Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-215.80 All Questions

View all questions & answers for the 156-215.80 exam

Exam 156-215.80 topic 1 question 296 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 296
Topic #: 1
[All 156-215.80 Questions]

If the first packet of an UDP session is rejected by a security policy, what does the firewall send to the client?

  • A. Nothing
  • B. TCP FIN
  • C. TCP RST
  • D. ICMP unreachable
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
djreymix
Highly Voted 3 years, 4 months ago
Exactly A is correct... is obviously... UDP SESSION... UDP SESSION!!!!!!
upvoted 6 times
DriVen
1 year, 8 months ago
yes! I can't understand why is there even a discussion here, feels like bots..
upvoted 1 times
...
...
Levis
Highly Voted 4 years, 4 months ago
A correct, bcoz UDP is stateless
upvoted 5 times
...
lacosta
Most Recent 9 months, 2 weeks ago
Answer D CCSE R80 course page 247 Point 5 of Statefull Inspection flow Also an explanation of how ICMP unreachable is used on UDP https://networkengineering.stackexchange.com/questions/62969/why-icmp-destination-port-unreachable-error-messeage-is-generated-for-unreliable
upvoted 1 times
...
zorolo
2 years, 6 months ago
I think it is "D", based on the CCSE courseware, “Stateful Inspection” section. According to the Inspection Process Flowchart details, if there is a match in the Rule Base, a NACK is sent, which is "ICMP unreachable" for UDP. As for statefulness, UDP communications usually expect answers that need to be tracked by firewalls, so even though UDP is stateless, it has a corresponding stateful inspection behavior in the firewall.
upvoted 1 times
...
z8d21oczd
2 years, 10 months ago
No, if the action is drop, nothing is send. if the action is drop, the firewall sends TCP RST for TCP and ICMP unreachable for UDP. As UDP ist stateless, it has to be icmp, as there is no UDP RST. This is basically the diffrence between action drop and action reject. D ist correct
upvoted 2 times
z8d21oczd
2 years, 10 months ago
i mean "if the action is reject" in the second sentence
upvoted 2 times
...
...
Crao
3 years, 8 months ago
Then it should be D since the question talks about 'reject'. I think it is D.
upvoted 1 times
...
wakopro
4 years, 1 month ago
Nothing is true for Drop action. ICMP unreachabe for reject
upvoted 3 times
mauchi
3 years, 8 months ago
of course not, it's asking about UDP, not ICMP. ICMP runs directly on IP, UDP is a transport layer protocol, you are mixing things up
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...