ExamGecko
Question list
Search
Search

Question 198 - 156-315.81 discussion

Report
Export

SmartEvent does NOT use which of the following procedures to identify events:

A.
Matching a log against each event definition
Answers
A.
Matching a log against each event definition
B.
Create an event candidate
Answers
B.
Create an event candidate
C.
Matching a log against local exclusions
Answers
C.
Matching a log against local exclusions
D.
Matching a log against global exclusions
Answers
D.
Matching a log against global exclusions
Suggested answer: C

Explanation:

SmartEvent does not use matching a log against local exclusions to identify events. Local exclusions are filters that are applied to logs before they are sent to the SmartEvent server. They are used to reduce the amount of logs that are forwarded by the Security Gateways or Log Servers, and to avoid sending irrelevant or sensitive logs. Local exclusions do not affect the event detection process, which is performed by the SmartEvent Correlation Unit on the SmartEvent server.

Reference:Check Point Security Expert R81 Course, SmartEvent Administration Guide, SK120193 - How to configure Local Log Filtering on Security Gateway / Cluster / VSX

asked 16/09/2024
Eb Store
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first