Check Point Certified Security Administrator (CCSA) R82 Exam Materials-Question 113 Discussion
Comment Image Comment Image Comment Image

During a routine audit, an administrator needs to review which users made changes to the security policy. Which log type should be reviewed? (Choose one answer)

  • A. Security Logs
  • B. Audit Logs
  • C. Traffic Logs
  • D. Compliance Logs
Correct Answer: B

Brave-Dump Clients Votes

B 100%

Comments



Anonymous User 2026-09-10 18:18:38

Selected Answers: B


B. Audit Logs

Audit Logs specifically record administrative actions performed in SmartConsole — including who made changes to the security policy, what was changed, and when — making them the correct log type to review for tracking policy modification history during an audit.

Why the others are wrong:

A. Security Logs — Security Logs record traffic/security events (connections, threats, blocks, etc.) generated by the Security Gateway's enforcement — not administrative changes made to the policy itself.
C. Traffic Logs — Traffic Logs are a subset of security logs showing network connection activity — they reflect what traffic passed through the gateway, not who edited the policy.
D. Compliance Logs — "Compliance Logs" isn't a standard Check Point log type for tracking policy edits — compliance-related data is typically handled through the Compliance Blade's monitoring/scoring, not a dedicated administrative change log.