Question 1
A financial services company is planning a multi-site QRadar V7.5 deployment. The primary data center will host the Console, an Event Processor, and a Flow Processor. A secondary disaster recovery (DR) site is required with a 4-hour Recovery Time Objective (RTO). The company wants to ensure that event and flow data collection is not interrupted at remote branch offices if the primary data center's WAN link fails. Each of the 10 branch offices generates approximately 1,500 EPS and 25,000 FPM.
Which architectural component should be placed at each branch office to meet these requirements for resilient data collection?
Answer and explanation
Correct answer: B
The Event Collector 1501 is the correct choice. It is designed to be placed at remote locations to collect logs and flows. Crucially, it has a 'store and forward' capability that allows it to cache data locally when the connection to the central Event Processor is lost. This ensures no data is lost during a WAN outage, directly meeting the requirement for resilient data collection. Data Nodes are for storage, QFlow Collectors are specific to flows from network taps, and a full Event Processor would be overkill and not the standard design pattern for this scenario.