Courseiva

156-215.81.20 · domain

Monitoring and Logging

This domain covers how Check Point logs are generated, stored, forwarded, and analyzed across Security Gateways and Management Server. Questions test SmartConsole Logs & Monitor, SmartEvent, log rotation and retention settings, log server configuration, and basic troubleshooting when expected logs do not appear in the GUI despite being generated on the gateway.

25 questions7 easy12 medium6 hard

Focused practice

Practice Monitoring and Logging questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Monitoring and Logging

Be able to locate log settings in SmartConsole, explain SmartEvent's role, and diagnose why gateway-generated logs are absent from Logs & Monitor. The key is knowing where logs are stored and forwarded, and how severity thresholds and rotation affect what you actually see.

Using Logs & Monitor in SmartConsole to view, filter, and track gateway and management logs

Configuring log rotation, retention, and storage limits for Security Management Server and gateways

SmartEvent blade functions: correlation, event generation, and threat/security event analysis

Troubleshooting missing logs using fw log, fw ctl, and log server connectivity checks

Watch out for

Common Monitoring and Logging exam traps

  • ▸Assuming logs shown by fw log on the gateway must appear in SmartConsole; they may not reach the management or log server.
  • ▸Confusing log rotation settings with retention or SmartEvent policy settings, and configuring the wrong object or location.
  • ▸Setting Log Severity too high, which suppresses lower-severity events and creates gaps in audit or troubleshooting data.

Question index

All Monitoring and Logging questions (25)

Click any question to see the full explanation, or start a practice session above.

1

A security administrator needs to send only Security Gateway log records to an external SIEM over syslog, while keeping the Management Server's own audit logs local. Which Check Point configuration should be performed?

Medium
2

An administrator wants to ensure that logs are indexed properly for quick searching in SmartView. Which process is responsible for this indexing?

Medium
3

An administrator is troubleshooting an issue where logs from a Security Gateway are not appearing in SmartLog. The administrator verifies that the gateway is sending logs to the Management Server, but the logs are not indexed. Which service should the administrator check on the Management Server to ensure proper log indexing?

Hard
4

An administrator needs to review logs from a specific Security Gateway that occurred between 2:00 AM and 4:00 AM yesterday. Which SmartConsole application should the administrator use to efficiently filter and analyze these logs?

Easy
5

A security administrator needs to configure a Security Gateway to send its logs to a third-party SIEM via syslog. The SIEM is reachable only through an external interface, and the administrator wants to avoid sending logs over the internal network. Which Check Point feature should be used to achieve this requirement?

Medium
6

An administrator needs to review all logs generated by a specific Security Gateway over the past week. The administrator wants to see the logs in a tabular format and apply filters based on source IP. Which SmartConsole tool should the administrator use?

Easy
7

An administrator needs to verify that a Security Gateway is sending logs to the Management Server. The administrator wants to see a real-time count of log messages received by the management server from each gateway. Which SmartConsole tool provides this information?

Easy
8

Your organization requires that all log files be rotated when they reach a specific size limit to ensure efficient disk usage. Where should an administrator configure the automatic log rotation settings in SmartConsole?

Medium
9

An administrator notices that the Security Management Server's disk space is being consumed rapidly by log files. The administrator wants to automatically delete logs older than 90 days to free up space. Which Check Point feature should be configured to achieve this?

Medium
10

A security administrator is investigating a suspicious connection to an external IP. The administrator needs to see the raw packet-level details captured by the Security Gateway's IPS blade to determine the exact payload that triggered the protection. Which SmartConsole tool should the administrator use to view this information?

Medium
11

A security analyst is investigating a suspected intrusion and needs to view all logs related to a specific source IP address across multiple Security Gateways. The logs are stored on a central Management Server. Which SmartConsole feature should the analyst use to efficiently search and filter these logs?

Hard
12

Which tab in SmartConsole allows an administrator to view the status of the Security Management Server and its associated gateways, including CPU and memory usage?

Easy
13

A security administrator is troubleshooting a performance issue on a Check Point R81 Security Gateway. The administrator suspects that a specific process is generating an excessive number of logs, causing high CPU usage. Which SmartConsole tool should the administrator use to view real-time, per-process resource consumption on the gateway?

Medium
14

An administrator wants to receive immediate notification when a critical security event, such as a malware infection, is detected by a Security Gateway. Which Check Point feature should the administrator configure to send an alert?

Easy
15

If an administrator needs to identify the source of a connection drop in the logs, which field is most useful to inspect first?

Medium
16

Refer to the exhibit. What is the most likely reason this traffic was dropped?

Hard
17

An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)

Medium
18

What is the primary function of the 'SmartEvent' blade in the context of logging?

Easy
19

A Security Gateway stops sending logs to the Management Server, and users report that SmartView Logs shows no new entries. The administrator confirms the gateway is passing traffic. Which action should be taken first to diagnose the log transmission problem?

Medium
20

An administrator is troubleshooting why logs from a Security Gateway are not appearing in SmartLog, even though the gateway is configured to send logs to the Management Server and the connection is established. The administrator runs 'cp_log_export' on the Management Server and sees that logs are being exported to an external syslog server successfully. What is the most likely reason for the logs not appearing in SmartLog?

Hard
21

An administrator observes that logs are missing from the 'Logs & Monitor' tab, but the 'fw log' command shows logs are being generated on the gateway. What is the most likely cause?

Medium
22

During an investigation, an administrator must find all connections that were dropped by the Security Gateway in the last 24 hours for a specific source IP. Which SmartConsole tool provides the most efficient way to search and filter these logs?

Hard
23

An administrator notices that the Security Management Server disk is filling rapidly because log files are retained indefinitely. The retention policy must keep logs for 90 days and then remove older records automatically. Where should this be configured?

Easy
24

What is the consequence of setting the 'Log Severity' threshold too high on a Security Gateway?

Hard
25

An administrator wants to ensure that specific logs are always sent to a remote Log Server, even if the primary Log Server becomes unreachable. Which feature should they configure?

Medium

Frequently asked questions

What does the Monitoring and Logging domain cover on the 156-215.81.20 exam?
Be able to locate log settings in SmartConsole, explain SmartEvent's role, and diagnose why gateway-generated logs are absent from Logs & Monitor. The key is knowing where logs are stored and forwarded, and how severity thresholds and rotation affect what you actually see.
How many questions are in this domain?
This page lists all 25 Monitoring and Logging questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Monitoring and Logging questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
checkpoint-ccsa CHECKPOINT-CCSA monitoring and logging Practice Questions