350-701 · Question #325
350-701 Question #325: Real Exam Question with Answer & Explanation
The correct answer is A: It can grant third-party SIEM integrations write access to the S3 bucket.. Advantages and Disadvantages to Configuring a Cisco-Managed Bucket: Some SIEM integration types (such as QRadar) may require advanced privileges for the user accessing the S3 bucket (beyond the basic Read permissions) and as such, may not work with https://docs.umbrella.com/deplo
Question
An engineer is configuring cloud logging using a company-managed Amazon S3 bucket for Cisco Umbrella logs. What benefit does this configuration provide for accessing log data?
Options
- AIt can grant third-party SIEM integrations write access to the S3 bucket.
- BData can be stored offline for 30 days.
- CNo other applications except Cisco Umbrella can write to the S3 bucket.
- DIt is included in the license cost for the multi-org console of Cisco Umbrella.
Explanation
Advantages and Disadvantages to Configuring a Cisco-Managed Bucket: Some SIEM integration types (such as QRadar) may require advanced privileges for the user accessing the S3 bucket (beyond the basic Read permissions) and as such, may not work with https://docs.umbrella.com/deployment-umbrella/docs/log-management#advantages For example, Splunk can have S3 full access if a self-managed S3 bucket is used: https://support.umbrella.com/hc/en-us/articles/230650987-Configuring-Splunk-with-a-Self- managed-S3-Bucket
Topics
Community Discussion
No community discussion yet for this question.