Valid XSIAM-Engineer Dumps shared by EduDump.com for Helping Passing XSIAM-Engineer Exam! EduDump.com now offer the newest XSIAM-Engineer exam dumps, the EduDump.com XSIAM-Engineer exam questions have been updated and answers have been corrected get the newest EduDump.com XSIAM-Engineer dumps with Test Engine here:
An organization requires the Broker VM to collect network flow data (NetFlow v9) from multiple Cisco routers. Due to network segmentation, the routers are in a different subnet than the Broker VM, and a firewall sits between them. The security policy mandates that only necessary ports are open. Additionally, the NetFlow data must be sent to the Broker VM for ingestion into Cortex XSIAM. Which specific firewall rules and Broker VM configurations are necessary to achieve this, assuming the Broker VM is deployed with its default network interface and the routers are configured to send NetFlow to the Broker VM's IP?
Correct Answer: B
NetFlow typically uses UDP, with 2055 being a common port for v9. Therefore, the firewall must permit UDP 2055 from the routers (source) to the Broker VM (destination). On the Broker VM, the Universal Data Collector is the component responsible for ingesting various data types, including NetFlow. It needs to be configured to specifically listen on UDP 2055 for NetFlow. Option A is incorrect as NetFlow typically uses UDP, not TCP. Option C is incorrect as the Broker VM is the collector, not an exporter. Option D is incorrect as 'Any-to-Any' is bad security practice, and specific configuration is needed. Option E uses a less common port and requires specific configuration beyond just enabling a custom listener, although the principle is similar to B if 9995 were the chosen port.