156-215.81.20 · domain
Monitoring and Logging
This domain covers how Check Point logs are generated, stored, forwarded, and analyzed across Security Gateways and Management Server. Questions test SmartConsole Logs & Monitor, SmartEvent, log rotation and retention settings, log server configuration, and basic troubleshooting when expected logs do not appear in the GUI despite being generated on the gateway.
Focused practice
Practice Monitoring and Logging questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Monitoring and Logging
Be able to locate log settings in SmartConsole, explain SmartEvent's role, and diagnose why gateway-generated logs are absent from Logs & Monitor. The key is knowing where logs are stored and forwarded, and how severity thresholds and rotation affect what you actually see.
Using Logs & Monitor in SmartConsole to view, filter, and track gateway and management logs
Configuring log rotation, retention, and storage limits for Security Management Server and gateways
SmartEvent blade functions: correlation, event generation, and threat/security event analysis
Troubleshooting missing logs using fw log, fw ctl, and log server connectivity checks
Watch out for
Common Monitoring and Logging exam traps
- ▸Assuming logs shown by fw log on the gateway must appear in SmartConsole; they may not reach the management or log server.
- ▸Confusing log rotation settings with retention or SmartEvent policy settings, and configuring the wrong object or location.
- ▸Setting Log Severity too high, which suppresses lower-severity events and creates gaps in audit or troubleshooting data.
Question index
All Monitoring and Logging questions (25)
Click any question to see the full explanation, or start a practice session above.
A security administrator needs to send only Security Gateway log records to an external SIEM over syslog, while keeping the Management Server's own audit logs local. Which Check Point configuration should be performed?
Medium2An administrator wants to ensure that logs are indexed properly for quick searching in SmartView. Which process is responsible for this indexing?
Medium3An administrator is troubleshooting an issue where logs from a Security Gateway are not appearing in SmartLog. The administrator verifies that the gateway is sending logs to the Management Server, but the logs are not indexed. Which service should the administrator check on the Management Server to ensure proper log indexing?
Hard4An administrator needs to review logs from a specific Security Gateway that occurred between 2:00 AM and 4:00 AM yesterday. Which SmartConsole application should the administrator use to efficiently filter and analyze these logs?
Easy5A security administrator needs to configure a Security Gateway to send its logs to a third-party SIEM via syslog. The SIEM is reachable only through an external interface, and the administrator wants to avoid sending logs over the internal network. Which Check Point feature should be used to achieve this requirement?
Medium6An administrator needs to review all logs generated by a specific Security Gateway over the past week. The administrator wants to see the logs in a tabular format and apply filters based on source IP. Which SmartConsole tool should the administrator use?
Easy7An administrator needs to verify that a Security Gateway is sending logs to the Management Server. The administrator wants to see a real-time count of log messages received by the management server from each gateway. Which SmartConsole tool provides this information?
Easy8Your organization requires that all log files be rotated when they reach a specific size limit to ensure efficient disk usage. Where should an administrator configure the automatic log rotation settings in SmartConsole?
Medium9An administrator notices that the Security Management Server's disk space is being consumed rapidly by log files. The administrator wants to automatically delete logs older than 90 days to free up space. Which Check Point feature should be configured to achieve this?
Medium10A security administrator is investigating a suspicious connection to an external IP. The administrator needs to see the raw packet-level details captured by the Security Gateway's IPS blade to determine the exact payload that triggered the protection. Which SmartConsole tool should the administrator use to view this information?
Medium11A security analyst is investigating a suspected intrusion and needs to view all logs related to a specific source IP address across multiple Security Gateways. The logs are stored on a central Management Server. Which SmartConsole feature should the analyst use to efficiently search and filter these logs?
Hard12Which tab in SmartConsole allows an administrator to view the status of the Security Management Server and its associated gateways, including CPU and memory usage?
Easy13A security administrator is troubleshooting a performance issue on a Check Point R81 Security Gateway. The administrator suspects that a specific process is generating an excessive number of logs, causing high CPU usage. Which SmartConsole tool should the administrator use to view real-time, per-process resource consumption on the gateway?
Medium14An administrator wants to receive immediate notification when a critical security event, such as a malware infection, is detected by a Security Gateway. Which Check Point feature should the administrator configure to send an alert?
Easy15If an administrator needs to identify the source of a connection drop in the logs, which field is most useful to inspect first?
Medium16Refer to the exhibit. What is the most likely reason this traffic was dropped?
Hard17An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)
Medium18What is the primary function of the 'SmartEvent' blade in the context of logging?
Easy19A Security Gateway stops sending logs to the Management Server, and users report that SmartView Logs shows no new entries. The administrator confirms the gateway is passing traffic. Which action should be taken first to diagnose the log transmission problem?
Medium20An administrator is troubleshooting why logs from a Security Gateway are not appearing in SmartLog, even though the gateway is configured to send logs to the Management Server and the connection is established. The administrator runs 'cp_log_export' on the Management Server and sees that logs are being exported to an external syslog server successfully. What is the most likely reason for the logs not appearing in SmartLog?
Hard21An administrator observes that logs are missing from the 'Logs & Monitor' tab, but the 'fw log' command shows logs are being generated on the gateway. What is the most likely cause?
Medium22During an investigation, an administrator must find all connections that were dropped by the Security Gateway in the last 24 hours for a specific source IP. Which SmartConsole tool provides the most efficient way to search and filter these logs?
Hard23An administrator notices that the Security Management Server disk is filling rapidly because log files are retained indefinitely. The retention policy must keep logs for 90 days and then remove older records automatically. Where should this be configured?
Easy24What is the consequence of setting the 'Log Severity' threshold too high on a Security Gateway?
Hard25An administrator wants to ensure that specific logs are always sent to a remote Log Server, even if the primary Log Server becomes unreachable. Which feature should they configure?
MediumOther domains
All 156-215.81.20 exam domains
Frequently asked questions
- What does the Monitoring and Logging domain cover on the 156-215.81.20 exam?
- Be able to locate log settings in SmartConsole, explain SmartEvent's role, and diagnose why gateway-generated logs are absent from Logs & Monitor. The key is knowing where logs are stored and forwarded, and how severity thresholds and rotation affect what you actually see.
- How many questions are in this domain?
- This page lists all 25 Monitoring and Logging questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Monitoring and Logging questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.