Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-215.80 All Questions

View all questions & answers for the 156-215.80 exam

Exam 156-215.80 topic 1 question 60 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 60
Topic #: 1
[All 156-215.80 Questions]

Choose what BEST describes the Policy Layer Traffic Inspection.

  • A. If a packet does not match any of the inline layers, the matching continues to the next Layer.
  • B. If a packet matches an inline layer, it will continue matching the next layer.
  • C. If a packet does not match any of the inline layers, the packet will be matched against the Implicit Clean-up Rule.
  • D. If a packet does not match a Network Policy Layer, the matching continues to its inline layer.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://community.checkpoint.com/thread/1092

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
gielda211
1 year, 11 months ago
Selected Answer: C
C is correct https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm
upvoted 1 times
...
Troglodyte
2 years, 4 months ago
Selected Answer: B
https://community.checkpoint.com/t5/Management/Policy-Layers-in-R80-x/td-p/1717 and https://community.checkpoint.com/legacyfs/online/checkpoint/40533_pastedImage_4.png
upvoted 2 times
...
KenLui
2 years, 5 months ago
from post of fepe15, the parent rule is the part of inline layer and the matching continues to next rule of ordered layer if parent rule is mismatch. So answer C is incorrect, it describes any inline layer isn't matched.
upvoted 1 times
...
fepe15
3 years, 3 months ago
The Inline Layer has a parent rule (Rule 2 in the example), and sub rules (Rules 2.1 and 2.2). The Action of the parent rule is the name of the Inline Layer. If the packet does not match the parent rule of the Inline Layer, the matching continues to the next rule of the Ordered Layer (Rule 3). If a packet matches the parent rule of the Inline Layer (Rule 2), the Security Gateway checks it against the sub rules: If the packet matches a sub rule in the Inline Layer (Rule 2.1), no more rule matching is done. If none of the higher rules in the Ordered Layer match the packet, the explicit Cleanup Rule is applied (Rule 2.2). If this rule is missing, the Implicit Cleanup Rule is applied (see Types of Rules in the Rule Base). No more rule matching is done. Important - Always add an explicit Cleanup Rule at the end of each Inline Layer, and make sure that its Action is the same as the Action of the Implicit Cleanup Rule.
upvoted 4 times
fepe15
3 years, 3 months ago
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm
upvoted 4 times
...
...
ShabVj
3 years, 3 months ago
For sure the C is the correct answer: Here is from the checkpoint document: If the packet does not match the parent rule of the Inline Layer, the matching continues to the next rule of the Ordered Layer (Rule 3). If a packet matches the parent rule of the Inline Layer (Rule 2), the Security Gateway checks it against the sub rules: If the packet matches a sub rule in the Inline Layer (Rule 2.1), no more rule matching is done. If none of the higher rules in the Ordered Layer match the packet, the explicit Cleanup Rule is applied (Rule 2.2). If this rule is missing, the Implicit Cleanup Rule is applied (see Types of Rules in the Rule Base). No more rule matching is done. https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm
upvoted 1 times
...
DUGDUGDUG
3 years, 4 months ago
nooooo the Implied Rules are part of the inline layer. so C is irrelevant
upvoted 1 times
...
chst
3 years, 9 months ago
End of questions, it's C https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Content/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm If none of the higher rules in the Ordered Layer match the packet, the explicit Cleanup Rule is applied (Rule 2.2). If this rule is missing, the Implicit Cleanup Rule is applied (see Types of Rules in the Rule Base). No more rule matching is done.
upvoted 2 times
...
saicosocial
3 years, 9 months ago
C could be WRONG because it's written very bad: it talks about matching IMPLICIT CLEANUP, but according to the best practices, you should have an EXPLICIT CLEANUP (I'm sure all of you have defined an EXPLICIT "Note - If you use the Cleanup rule as the last explicit rule, the Last Implied Rule and the Implicit Cleanup Rule are not enforced" And I want add to the discussion that an inline layer is A PART of an Ordered Layers. So it's not so obvious that when the packet does not match any inline layers it will finish on the cleanup. That's because the rule base is not composed only of inline layers ;) My2cents
upvoted 2 times
theManFromRoom5
3 years, 5 months ago
I agree with you to some extent, however, the fact that it has reached an inline layer means that it has already fallen under the category of an ordered layer and as a result, I would think that it would either have to match one of the inline layers to that ordered layer rule or else be subject to implicit rules - seeing as an explicit cleanup rule would be an ordered layer rule, to which the packet would no longer be able to be checked by, having already 'entered' another ordered layer rule. Mylackofcents
upvoted 1 times
...
mrXam
3 years, 9 months ago
I agree. There is difference between inline and ordered layers which brings uncertainty to answer C.
upvoted 1 times
...
...
mauchi
3 years, 10 months ago
To me the one that makes most sense is C. As I understand it, if the packet does not match any of the inline layers, that means we have arrived at the end of a specific ordered layer, and at the end there is always the Implicit Clean=up Rule, which discards the packet. B However, matching an inline layer, doesn't mean you continue to the next layer, because if the rule matched in the inline layer is an action DROP, then nothing else will be checked.
upvoted 1 times
...
Aychi
4 years ago
I think C is the right answer
upvoted 1 times
Aychi
4 years ago
the implicit clean-up rule (could be either an accep or drop)
upvoted 1 times
mauchi
3 years, 10 months ago
implicit clean up rule is always drop...
upvoted 2 times
Hernan_Mella
2 years, 4 months ago
No! it can accept or drop
upvoted 2 times
...
...
...
...
wakopro
4 years, 1 month ago
I think the correct answer is C. The question is about Policy with Inline LayersIt's. It´s very clear in the link reference.
upvoted 1 times
...
Rafael_Lara
4 years, 3 months ago
The question says what is the BEST answer. B and C are correct, but i think that B is more embracing. So, I would choose B as the BEST answer.
upvoted 1 times
securitygeek
4 years, 3 months ago
You have gotten inline and ordered layers mixed up. B isnt correct - only correct option is C
upvoted 2 times
...
Hernan_Mella
2 years, 4 months ago
The action of the rule can be drop so B is incorrect.
upvoted 1 times
...
...
Levis
4 years, 4 months ago
C is correct, read below for clarity. https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Content/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm
upvoted 1 times
...
Timber
4 years, 5 months ago
I also think the correct answer is C. I suspect the confusion here is the difference between Policy Layers and Inline Layers.
upvoted 3 times
...
C4rlos
4 years, 7 months ago
I think the correct answer is C. From the reference provided in explanation: In Ordered Layers when an accept rule from the first layer is matched, the gateway goes over the rules in the next layer. In Inline Layers only traffic matched/accepted on the parent rule will reach and be inspected by the inside layer rules. The question is about inline layer, not ordered layer!
upvoted 4 times
secadmin44
4 years, 7 months ago
You're not right. The explanation of the answer is shown in the following pic. You can see, that an inline layer is matched and the the gateway goes over to the next layer. It goes from an inline layer of "access layer" to the "content layer". So B is right! https://community.checkpoint.com/legacyfs/online/checkpoint/40533_pastedImage_4.png
upvoted 3 times
C4rlos
4 years, 6 months ago
Matching an inline layer doesn't mean, that packet will continue matching the next layer. It would have to match a subrule that would have to accept the packet. Option C seems to be the best for me.
upvoted 4 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...