The destination server for Security Gateway logs depends on a Security Management Server configuration.
Select an option, then click Submit answer.
C You can enable logging on the Security Management Server (enabled by default), or deploy a dedicated Log Server. https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_LoggingAndMonitoring_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_LoggingAndMonitoring_AdminGuide/120829 upvoted 13 times
D is true. Security Gateway logs are configured under Security Gateway -> General Properties A - total stupid B - wrong. Log server/s for GW is not configured under SMS object ,but under GW object C - wrong. This is true, but this is not what they are asking for. upvoted 1 times
the best answer is B: To set up Domain gateways to send logs to the Domain Log Server: 1) Launch SmartDashboard for the Domain Management Server and double-click the Security Gateway object to display its Check Point Gateway window. 2) Display the Additional Logging page (under Logs and Masters) and check Forward log files to Security Management Server. The Security Management Servers drop-down list is enabled. 3) Select the new Domain Log Server from the Security Management Server drop-down list and click OK. Synchronizing Domain Log https://sc1.checkpoint.com/documents/R77/CP_R77_Multi-DomainSecurityManagement_WebAdminGuide/15416.htm upvoted 1 times
Negative, D is correct, 'cause logs are not automatically forwarded to a new log server upvoted 2 times
C is correct phrase, but not related to the question. Enable logging is on SMS and on the log-server. Configure logging destination is on the GW object (via smartConsole). config each GW to send logs to the log-server (destination) is in "General Properties" of GW object. CCSA R.80 book, p.490 D looks more correct answer (the word "enable", puts some doubts though) upvoted 3 times