Question 1
A Managed Security Service Provider (MSSP) is designing a FortiSIEM deployment for a new client with strict data sovereignty requirements. The client's infrastructure is split between an on-premises data center in Canada and a public cloud environment in the UK. All logs generated in a specific region must be processed and stored within that same region. Which architectural design best meets these requirements while maintaining centralized management?
Answer and explanation
Correct answer: C
This is the correct architecture. Collectors can be deployed in each geographic region to receive, parse, and compress logs locally. This ensures that the initial processing happens within the region. While the event data is ultimately sent to the central Supervisor for correlation and storage, this model is the standard FortiSIEM design for handling geographically distributed log sources efficiently and is the first step towards meeting sovereignty, although full sovereignty would require local supervisors. The other options are architecturally flawed: direct agent forwarding is inefficient and doesn't meet the regional processing requirement, a Supervisor/Worker split doesn't ensure logs stay local during processing, and two separate Supervisor deployments create management overhead without a unified view.