Courseiva
Monitoring and Logging →mediumMultiple Select

156-215.81.20 Monitoring and Logging Practice Question

An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)

⚠ Common exam trap

The trap here is assuming that common fields like source and destination IP addresses are required for the export, when the specific requirement is for action and rule number.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

action

To meet the requirement of including the action taken and the rule number in exported syslog messages, the administrator must ensure that the 'action' and 'rule' fields are included. These fields provide the necessary information to identify what the gateway did and which policy rule was matched, enabling effective SIEM analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    action

    Why this is correct

    The 'action' field indicates what the Security Gateway did with the connection, such as Accept, Drop, or Reject. Including this field in the syslog export ensures that the SIEM can distinguish between allowed and blocked traffic, which is essential for security monitoring and compliance. Without it, the SIEM would not know the outcome of the connection.

  • ✗

    src

    Why it's wrong here

    The 'src' field represents the source IP address of the connection. While important for many analyses, it is not specifically required to show the action taken or the rule number. The requirement is to include the action and rule number, so 'src' is not one of the two fields that must be included to meet the stated goal.

  • ✗

    proto

    Why it's wrong here

    The 'proto' field indicates the protocol (e.g., TCP, UDP, ICMP). While useful for understanding the nature of the traffic, it does not convey the action taken or the rule number. The requirement is to include action and rule number, so 'proto' is not one of the two fields that must be included to satisfy the administrator's need.

  • ✗

    dst

    Why it's wrong here

    The 'dst' field is the destination IP address. Like 'src', it is a valuable field for traffic analysis, but it does not provide information about the action taken or the rule number. The administrator's goal is to include action and rule number, so 'dst' is not necessary for this specific requirement, though it may be included for other purposes.

  • ✓

    rule

    Why this is correct

    The 'rule' field contains the rule number that matched the connection in the Security Policy. This is critical for identifying which policy rule triggered the log entry, allowing administrators to correlate logs with specific rules and troubleshoot policy issues. It is often required for auditing and forensic analysis in a SIEM.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.