Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-315.80 All Questions

View all questions & answers for the 156-315.80 exam

Exam 156-315.80 topic 1 question 139 discussion

Actual exam question from Checkpoint's 156-315.80
Question #: 139
Topic #: 1
[All 156-315.80 Questions]

The Correlation Unit performs all but the following actions:

  • A. Marks logs that individually are not events, but may be part of a larger pattern to be identified later.
  • B. Generates an event based on the Event policy.
  • C. Assigns a severity level to the event.
  • D. Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dkx0stv
Highly Voted 4 years, 5 months ago
C is correct. The question asks for "all BUT the following..." CCSE manual, page 438, reads as follows: When analyzing a log, the Correlation Unit performs one of the following actions: • Marks logs that individually are not events, but may be part of a larger pattern to be identified later • Generates an event based on the Event policy • Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event • Discards logs that do not meet event criteria
upvoted 12 times
...
LGP1983
Most Recent 12 months ago
THE SMART EVENT SERVER PERFORM ANOTHER ANALYSIS TO DETERMINE THE SEVERITY OF THE EVENT AND WHAT ACTION TO TAKE
upvoted 1 times
LGP1983
12 months ago
Correlation Unit Generates an event based on the Event policy, Then B is correct
upvoted 1 times
...
...
garlos94
1 year, 11 months ago
Selected Answer: B
* The SmartEvent Correlation Unit analyzes each log entry as it enters a Log Server, looking for patterns according to the installed Event Policy. The logs contain data from both Check Point products and certain third-party devices. When a threat pattern is identified, the SmartEvent Correlation Unit forwards what is known as an event to the SmartEvent Server. * When the SmartEvent Server receives events from a SmartEvent Correlation Unit, it assigns a severity level to the event, invokes any defined automatic reactions, and adds the event to the Events Database, which resides on the server. The severity level and automatic reaction are based on the Events Policy.
upvoted 1 times
...
lordlich
2 years, 9 months ago
C is correct
upvoted 1 times
...
Cedric2402
4 years, 7 months ago
According CCSE manual, page 438, the correct answer is B.
upvoted 2 times
kambata
3 years, 11 months ago
What you have quoted "CCSE guide page 438" proves that the answer is "C" not B ....
upvoted 3 times
...
Hernan_Mella
2 years, 3 months ago
NOT question
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...