Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-315.81 All Questions

View all questions & answers for the 156-315.81 exam

Exam 156-315.81 topic 1 question 74 discussion

Actual exam question from Checkpoint's 156-315.81
Question #: 74
Topic #: 1
[All 156-315.81 Questions]

What are the attributes that SecureXL will check after the connection is allowed by Security Policy?

  • A. Source address, Destination address, Destination port, Protocol
  • B. Source MAC address, Destination MAC address, Source port, Destination port, Protocol
  • C. Source address, Destination address, Source port, Destination port, Protocol
  • D. Source address, Destination address, Source port, Destination port
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
McBeano
1 year, 4 months ago
Selected Answer: A
I think the keywords here are "AFTER the connection is allowed.." which I'm assuming means the traffic matches a SecureXL "Accept Template" Looking at the default output of the command "fwaccel templates" in the below link, you can see that Source IP, Dest IP, DPort, and PR (protocol?) are listed. SPort has a * value. https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/PTG/SecureXL/fwaccel-templates.htm
upvoted 1 times
...
rabbirobert
1 year, 5 months ago
I would say C (CCSE kortext site 323) A would be for Connection/Session Rate Accleration. But not absolutly sure
upvoted 2 times
...
lalaliano
1 year, 8 months ago
Selected Answer: A
A is correct, page 324 CCSE student and lab manual
upvoted 4 times
...
vgs2023
1 year, 8 months ago
Selected Answer: A
A is correct, because Templates resource.
upvoted 2 times
...
Gab_agl
1 year, 9 months ago
Selected Answer: A
I think the correct answer is A. As we have seen in the packet acceleration, the first packet of each connection has to go through the F2F path and then the connection gets offloaded to the SecureXL. The connection rate acceleration works by processing the first packet of a connection within SecureXL and not sending it to the Firewall. This is possible with help of templates (explained below) which identifies the allowable connections by 4 attributes: Source address Destination address Destination port Protocol If a connection with these four attributes has been allowed by the Firewall previously, then it will continue to allow more connections with the same four attributes. unless: The policy has been updated The policy includes source port restriction The service uses dynamically mapped ports. e.g. RPC-DCOM
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...