156-215.81.20 Monitoring and Logging Practice Question
An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)
⚠ Common exam trap
The trap here is assuming that common fields like source and destination IP addresses are required for the export, when the specific requirement is for action and rule number.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
action
To meet the requirement of including the action taken and the rule number in exported syslog messages, the administrator must ensure that the 'action' and 'rule' fields are included. These fields provide the necessary information to identify what the gateway did and which policy rule was matched, enabling effective SIEM analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
action
Why this is correct
The 'action' field indicates what the Security Gateway did with the connection, such as Accept, Drop, or Reject. Including this field in the syslog export ensures that the SIEM can distinguish between allowed and blocked traffic, which is essential for security monitoring and compliance. Without it, the SIEM would not know the outcome of the connection.
- ✗
src
Why it's wrong here
The 'src' field represents the source IP address of the connection. While important for many analyses, it is not specifically required to show the action taken or the rule number. The requirement is to include the action and rule number, so 'src' is not one of the two fields that must be included to meet the stated goal.
- ✗
proto
Why it's wrong here
The 'proto' field indicates the protocol (e.g., TCP, UDP, ICMP). While useful for understanding the nature of the traffic, it does not convey the action taken or the rule number. The requirement is to include action and rule number, so 'proto' is not one of the two fields that must be included to satisfy the administrator's need.
- ✗
dst
Why it's wrong here
The 'dst' field is the destination IP address. Like 'src', it is a valuable field for traffic analysis, but it does not provide information about the action taken or the rule number. The administrator's goal is to include action and rule number, so 'dst' is not necessary for this specific requirement, though it may be included for other purposes.
- ✓
rule
Why this is correct
The 'rule' field contains the rule number that matched the connection in the Security Policy. This is critical for identifying which policy rule triggered the log entry, allowing administrators to correlate logs with specific rules and troubleshoot policy issues. It is often required for auditing and forensic analysis in a SIEM.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.