Check Point Certified Security Administrator (CCSA) R82 Exam Materials-Question 169 Discussion
Comment Image Comment Image Comment Image

Which component is the source of the Logs sent to the Log Server? (Choose one answer)

  • A. The SmartReporter along with the Eventia Reporter.
  • B. The SmartEvent Correlation Unit
  • C. The SmartEvent Server
  • D. Security Gateway
Correct Answer: D

Brave-Dump Clients Votes

D 100%

Comments



Anonymous User 2026-09-13 04:01:13

Selected Answers: D


The correct answer is **D. Security Gateway**.

The R82 Logging and Monitoring Administration Guide confirms this directly: Security Gateways send logs to the Log Servers on the Security Management Server or on a dedicated server. Another section reinforces it, stating that Security Gateways / Clusters generate network logs, while the Management Server generates a separate category — audit logs (records of administrator actions).

Why the other options are wrong:

- **A. The SmartReporter along with the Eventia Reporter** — These are legacy reporting tools (pre-R80) that consume and present log data for reporting purposes; they aren't the source generating the logs in the first place.
- **B. The SmartEvent Correlation Unit** — This component processes and correlates logs after they've already been generated and collected, to identify security events and patterns. It analyzes logs, but doesn't originate them.
- **C. The SmartEvent Server** — Similarly, this is a management/analysis component that works with logs (aggregating and enabling analysis via SmartConsole's Logs & Events view) after they've been generated at the enforcement point, not the source of the logs themselves.

The Security Gateway is where traffic is actually inspected against the Security Policy, so it's the component that originates and forwards the raw logs to the Log Server.