Courseiva

156-215.81.20 · topic practice

Monitoring and Logging practice questions

This domain covers how Check Point logs are generated, stored, forwarded, and analyzed across Security Gateways and Management Server. Questions test SmartConsole Logs & Monitor, SmartEvent, log rotation and retention settings, log server configuration, and basic troubleshooting when expected logs do not appear in the GUI despite being generated on the gateway.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Monitoring and Logging

What the exam tests

What to know about Monitoring and Logging

Be able to locate log settings in SmartConsole, explain SmartEvent's role, and diagnose why gateway-generated logs are absent from Logs & Monitor. The key is knowing where logs are stored and forwarded, and how severity thresholds and rotation affect what you actually see.

Using Logs & Monitor in SmartConsole to view, filter, and track gateway and management logs

Configuring log rotation, retention, and storage limits for Security Management Server and gateways

SmartEvent blade functions: correlation, event generation, and threat/security event analysis

Troubleshooting missing logs using fw log, fw ctl, and log server connectivity checks

Watch out for

Common Monitoring and Logging exam traps

  • ▸Assuming logs shown by fw log on the gateway must appear in SmartConsole; they may not reach the management or log server.
  • ▸Confusing log rotation settings with retention or SmartEvent policy settings, and configuring the wrong object or location.
  • ▸Setting Log Severity too high, which suppresses lower-severity events and creates gaps in audit or troubleshooting data.

Practice set

Monitoring and Logging questions

20 questions · select your answer, then reveal the explanation

An administrator notices that logs are not appearing in SmartView Tracker for a specific Security Gateway. The gateway connectivity status is 'Unknown'. Which command is the primary method to verify the status of the log connection from the gateway to the Management Server?

An administrator needs to identify which policy rule is causing a high volume of 'Accept' logs for internal traffic. Which SmartView Tracker or SmartView feature is the most efficient way to aggregate and visualize this data?

Which TWO of the following tasks are performed by the 'cp_log_export' tool in a Check Point environment?

Which THREE of the following are valid methods to troubleshoot a situation where logs are not appearing in SmartView?

Which log tracking option should an administrator select to ensure that the log includes both the start and end of a connection?

When troubleshooting log connectivity, which port is typically used for the communication between the Security Gateway and the Management Server for log transmission?

Which feature in SmartView allows an administrator to combine multiple logs into a single report for compliance auditing?

An administrator notices that logs are truncated in SmartView. What is the most likely cause for this behavior?

An administrator notices that logs are not appearing in SmartView Tracker for a specific gateway. The gateway is reachable, and the policy shows 'Log' enabled on all rules. Which command should be run on the Security Gateway to verify if the Log Server is receiving the connection correctly?

Refer to the exhibit. An administrator is investigating why logs are missing from SmartView. The gateway status shows 'Connected' to the log server, but logs per second is zero. What is the most likely cause?

Exhibit

Log server: 192.168.1.10
Status: Connected
Log entries/sec: 0
Policy: Standard
Last log sent: 10:00:00

Which TWO of the following steps are required to properly configure Log Forwarding to an external syslog server?

If logs are missing from the Management Server, but 'fw log' shows traffic on the Gateway, what is the first troubleshooting step to perform?

Which THREE of the following are valid methods to free up disk space on a Security Management Server when log partitions are full?

Refer to the exhibit. An administrator notices that logs are being rotated at 10:00 PM instead of midnight. What could be the cause of this unexpected behavior?

Exhibit

Log Switch time: 00:00
Log Switch size: 2048 MB
Threshold: 90%
Keep logs: 30 days

Which log severity level should be filtered to reduce noise in the logs without missing critical security events?

Which TWO actions should be taken if the Management Server log indexer service is crashing consistently?

What must be installed on the Management Server to enable full log analysis and reporting features?

When troubleshooting log gaps, which file on the Gateway is the most useful to check for connectivity errors?

An administrator notices that SmartView Monitor is not displaying real-time traffic data for a specific Security Gateway. Which action should the administrator perform first to troubleshoot this issue?

Refer to the exhibit. An administrator is troubleshooting intermittent connectivity issues reported by users. Based on the CPView data provided, what is the most likely cause of the packet loss?

Exhibit

CPView output showing: Load: 15% | Memory: 40% | Connections: 850,000 | Conns/sec: 1200 | Packets/sec: 4500

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Monitoring and Logging sessions

Start a Monitoring and Logging only practice session

Every question in these sessions is drawn from the Monitoring and Logging domain — nothing else.

Related practice questions

Related 156-215.81.20 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 156-215.81.20 exam test about Monitoring and Logging?
Be able to locate log settings in SmartConsole, explain SmartEvent's role, and diagnose why gateway-generated logs are absent from Logs & Monitor. The key is knowing where logs are stored and forwarded, and how severity thresholds and rotation affect what you actually see.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Monitoring and Logging questions in a focused session?
Yes — the session launcher on this page draws every question from the Monitoring and Logging domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 156-215.81.20 topics?
Use the topic links above to move to related areas, or go back to the 156-215.81.20 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 156-215.81.20 exam covers. They are not copied from any real exam or dump site.