ExamGecko
Question list
Search
Search

Question 182 - 156-315.81 discussion

Report
Export

What is the benefit of ''tw monitor'' over ''tcpdump''?

A.
''fw monitor'' reveals Layer 2 information, while ''tcpdump'' acts at Layer 3.
Answers
A.
''fw monitor'' reveals Layer 2 information, while ''tcpdump'' acts at Layer 3.
B.
''fw monitor'' is also available for 64-Bit operating systems.
Answers
B.
''fw monitor'' is also available for 64-Bit operating systems.
C.
With ''fw monitor'', you can see the inspection points, which cannot be seen in ''tcpdump''
Answers
C.
With ''fw monitor'', you can see the inspection points, which cannot be seen in ''tcpdump''
D.
''fw monitor'' can be used from the CLI of the Management Server to collect information from multiple gateways.
Answers
D.
''fw monitor'' can be used from the CLI of the Management Server to collect information from multiple gateways.
Suggested answer: C

Explanation:

The benefit of fw monitor over tcpdump is that with fw monitor, you can see the inspection points, which cannot be seen in tcpdump. Inspection points are the locations in the firewall kernel where packets are inspected by the security policy and other software blades. Fw monitor allows you to capture packets at different inspection points and see how they are processed by the firewall. Tcpdump, on the other hand, is a generic packet capture tool that only shows the packets as they enter or leave the network interface.

Reference:Check Point Security Expert R81 Course,fw monitor, tcpdump

asked 16/09/2024
Benjamin Colart
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first