Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-215.80 All Questions

View all questions & answers for the 156-215.80 exam

Exam 156-215.80 topic 1 question 217 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 217
Topic #: 1
[All 156-215.80 Questions]

A Cleanup rule:

  • A. logs connections that would otherwise be dropped without logging by default.
  • B. drops packets without logging connections that would otherwise be dropped and logged by default.
  • C. logs connections that would otherwise be accepted without logging by default.
  • D. drops packets without logging connections that would otherwise be accepted and logged by default.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
LashFX
2 years ago
@watt..If you don't log traffic being dropped by the cleanup rule how would you know the traffic you intend to be accepted is being dropped by which rule? You will troubleshoot not knowing where the issue is. Disk space is not a problem as you can set how long the logs should be stored and will be automatically be deleted to free up space.
upvoted 1 times
...
kambata
4 years ago
A, correct.
upvoted 4 times
...
watt
4 years, 4 months ago
It doesn't make sense. The cleanup rule should drop without logging. Why would anyone want to log all the incoming traffic to the GW?
upvoted 1 times
rr80
4 years, 3 months ago
There are 2 reasons that I have in my mind. 1st -If your actual rule base is set up correctly and all traffic hits rules that it should. If don't, you can easily check logs, troubleshot and see that FW block traffic which normally should pass FW. In case if rule base is set up correctly, you can push this problem to your Network team/storage or whatever to fix this problem. 2nd - Analyzing dropped packets you can see how much traffic and what type of traffic were blocked and someone from your organization may dig deeper to draw some conclusions.
upvoted 1 times
Wattttt
4 years, 3 months ago
There is no logical reason for that. If there's any problem, then I would log the traffic. If not, the mgmt server will run out of space because of non-stop incoming logs... A GW which is located between your internal and external network gets tons of packets and data. The mgmt server won't be able to proccess so many logs.
upvoted 1 times
kbk89
4 years, 2 months ago
na 2tb of hdd space is more than enough for logging all kinds of traffic , thats what we have in our company as well and in case you didnt know you can setup settings on the smartconsole to get rid of old logs as soon as your logs get filled to a certain level which also you can change so what you are saying makes no sense at all.
upvoted 1 times
...
rr80
4 years, 3 months ago
IDK, I work in 4 different environments and all off them log cleanup rule. Usually they keep 7-30 days logs available straight away and the rest are archived, send to the server and keep there for few years in case that someone would like to make deep investigation.
upvoted 2 times
...
...
mauchi
3 years, 10 months ago
because it helps with troubleshooting. It happened to me that a rule accepting certain traffic was there in the rule base, however it was being dropped as visible on the logs, at the clean up rule. The issue was that the policy hadnt been installed so the rule wasn't taking effect. It just helpful, thats all
upvoted 1 times
...
...
Anni_CCSA
4 years ago
with enough diskspace these days, why not ? You can rotate logs if needed. And it makes troubleshooting more easy.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...