Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-215.80 All Questions

View all questions & answers for the 156-215.80 exam

Exam 156-215.80 topic 1 question 209 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 209
Topic #: 1
[All 156-215.80 Questions]

Your boss wants you to closely monitor an employee suspected of transferring company secrets to the competition. The IT department discovered the suspect installed a WinSCP client in order to use encrypted communication. Which of the following methods is BEST to accomplish this task?

  • A. Use SmartView Tracker to follow his actions by filtering log entries that feature the WinSCP destination port. Then, export the corresponding entries to a separate log file for documentation.
  • B. Use SmartDashboard to add a rule in the firewall Rule Base that matches his IP address, and those of potential targets and suspicious protocols. Apply the alert action or customized messaging.
  • C. Watch his IP in SmartView Monitor by setting an alert action to any packet that matches your Rule Base and his IP address for inbound and outbound traffic.
  • D. Send the suspect an email with a keylogging Trojan attached, to get direct information about his wrongdoings.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CCSAChallenger
1 year, 12 months ago
Makes no sense to make exports, which are an action in time, which means you need to make multiple exports, when your objective is monitoring. I would do B in a real situation...
upvoted 1 times
...
ShabVj
3 years, 2 months ago
Why not C? If we specify only Port 22 as a filter the report will give us all WinSCP traffic of the network ( unrelated traffic ) , if we want to monitor the user specifically i would go with option C.
upvoted 1 times
...
kambata
4 years ago
A, sounds logical.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...