C is correct. The question asks for "all BUT the following..."
CCSE manual, page 438, reads as follows:
When analyzing a log, the Correlation Unit performs one of the following actions:
• Marks logs that individually are not events, but may be part of a larger pattern to be identified later
• Generates an event based on the Event policy
• Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event
• Discards logs that do not meet event criteria
* The SmartEvent Correlation Unit analyzes each log entry as it enters a Log Server, looking for patterns according to the installed Event Policy. The logs contain data from both Check Point products and certain third-party devices. When a threat pattern is identified, the SmartEvent Correlation Unit forwards what is known as an event to the SmartEvent Server.
* When the SmartEvent Server receives events from a SmartEvent Correlation Unit, it assigns a severity level to the event, invokes any defined automatic reactions, and adds the event to the Events Database, which resides on the server. The severity level and automatic reaction are based on the Events Policy.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dkx0stv
Highly Voted 4 years, 5 months agoLGP1983
Most Recent 12 months agoLGP1983
12 months agogarlos94
1 year, 11 months agolordlich
2 years, 9 months agoCedric2402
4 years, 7 months agokambata
3 years, 11 months agoHernan_Mella
2 years, 3 months ago