Question 1
A financial institution is implementing a multi-tenant QRadar deployment to serve three distinct business units: Retail Banking, Investment Banking, and Wealth Management. Compliance mandates strict data segregation between these units. The administrator has created a separate Domain for each unit. During testing, it's discovered that a shared, central authentication log source is visible to users in all three domains. What is the most appropriate action to ensure the shared log source's data is correctly segregated and assigned to the relevant domain based on event payloads?
Answer and explanation
Correct answer: D
When a log source contains data relevant to multiple domains, it should not be assigned to a single domain. Instead, the log source should be left unassigned. Then, a custom event property can be created to parse a unique identifier from the event payload (e.g., a business unit ID). This custom property is then configured to tag events to the correct domain, ensuring proper data segregation at the event level.