ExamGecko
Question list
Search
Search

Question 401 - 156-315.81 discussion

Report
Export

In terms of Order Rule Enforcement, when a packet arrives at the gateway, the gateway checks it against the rules in the top Policy Layer, sequentially from top to bottom Which of the following statements is correct?

A.
If the Action of the matching rule is Accept the gateway will drop the packet
Answers
A.
If the Action of the matching rule is Accept the gateway will drop the packet
B.
If the Action of the matching rule is Drop, the gateway continues to check rules in the next Policy Layer down
Answers
B.
If the Action of the matching rule is Drop, the gateway continues to check rules in the next Policy Layer down
C.
If the Action of the matching rule is Drop the gateway stops matching against later rules in the Policy Rule Base and drops the packet
Answers
C.
If the Action of the matching rule is Drop the gateway stops matching against later rules in the Policy Rule Base and drops the packet
D.
If the rule does not match in the Network policy it will continue to other enabled polices
Answers
D.
If the rule does not match in the Network policy it will continue to other enabled polices
Suggested answer: C

Explanation:

If the action of the matching rule is Drop, the gateway stops matching against later rules in the Policy Rule Base and drops the packet. This is because the Drop action is a final action that terminates the rule matching process and discards the packet. The gateway does not continue to check rules in the next Policy Layer down or in other enabled policies.

Reference: [Policy Layers and Sub-Policies]

https://sc1.checkpoint.com/documents/R81/CP_R81_SecMGMT/html_frameset.htm?topic=documents/R81/CP_R81_SecMGMT/126197

asked 16/09/2024
Wilco Gent
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first