exam questions

Exam 156-315.81.20 All Questions

View all questions & answers for the 156-315.81.20 exam

Exam 156-315.81.20 topic 1 question 39 discussion

Actual exam question from Checkpoint's 156-315.81.20
Question #: 39
Topic #: 1
[All 156-315.81.20 Questions]

The Log server sends what to the Correlation Unit?

  • A. Authentication requests
  • B. Event Policy
  • C. Logs
  • D. CPMI dbsync
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
57ad24d
2 weeks, 4 days ago
Selected Answer: C
The correct answer is: C. Logs Explanation: The Log Server sends logs to the Correlation Unit for analysis. The Correlation Unit processes these logs to identify potential threats, generate events, and apply the event correlation policies defined in the system. This is a critical component of Check Point's SmartEvent architecture, which is used for real-time threat detection and security event management. Other Options: A. Authentication requests: Not applicable, as authentication is handled by other components like the Security Gateway or RADIUS server. B. Event Policy: The Event Policy is configured in the SmartEvent GUI and applied to the Correlation Unit, not sent by the Log Server. D. CPMI dbsync: Refers to synchronization of management data between Check Point components and is unrelated to log processing by the Correlation Unit.
upvoted 1 times
...
mfhashmi
3 months, 3 weeks ago
Selected Answer: C
C. Logs Explanation: The Log Server sends logs to the Correlation Unit. The Correlation Unit analyzes logs in real-time, correlating them to detect security events and incidents, which are then passed to Check Point's SmartEvent for further analysis and response.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago