
- STRIDE at Cymbal Federal.mp4
- Process for attack simulation and threat analysis (PASTA)
- PASTA at Cymbal Federal
- Common Vulnerability Scoring System (CVSS)
- CVSS at Cymbal Federal
- Selecting a threat modeling technique
- SecOps-specific tools for threat modeling
- SecOps-specific tools at Cymbal Federal
- Threat mapping
- Best practices for effective threat
- Module summary
Security Engineering
- Module overview
- Introduction to security engineering
- The secure by design approach
- Secure by design and SecOps
- Security engineers in the SOC
- The security engineering workflow
- Introduction to security controls
- Technical security controls
- Administrative security controls
- Tools for security engineers
- Security engineering best practices
- Module review
Splunk Advanced - Lite Management
- Module overview
- Introduction to Splunk management
- Who is responsible for managing Splunk
- Configuration files in Splunk
- Administering Splunk with Splunk Web and btool
- Best practices and advanced troubleshooting in Splunk
- Splunk management at Cymbal Federal
- Module review