Courseiva

CCNA Monitoring And Logging Questions

25 questions · Monitoring And Logging topic · All types, answers revealed

1
MCQmedium

A security administrator needs to send only Security Gateway log records to an external SIEM over syslog, while keeping the Management Server's own audit logs local. Which Check Point configuration should be performed?

A.Enable Log Forwarding in the Security Gateway object and set the Management Server as the target.
B.Configure Log Forwarding on the Security Gateway object with the external syslog server as the target and select the Security log type.
C.Run cp_log_export on the Management Server with the --audit flag and a remote destination.
D.Modify the fwd.elg file on the Security Gateway to redirect log output to the SIEM.
AnswerB

Log Forwarding is configured per Security Gateway and lets you choose which log types are exported. Pointing it at the external syslog server and selecting the Security log type exports gateway security logs while leaving management audit logs untouched, exactly matching the stated requirement.

Why this answer

Log Forwarding is the supported Check Point feature for exporting logs from a Security Gateway to an external destination such as a syslog server. Because it is configured on the gateway object and lets you select log types, it can send security logs to the SIEM while leaving management-side audit logs in place. Other mechanisms either loop logs back internally or target the wrong log category.

Exam trap

The trap here is assuming Log Forwarding is configured on the Management Server object rather than on the individual Security Gateway object that produces the logs.

2
MCQmedium

An administrator wants to ensure that logs are indexed properly for quick searching in SmartView. Which process is responsible for this indexing?

A.fwd
B.log_indexer
C.cpd
D.smartview_server
AnswerB

The 'log_indexer' is specifically responsible for reading raw log files and creating a searchable index. This allows SmartView to quickly retrieve and filter log data. If this process is stopped or overloaded, search results in SmartView will be delayed or incomplete for recent events.

Why this answer

The log indexing process is critical for search performance. Understanding that the Log Indexer daemon performs this task allows administrators to troubleshoot why certain logs might be missing from search results. If the indexer is failing, searching becomes extremely slow or impossible, even if the logs are physically present on the server's disk.

Exam trap

Candidates frequently confuse the background 'log_indexer' process with general logging daemons like fwd or syslog, leading to incorrect troubleshooting steps.

3
MCQhard

An administrator is troubleshooting an issue where logs from a Security Gateway are not appearing in SmartLog. The administrator verifies that the gateway is sending logs to the Management Server, but the logs are not indexed. Which service should the administrator check on the Management Server to ensure proper log indexing?

A.fwd
B.CPView
C.solr
D.cpd
AnswerC

The solr service is the indexing engine used by Check Point for log indexing in SmartLog. If solr is not running or is malfunctioning, logs will not be indexed and thus will not appear in SmartLog searches. The administrator should verify that the solr service is active and check its logs for errors to resolve the indexing issue.

Why this answer

The solr service is responsible for indexing logs on the Management Server. When logs are received, solr processes them to enable fast searching in SmartLog. If solr is not running or has errors, logs will not be indexed and will be missing from SmartLog.

The administrator should check the status of the solr service and review its logs for any issues.

Exam trap

The trap here is confusing the solr indexing service with general management services like cpd or monitoring tools like CPView, which do not handle log indexing.

4
MCQeasy

An administrator needs to review logs from a specific Security Gateway that occurred between 2:00 AM and 4:00 AM yesterday. Which SmartConsole application should the administrator use to efficiently filter and analyze these logs?

A.SmartView Monitor
B.SmartLog
C.SmartEvent
D.SmartDashboard
AnswerB

SmartLog is the log analysis tool in SmartConsole that allows administrators to search, filter, and analyze historical logs from all managed gateways. It supports time-range queries and granular filtering, making it ideal for reviewing specific events within a defined period. This directly meets the requirement to examine logs from a particular gateway and time window.

Why this answer

SmartLog is the correct tool for searching and analyzing historical logs. It provides a dedicated interface with time-range filters and query capabilities, allowing the administrator to isolate logs from a specific gateway and time window. Other tools like SmartView Monitor, SmartEvent, and SmartDashboard serve different purposes and are not suited for this task.

Exam trap

The trap here is confusing SmartEvent, which is for event correlation and reporting, with SmartLog, which is the primary tool for ad-hoc log investigation.

5
MCQmedium

A security administrator needs to configure a Security Gateway to send its logs to a third-party SIEM via syslog. The SIEM is reachable only through an external interface, and the administrator wants to avoid sending logs over the internal network. Which Check Point feature should be used to achieve this requirement?

A.Logging and Status Blade
B.Log Exporter
C.SmartEvent Correlation Unit
D.SmartView Tracker
AnswerB

Log Exporter is a Check Point feature that allows exporting logs from the Security Gateway to an external syslog server. It supports sending logs directly from the gateway, which can be configured to use a specific interface, such as an external one, to reach the SIEM. This meets the requirement of avoiding the internal network for log transmission.

Why this answer

Log Exporter is the correct feature because it is designed to export logs from Check Point Security Gateways to external syslog servers. It can be configured to use a specific source interface, allowing the administrator to direct traffic through an external interface and avoid the internal network. This provides the required functionality without relying on the Management Server for forwarding.

Exam trap

The trap here is assuming that the Logging and Status Blade alone can forward logs to external syslog servers, when in fact it only sends logs to the Management Server.

6
MCQeasy

An administrator needs to review all logs generated by a specific Security Gateway over the past week. The administrator wants to see the logs in a tabular format and apply filters based on source IP. Which SmartConsole tool should the administrator use?

A.SmartEvent
B.SmartView Monitor
C.SmartLog
D.SmartView Tracker
AnswerC

SmartLog is the modern log query tool in SmartConsole, providing a tabular view of logs with powerful filtering capabilities. Administrators can filter by gateway, time range, and source IP, among other fields. It is designed for exactly this purpose: reviewing and analyzing logs from specific gateways over a specified period. Therefore, SmartLog is the correct tool.

Why this answer

SmartLog is the primary tool in SmartConsole for querying and viewing logs. It provides a tabular format and allows filtering by various fields, including gateway and source IP. SmartView Tracker is deprecated, SmartEvent is for event correlation, and SmartView Monitor is for real-time monitoring.

Thus, SmartLog is the correct choice.

Exam trap

The trap here is assuming that SmartView Tracker is still the go-to tool for log viewing, but in R81.20 it has been replaced by SmartLog.

7
MCQeasy

An administrator needs to verify that a Security Gateway is sending logs to the Management Server. The administrator wants to see a real-time count of log messages received by the management server from each gateway. Which SmartConsole tool provides this information?

A.SmartEvent
B.SmartConsole Logs & Monitor
C.SmartLog
D.SmartView Monitor
AnswerD

SmartView Monitor provides real-time counters and statuses, including the number of logs received from each gateway. Under the 'Logging' section, administrators can view per-gateway log reception statistics, which directly answers the need to see a real-time count of log messages. This tool is specifically designed for monitoring gateway and management server health and traffic.

Why this answer

SmartView Monitor includes a Logging section that shows real-time statistics, such as the number of logs received from each Security Gateway. This allows administrators to quickly verify that gateways are successfully sending logs to the management server. SmartLog is for querying individual logs, SmartEvent is for correlation, and SmartConsole Logs & Monitor is the container for these tools, not a monitoring tool itself.

Exam trap

The trap here is confusing SmartView Monitor with SmartLog; while both are under Logs & Monitor, only SmartView Monitor provides real-time counters for log reception.

8
MCQmedium

Your organization requires that all log files be rotated when they reach a specific size limit to ensure efficient disk usage. Where should an administrator configure the automatic log rotation settings in SmartConsole?

A.Gateway object properties > Logs
B.Global Properties > Log and Alert
C.Log Server object properties > Log Management
D.SmartView Monitor > General Settings
AnswerC

The Log Server object settings provide the granular control necessary to define log rotation. By adjusting the 'Log Management' parameters, an administrator can specify file size limits or time-based triggers, ensuring the system automatically rotates logs to maintain disk availability without manual intervention or service interruption.

Why this answer

Log rotation settings are managed within the Log Server properties, specifically under the 'Log Management' section. Proper rotation configuration prevents disk partition overflow, which would stop the Logging process entirely. Managing these settings ensures the Security Management Server maintains performance and data integrity while adhering to the retention policies defined by organizational security requirements for historical log archival and system stability.

Exam trap

Candidates often look for log settings under the Gateway object or Global Properties, failing to realize that log rotation specific to disk management is configured within the Log Server object.

9
MCQmedium

An administrator notices that the Security Management Server's disk space is being consumed rapidly by log files. The administrator wants to automatically delete logs older than 90 days to free up space. Which Check Point feature should be configured to achieve this?

A.SmartEvent Policy
B.Database Revision Control
C.Log Exporter
D.Log Retention Policy
AnswerD

Log Retention Policy is a feature in Check Point that allows administrators to define how long logs are kept before being deleted. It can be configured to automatically delete logs older than a specified number of days, such as 90 days. This directly addresses the requirement to free up disk space by removing old logs without manual intervention.

Why this answer

Log Retention Policy is the correct feature because it allows the administrator to set a retention period for logs, after which they are automatically deleted. This directly solves the problem of disk space being consumed by old logs. Other features like Log Exporter, SmartEvent Policy, and Database Revision Control do not provide automatic log deletion based on age.

Exam trap

The trap here is confusing Log Exporter with a log management tool that can delete logs, but Log Exporter only forwards logs and does not remove them from local storage.

10
MCQmedium

A security administrator is investigating a suspicious connection to an external IP. The administrator needs to see the raw packet-level details captured by the Security Gateway's IPS blade to determine the exact payload that triggered the protection. Which SmartConsole tool should the administrator use to view this information?

A.SmartView Tracker
B.Forensics
C.SmartLog
D.SmartView Monitor
AnswerB

Forensics is a SmartConsole view that stores and displays packet captures for IPS events, including the raw payload that triggered a protection. By enabling Forensics in the IPS policy, the administrator can later open the Forensics view, locate the relevant log entry, and inspect the exact packet data. This directly answers the need to see packet-level details for the suspicious connection.

Why this answer

The Forensics view in SmartConsole is designed to provide packet-level details for IPS events, capturing the raw payload that triggered a protection. While SmartLog and SmartView Tracker show log entries, they do not include the actual packet data. SmartView Monitor is for real-time status, not forensic analysis.

Therefore, Forensics is the correct tool for examining the exact payload of the suspicious connection.

Exam trap

The trap here is assuming that SmartLog, which is the default log viewer, includes packet capture data for IPS events, when in fact that data is only available in the separate Forensics view.

11
MCQhard

A security analyst is investigating a suspected intrusion and needs to view all logs related to a specific source IP address across multiple Security Gateways. The logs are stored on a central Management Server. Which SmartConsole feature should the analyst use to efficiently search and filter these logs?

A.SmartEvent
B.SmartLog
C.SmartView Tracker
D.Log Consolidation
AnswerB

SmartLog is a unified, indexed log viewing tool in SmartConsole that provides fast search and filtering across all logs stored on the Management Server. It supports complex queries, including searching by source IP, and can aggregate logs from multiple gateways. This makes it the most efficient feature for the analyst's requirement to investigate across multiple gateways.

Why this answer

SmartLog is the correct feature because it is specifically designed for fast, indexed searching of logs across multiple gateways. It allows the analyst to filter by source IP and view results from all gateways in a single interface. SmartView Tracker is less efficient, SmartEvent is for events, and Log Consolidation is not a search tool.

Thus, SmartLog is the most efficient choice.

Exam trap

The trap here is assuming that SmartEvent can be used for raw log searches, but it only shows correlated events and lacks the granular filtering needed for detailed log analysis.

12
MCQeasy

Which tab in SmartConsole allows an administrator to view the status of the Security Management Server and its associated gateways, including CPU and memory usage?

A.Security Policies
B.Logs & Monitor
C.Gateways & Servers
D.Manage & Settings
AnswerC

This tab provides the 'Device & License Information' view, which displays real-time health data including CPU utilization, memory usage, and interface traffic statistics. It is the centralized location within SmartConsole for performing infrastructure monitoring and verifying the operational status of all managed security devices in the environment.

Why this answer

The 'Gateways & Servers' view in SmartConsole provides a comprehensive health status of the managed environment. Monitoring system resources is fundamental for administrators to proactively identify performance bottlenecks or impending hardware failures. This ensures the Security Management Server and gateways remain operational and capable of processing security policies and logs without unexpected downtime or degradation in system responsiveness.

Exam trap

Candidates frequently choose 'Logs & Monitor' or 'Security Policies' because they are the most commonly used tabs, failing to realize the system health view is located under 'Gateways & Servers'.

13
MCQmedium

A security administrator is troubleshooting a performance issue on a Check Point R81 Security Gateway. The administrator suspects that a specific process is generating an excessive number of logs, causing high CPU usage. Which SmartConsole tool should the administrator use to view real-time, per-process resource consumption on the gateway?

A.SmartView Tracker
B.cpview
C.SmartView Monitor
D.SmartEvent
AnswerB

cpview is the correct tool because it provides real-time, interactive monitoring of a Security Gateway's performance, including CPU and memory usage broken down by process. This allows the administrator to identify which specific process is consuming excessive resources, directly addressing the troubleshooting scenario. It is a command-line utility available directly on the gateway.

Why this answer

The correct answer is cpview, as it is the dedicated real-time monitoring tool that runs on a Check Point Security Gateway. It provides detailed, per-process CPU and memory statistics, enabling administrators to quickly identify resource-heavy processes. Other tools like SmartView Monitor offer broader overviews but lack the granularity needed for this specific troubleshooting task.

Exam trap

The trap here is confusing high-level monitoring tools like SmartView Monitor with low-level, real-time diagnostic utilities like cpview.

14
MCQeasy

An administrator wants to receive immediate notification when a critical security event, such as a malware infection, is detected by a Security Gateway. Which Check Point feature should the administrator configure to send an alert?

A.Log Exporter
B.SmartView Monitor threshold alerts
C.SmartEvent correlation policy
D.Alert definitions in SmartConsole
AnswerD

Alert definitions in SmartConsole allow administrators to configure specific conditions, such as malware detection, and specify actions like sending an email or SNMP trap. This provides immediate notification when the event occurs, directly fulfilling the requirement for real-time alerting on critical security events.

Why this answer

Alert definitions in SmartConsole are the correct feature for configuring immediate notifications on specific security events. The administrator can define an alert that triggers when a malware log is generated, and set actions such as email or SNMP traps. This provides real-time awareness of critical incidents without relying on external systems.

Exam trap

The trap here is confusing performance monitoring alerts with security event alerts; SmartView Monitor thresholds do not cover log-based security events.

15
MCQmedium

If an administrator needs to identify the source of a connection drop in the logs, which field is most useful to inspect first?

A.User
B.Reason
C.Interface
D.Service
AnswerB

The 'Reason' or 'Blade' field directly states why the connection was dropped (e.g., 'Policy' for a rule block, or 'IPS' for a threat detection). This is the most efficient starting point for troubleshooting, as it identifies the exact security component that made the decision to block the traffic.

Why this answer

Identifying the 'Drop' reason is key. The 'Policy' or 'Reason' field typically contains the specific rule number or the name of the software blade (like IPS or Anti-Bot) that caused the drop. Mastering this analysis technique allows for rapid troubleshooting of connectivity problems, minimizing downtime and allowing for quicker policy adjustments when valid traffic is being incorrectly blocked.

Exam trap

Students tend to look at generic traffic fields like source or destination IP first, rather than focusing directly on the rule number or drop reason.

16
MCQhard

Refer to the exhibit. What is the most likely reason this traffic was dropped?

A.The traffic was blocked by a firewall rule.
B.The traffic triggered an IPS protection signature.
C.The packet was dropped due to a routing error.
D.The connection was rejected by the server.
AnswerB

The log explicitly states that the 'Blade' is 'IPS' and the 'Reason' is 'Threat Prevention'. This confirms that the IPS engine analyzed the packet and identified it as matching a known malicious signature or anomaly, leading to an automatic block to protect the network from potential attack.

Why this answer

The log output provides specific metadata about the drop. By identifying that the 'Blade' is IPS and the 'Reason' is Threat Prevention, we can conclude the traffic matched a malicious pattern detected by the IPS engine. This is a critical distinction, as it differentiates between a standard policy block and a security-enforced threat protection action.

Exam trap

Candidates often mistake an IPS threat prevention drop for a standard security policy rule block, ignoring the specific blade metadata.

17
Multi-Selectmedium

An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)

Select 2 answers
A.action
B.src
C.proto
D.dst
E.rule
AnswersA, E

The 'action' field indicates what the Security Gateway did with the connection, such as Accept, Drop, or Reject. Including this field in the syslog export ensures that the SIEM can distinguish between allowed and blocked traffic, which is essential for security monitoring and compliance. Without it, the SIEM would not know the outcome of the connection.

Why this answer

To meet the requirement of including the action taken and the rule number in exported syslog messages, the administrator must ensure that the 'action' and 'rule' fields are included. These fields provide the necessary information to identify what the gateway did and which policy rule was matched, enabling effective SIEM analysis.

Exam trap

The trap here is assuming that common fields like source and destination IP addresses are required for the export, when the specific requirement is for action and rule number.

18
MCQeasy

What is the primary function of the 'SmartEvent' blade in the context of logging?

A.To store raw logs for long-term audit.
B.To correlate logs and identify security events.
C.To manage the deployment of security patches.
D.To monitor network bandwidth usage.
AnswerB

The primary purpose of the SmartEvent blade is to correlate individual log entries from multiple sources to identify significant security incidents. It uses predefined policies to detect complex attack patterns, such as port scanning or brute-force attempts, providing actionable alerts that are more useful than raw logs.

Why this answer

SmartEvent is a powerful correlation engine that transforms raw logs into meaningful security events. It is essential for identifying patterns that span across multiple logs. By categorizing and prioritizing these events, it allows security teams to manage thousands of logs effectively, transforming data overflow into manageable security insights that drive faster decision-making and incident response.

Exam trap

Candidates commonly confuse SmartEvent's correlation and threat identification function with basic log forwarding or simple firewall rule generation.

19
MCQmedium

A Security Gateway stops sending logs to the Management Server, and users report that SmartView Logs shows no new entries. The administrator confirms the gateway is passing traffic. Which action should be taken first to diagnose the log transmission problem?

A.Increase the log storage quota on the Security Gateway.
B.Verify SIC trust status between the Security Gateway and the Management Server.
C.Restart the SmartConsole client to refresh the log view.
D.Change the log forwarding port in Global Properties.
AnswerB

Log transmission depends on the secure communication channel established by SIC. If SIC is broken or the trust state is not established, the gateway cannot deliver logs even though traffic forwarding continues. Checking SIC status is therefore the logical first diagnostic step for missing logs.

Why this answer

Secure Internal Communication, or SIC, is the trust foundation for all traffic between a Security Gateway and its Management Server, including log delivery. When logs stop arriving but traffic still flows, verifying SIC status quickly identifies whether the management channel itself is broken. Other actions either treat display symptoms or alter configuration without evidence.

Exam trap

The trap here is assuming missing logs always indicate a logging configuration error, when a broken SIC trust relationship can silently stop log delivery while traffic forwarding continues normally.

20
MCQhard

An administrator is troubleshooting why logs from a Security Gateway are not appearing in SmartLog, even though the gateway is configured to send logs to the Management Server and the connection is established. The administrator runs 'cp_log_export' on the Management Server and sees that logs are being exported to an external syslog server successfully. What is the most likely reason for the logs not appearing in SmartLog?

A.The Management Server's disk is full, preventing new logs from being written.
B.The Security Gateway's log forwarding configuration is incorrect.
C.SmartLog is not licensed on the Management Server.
D.The log indexer service on the Management Server is not running.
AnswerD

If the log indexer service is not running, logs may still be received and even exported to external syslog, but they will not be indexed for SmartLog. SmartLog relies on the indexer to make logs searchable. The fact that 'cp_log_export' works confirms that logs are present on the server, but the indexer's failure explains their absence in SmartLog.

Why this answer

The log indexer service is responsible for indexing logs so they can be searched in SmartLog. If it is not running, logs may still be received and exported via 'cp_log_export', but they will not appear in SmartLog. This matches the scenario where logs are present but not visible in SmartLog.

Exam trap

The trap here is assuming that successful log export means the logs are also indexed, but indexing is a separate process that can fail independently.

21
MCQmedium

An administrator observes that logs are missing from the 'Logs & Monitor' tab, but the 'fw log' command shows logs are being generated on the gateway. What is the most likely cause?

A.The Security Policy is not set to log.
B.The log server connection is interrupted or the FWD process is down.
C.The Log Server disk is full.
D.The SmartConsole client is outdated.
AnswerB

The fwd process on the gateway acts as the transport layer for logs sent to the management server. If the process is down or the network path to the management server is blocked, logs will remain local and never be indexed, appearing missing in the centralized SmartView interface.

Why this answer

This scenario points to a communication breakdown between the gateway and the Log Server. The logs are generated locally but not successfully reaching the management server, often due to a stopped fwd process or communication failure. Identifying this distinction allows the administrator to focus on the transport layer rather than the policy configuration, saving time and restoring log visibility faster.

Exam trap

Test-takers frequently assume that if logs are successfully generated locally via 'fw log', the management server must be receiving them, overlooking transport-layer failures or downed FWD processes.

22
MCQhard

During an investigation, an administrator must find all connections that were dropped by the Security Gateway in the last 24 hours for a specific source IP. Which SmartConsole tool provides the most efficient way to search and filter these logs?

A.SmartConsole Audit Logs filtered by administrator name.
B.SmartView Logs with a filter on the source IP and Action equal to Drop.
C.SmartEvent with a predefined report on network activity.
D.cpview on the Security Gateway with the connections view.
AnswerB

SmartView Logs is the modern log analysis interface in SmartConsole, and it supports filtering by fields such as source IP and action. Applying a filter for the specific source and Drop action returns exactly the dropped connections for that host, making it the most efficient and accurate way to investigate this scenario.

Why this answer

SmartView Logs provides field-based filtering in SmartConsole, allowing an administrator to combine conditions such as source IP and action to narrow millions of records down to the relevant dropped connections. It queries indexed logs efficiently and displays results immediately. Other tools focus on correlation, real-time performance, or administrative auditing and cannot perform this targeted historical search.

Exam trap

The trap here is confusing SmartEvent, which correlates and reports on events, with SmartView Logs, which is the tool for direct filtering and searching of individual log records.

23
MCQeasy

An administrator notices that the Security Management Server disk is filling rapidly because log files are retained indefinitely. The retention policy must keep logs for 90 days and then remove older records automatically. Where should this be configured?

A.By scheduling a cron job that deletes files from the log directory nightly.
B.By adjusting the log size limit per gateway in Global Properties.
C.In the Security Gateway object's Logging and Time settings.
D.In the Management Server object's Logging settings, by defining a log retention period.
AnswerD

The Management Server object includes logging configuration where an administrator can set how many days logs are retained. Specifying 90 days causes logs older than that threshold to be removed automatically, directly addressing the disk growth while meeting the retention requirement.

Why this answer

Log retention is governed on the Management Server object, where an administrator defines how many days logs are kept. Setting 90 days ensures older records are purged automatically, controlling disk consumption while satisfying the retention policy. Gateway-side settings and manual file deletion do not provide supported, age-based log lifecycle management.

Exam trap

The trap here is assuming log retention is a Security Gateway setting, when it is actually configured on the Management Server object that stores the logs.

24
MCQhard

What is the consequence of setting the 'Log Severity' threshold too high on a Security Gateway?

A.The gateway stops processing traffic.
B.The management server becomes overloaded.
C.Important security events may not be logged.
D.The CPU usage on the gateway increases significantly.
AnswerC

If the severity threshold is set too high (e.g., only logging critical events), lower-severity events like 'Information' or 'Warning' logs will be discarded. This can lead to missing subtle indicators of a compromise or reconnaissance activities that do not trigger a 'Critical' status but are vital for security analysis.

Why this answer

Setting a high severity threshold limits the volume of logs generated, which improves performance but risks missing lower-priority security events. Administrators must balance log detail with system performance. Finding the right balance is essential for maintaining a clean log environment that facilitates effective threat detection without overloading the storage systems or creating a bottleneck in the log indexing process on the Management Server.

Exam trap

Candidates often assume that high severity thresholds only impact performance, failing to recognize that this configuration directly results in the loss of visibility into critical security events.

25
MCQmedium

An administrator wants to ensure that specific logs are always sent to a remote Log Server, even if the primary Log Server becomes unreachable. Which feature should they configure?

A.Log Aggregation
B.Log Redundancy
C.Log Compression
D.Log Indexing
AnswerB

Configuring multiple log servers in the gateway properties enables log redundancy. If the primary log server is unreachable, the gateway attempts to forward logs to the secondary server, ensuring continuous logging and preventing data loss during maintenance or unexpected outages of the primary logging infrastructure component.

Why this answer

Log redundancy ensures high availability for log storage. By defining multiple Log Servers in the gateway object properties, Check Point gateways can automatically failover or load-balance log traffic. This is crucial for maintaining compliance in environments where continuous logging is a strict requirement, ensuring that no security events are lost during a single-point-of-failure event on the primary logging server.

Exam trap

Candidates often confuse 'Log Redundancy' with 'High Availability' for the firewall cluster. They mistakenly look for cluster settings instead of specifically configuring log server redundancy in the object properties.

Ready to test yourself?

Try a timed practice session using only Monitoring And Logging questions.