156-215.81.20 Monitoring and Logging Practice Question
A security administrator needs to send only Security Gateway log records to an external SIEM over syslog, while keeping the Management Server's own audit logs local. Which Check Point configuration should be performed?
⚠ Common exam trap
The trap here is assuming Log Forwarding is configured on the Management Server object rather than on the individual Security Gateway object that produces the logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Log Forwarding on the Security Gateway object with the external syslog server as the target and select the Security log type.
Log Forwarding is the supported Check Point feature for exporting logs from a Security Gateway to an external destination such as a syslog server. Because it is configured on the gateway object and lets you select log types, it can send security logs to the SIEM while leaving management-side audit logs in place. Other mechanisms either loop logs back internally or target the wrong log category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Log Forwarding in the Security Gateway object and set the Management Server as the target.
Why it's wrong here
Setting the Management Server as the target simply loops logs back into the same management domain, which does not deliver anything to the external SIEM and can create duplicate records. Log Forwarding requires an external destination, so pointing it at the Management Server fails to meet the requirement of shipping gateway logs off-box.
- ✓
Configure Log Forwarding on the Security Gateway object with the external syslog server as the target and select the Security log type.
Why this is correct
Log Forwarding is configured per Security Gateway and lets you choose which log types are exported. Pointing it at the external syslog server and selecting the Security log type exports gateway security logs while leaving management audit logs untouched, exactly matching the stated requirement.
- ✗
Run cp_log_export on the Management Server with the --audit flag and a remote destination.
Why it's wrong here
cp_log_export is not the supported mechanism for forwarding Security Gateway logs to an external syslog server; that role belongs to Log Forwarding. Using the audit flag would target management audit records, the opposite of what is needed, and the tool would not isolate gateway security logs as required.
- ✗
Modify the fwd.elg file on the Security Gateway to redirect log output to the SIEM.
Why it's wrong here
fwd.elg is a debug log for the forwarding daemon, not a configuration file for routing logs. Editing it does not create a supported export path and could disrupt the forwarding daemon's stability. The correct approach uses the Log Forwarding settings in the gateway object, not internal debug files.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.