The Correlation Unit performs all but the following actions:
A.
Marks logs that individually are not events, but may be part of a larger pattern to be identified later.
B.
Generates an event based on the Event policy.
C.
Assigns a severity level to the event.
D.
Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event.
The Answer Is:
C
This question includes an explanation.
Explanation:
The Correlation Unit in Check Point Security Management performs several actions, but it does not assign a severity level to the event. The Correlation Unit is responsible for identifying patterns in logs, marking logs that are part of larger patterns, generating events based on the Event policy, and adding new log entries to ongoing events. However, assigning a severity level to an event is typically done through the Event policy configuration, not by the Correlation Unit.
References: Check Point Certified Security Expert R81 Study Guide
156-315.81 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"