nerdexam
EC-Council

312-49 · Question #691

An investigator is analyzing a checkpoint firewall log and comes across symbols. What type of log is he looking at?

The correct answer is C. An email marked as potential spam. In Check Point firewall logs, different symbols and icons represent different security events. The symbol referenced in this question corresponds to email traffic flagged as potential spam by the firewall's content inspection or anti-spam blade. Check Point SmartView Tracker…

Submitted by carter_n· Apr 18, 2026Network Forensics

Question

An investigator is analyzing a checkpoint firewall log and comes across symbols. What type of log is he looking at?

Options

  • ASecurity event was monitored but not stopped
  • BMalicious URL detected
  • CAn email marked as potential spam
  • DConnection rejected

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    89% (34)
  • D
    5% (2)

Explanation

In Check Point firewall logs, different symbols and icons represent different security events. The symbol referenced in this question corresponds to email traffic flagged as potential spam by the firewall's content inspection or anti-spam blade. Check Point SmartView Tracker uses color-coded icons and symbols to categorize log entries: connection rejections, monitored events, malicious URL detections, and spam detections each have distinct visual indicators. Investigators must be familiar with these symbols to correctly interpret log entries during an investigation.

Topics

#Firewall Logs#Checkpoint Firewall#Log Analysis#Spam Detection

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice