nerdexam
Check_Point

156-215.80 · Question #302

Which is the correct order of a log flow processed by SmartEvent components:

The correct answer is D. Firewall > Log Server > Correlation Unit > SmartEvent Server Database > SmartEvent Client. In Check Point SmartEvent, logs flow from the firewall to the Log Server, then to the Correlation Unit for pattern analysis, then to the SmartEvent Server Database for storage, and finally to the SmartEvent Client for display.

Monitoring and Reporting

Question

Which is the correct order of a log flow processed by SmartEvent components:

Options

  • AFirewall > Correlation Unit > Log Server > SmartEvent Server Database > SmartEvent Client
  • BFirewall > SmartEvent Server Database > Correlation Unit > Log Server > SmartEvent Client
  • CFirewall > Log Server > SmartEvent Server Database > Correlation Unit > SmartEvent Client
  • DFirewall > Log Server > Correlation Unit > SmartEvent Server Database > SmartEvent Client

How the community answered

(32 responses)
  • B
    6% (2)
  • C
    3% (1)
  • D
    91% (29)

Why each option

In Check Point SmartEvent, logs flow from the firewall to the Log Server, then to the Correlation Unit for pattern analysis, then to the SmartEvent Server Database for storage, and finally to the SmartEvent Client for display.

AFirewall > Correlation Unit > Log Server > SmartEvent Server Database > SmartEvent Client

This order incorrectly inserts the Correlation Unit before the Log Server - the Correlation Unit depends on logs already being received and indexed by the Log Server before it can process them.

BFirewall > SmartEvent Server Database > Correlation Unit > Log Server > SmartEvent Client

This order bypasses the Log Server as the initial recipient and incorrectly routes firewall logs straight to the SmartEvent Server Database before any correlation has occurred.

CFirewall > Log Server > SmartEvent Server Database > Correlation Unit > SmartEvent Client

This order places the SmartEvent Server Database storage step before the Correlation Unit analysis step - events must first be correlated by the Correlation Unit before their results are stored in the database.

DFirewall > Log Server > Correlation Unit > SmartEvent Server Database > SmartEvent ClientCorrect

The firewall generates and forwards raw logs to the Log Server first, the Correlation Unit then reads and analyzes those logs to detect event patterns, correlated results are written to the SmartEvent Server Database, and finally the SmartEvent Client queries that database to present events to administrators.

Concept tested: Check Point SmartEvent log processing component order

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SmartEvent_AdminGuide/Content/Topics-SmartEvent-AG/SmartEvent-Architecture.htm

Topics

#SmartEvent#log flow#Correlation Unit#event management

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice