Log Forwarding is configured per Security Gateway and lets you choose which log types are exported. Pointing it at the external syslog server and selecting the Security log type exports gateway security logs while leaving management audit logs untouched, exactly matching the stated requirement.
Why this answer
Log Forwarding is the supported Check Point feature for exporting logs from a Security Gateway to an external destination such as a syslog server. Because it is configured on the gateway object and lets you select log types, it can send security logs to the SIEM while leaving management-side audit logs in place. Other mechanisms either loop logs back internally or target the wrong log category.
Exam trap
The trap here is assuming Log Forwarding is configured on the Management Server object rather than on the individual Security Gateway object that produces the logs.