nerdexam
Check_Point

156-215.80 · Question #137

Look at the following screenshot and select the BEST answer.

The correct answer is A. Clients external to the Security Gateway can download archive files from FTP_Ext server using. The referenced policy rule permits external clients to download archive files from the FTP_Ext server via FTP.

Security Policy Management

Question

Look at the following screenshot and select the BEST answer.

Options

  • AClients external to the Security Gateway can download archive files from FTP_Ext server using
  • BInternal clients can upload and download any-files to FTP_Ext-server using FTP.
  • CInternal clients can upload and download archive-files to FTP_Ext server using FTP.
  • DClients external to the Security Gateway can upload any files to the FTP_Ext-server using FTP.

How the community answered

(51 responses)
  • A
    45% (23)
  • B
    6% (3)
  • C
    16% (8)
  • D
    33% (17)

Why each option

The referenced policy rule permits external clients to download archive files from the FTP_Ext server via FTP.

AClients external to the Security Gateway can download archive files from FTP_Ext server usingCorrect

The screenshot depicts an FTP security rule configured to allow inbound FTP download traffic specifically for archive file types originating from the FTP_Ext server, meaning clients external to the Security Gateway are permitted to retrieve archive files. The traffic direction (download), source location (external), and file type restriction (archive) in the rule all align with this answer.

BInternal clients can upload and download any-files to FTP_Ext-server using FTP.

This option incorrectly identifies the clients as internal and incorrectly states that any file type can be transferred in both directions, contradicting the directional and file-type restrictions visible in the rule.

CInternal clients can upload and download archive-files to FTP_Ext server using FTP.

This option incorrectly identifies the clients as internal rather than external, which contradicts the traffic source shown in the policy rule.

DClients external to the Security Gateway can upload any files to the FTP_Ext-server using FTP.

This option incorrectly states that external clients can upload files, whereas the rule only permits the download operation for the specified archive file type.

Concept tested: Check Point FTP Security Server rule interpretation

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECRM/FTP-Security-Server.htm

Topics

#Rule Base analysis#FTP#content filtering#access control rule

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice