The Correlation Unit performs all but the following actions:
The Correlation Unit performs all but the following actions:
The Correlation Unit performs tasks such as marking logs that individually are not events but may form part of a larger pattern, generating events based on the Event policy, and adding new log entries to ongoing events. However, assigning a severity level to the event is typically the responsibility of the SmartEvent Server, not the Correlation Unit. Thus, the Correlation Unit does not assign a severity level to events.
C is correct. The question asks for "all BUT the following..." CCSE manual, page 438, reads as follows: When analyzing a log, the Correlation Unit performs one of the following actions: • Marks logs that individually are not events, but may be part of a larger pattern to be identified later • Generates an event based on the Event policy • Takes a new log entry that is part of a group of items that together make up an event, and adds it to an ongoing event • Discards logs that do not meet event criteria
According CCSE manual, page 438, the correct answer is B.
What you have quoted "CCSE guide page 438" proves that the answer is "C" not B ....
NOT question
THE SMART EVENT SERVER PERFORM ANOTHER ANALYSIS TO DETERMINE THE SEVERITY OF THE EVENT AND WHAT ACTION TO TAKE
Correlation Unit Generates an event based on the Event policy, Then B is correct
* The SmartEvent Correlation Unit analyzes each log entry as it enters a Log Server, looking for patterns according to the installed Event Policy. The logs contain data from both Check Point products and certain third-party devices. When a threat pattern is identified, the SmartEvent Correlation Unit forwards what is known as an event to the SmartEvent Server. * When the SmartEvent Server receives events from a SmartEvent Correlation Unit, it assigns a severity level to the event, invokes any defined automatic reactions, and adds the event to the Events Database, which resides on the server. The severity level and automatic reaction are based on the Events Policy.
C is correct