ExamGecko
Question list
Search
Search

Question 88 - 156-315.81 discussion

Report
Export

The Correlation Unit performs all but the following actions:

A.
Marks logs that individually are not events, but may be part of a larger pattern to be identified later.
Answers
A.
Marks logs that individually are not events, but may be part of a larger pattern to be identified later.
B.
Generates an event based on the Event policy.
Answers
B.
Generates an event based on the Event policy.
C.
Assigns a severity level to the event.
Answers
C.
Assigns a severity level to the event.
D.
Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event.
Answers
D.
Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event.
Suggested answer: C

Explanation:

The Correlation Unit in Check Point Security Management performs several actions, but it does not assign a severity level to the event. The Correlation Unit is responsible for identifying patterns in logs, marking logs that are part of larger patterns, generating events based on the Event policy, and adding new log entries to ongoing events. However, assigning a severity level to an event is typically done through the Event policy configuration, not by the Correlation Unit.

asked 16/09/2024
jonathan siu
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first