Question 1
A global financial institution is planning a Cortex XSOAR deployment to serve three distinct regional SOCs (AMER, EMEA, APAC), each with its own regulatory and data sovereignty requirements. The goal is to maintain centralized playbook management and threat intelligence sharing while ensuring that incident data from one region is not accessible by analysts in another. Which architectural design best meets these requirements?
Answer and explanation
Correct answer: C
The optimal solution is to use XSOAR's multi-tenancy feature. A main (master) tenant can be used for central content management (playbooks, integrations) and threat intelligence, which can then be propagated to the child tenants. Each regional SOC operates within its own child tenant, ensuring strict data isolation and meeting sovereignty requirements. RBAC alone on a single instance does not provide true data segregation. Fully separate instances create significant management overhead for content synchronization.