The security operations center requires every management event from the new appliance to appear in their collector. When should that event forwarding be established, and what completes the task?
Select an answer to reveal the explanation.
Short Explanation
Your SOC doesn't want those management events to be fussy — they can't catch what they never received. Wiring event forwarding in at deployment puts the tape down before the incident, not after the paperwork. Don't forget the second half either: prove the events actually arrive, because a forwarding rule nobody verified is just a hope saved to disk.
Full Explanation
Forwarding system events to a central collector is basic management-network configuration in the same family as the gateway and the name servers: it depends on reachability, transport and severity settings, and the receiver's acceptance policy, and it should exist before the appliance carries production data. The SOC's detection coverage, retention evidence, and incident timelines all assume the estate spoke from day one; anything bolted on later leaves a gap nobody can fill retroactively, because unpreserved events are permanently gone. Deferring to the first audit finding fails twice — the coverage hole persists through every incident in the interval, and building and testing a new network path under audit pressure is the worst possible moment for it. Scripted browser pulls of the GUI invert the architecture: they are brittle, miss machine-readable detail, and hand the SOC yet another stored credential for a web interface not designed as an API. Treating forwarding as a cloud feature fails by mechanism — event export is a local service pushing to a target the customer controls, typically entirely inside their own network with no internet dependency at all. Exam caveat: verify the forwarded severity level matches what the SOC subscribed to, or the feed arrives technically alive and practically useless. Operational check: generate a known management event, locate it in the collector bearing the correct device name, and record the target and protocol in the deployment record.