nerdexam
Check_Point

156-215.80 · Question #180

The command fw fetch causes the:

The correct answer is B. Security Gateway to retrieve the compiled policy and inspect code from the Security Management. The 'fw fetch' command instructs the Security Gateway to pull the compiled security policy and INSPECT kernel code from the Security Management Server.

Security Gateway Troubleshooting

Question

The command fw fetch causes the:

Options

  • ASecurity Management Server to retrieve the IP addresses of the target Security Gateway.
  • BSecurity Gateway to retrieve the compiled policy and inspect code from the Security Management
  • CSecurity Gateway to retrieve the user database information from the tables on the Security
  • DSecurity Management Server to retrieve the debug logs of the target Security Gateway

How the community answered

(44 responses)
  • B
    93% (41)
  • C
    2% (1)
  • D
    5% (2)

Why each option

The 'fw fetch' command instructs the Security Gateway to pull the compiled security policy and INSPECT kernel code from the Security Management Server.

ASecurity Management Server to retrieve the IP addresses of the target Security Gateway.

The Security Management Server does not retrieve IP addresses from the gateway using fw fetch; gateway IP addressing is configured statically within the gateway object definition in SmartConsole.

BSecurity Gateway to retrieve the compiled policy and inspect code from the Security ManagementCorrect

The 'fw fetch' command causes the Security Gateway to connect to the Security Management Server and download the compiled policy package, which includes the security rules and the INSPECT kernel code required to enforce them. This is commonly used to manually recover or re-apply a policy on a gateway without initiating a full install from SmartConsole. Notably, the Security Gateway initiates the retrieval, which is the reverse of the standard 'Install Policy' push workflow.

CSecurity Gateway to retrieve the user database information from the tables on the Security

User database synchronization is handled by separate commands such as 'fwm dbexport' or related user-database utilities, not by fw fetch.

DSecurity Management Server to retrieve the debug logs of the target Security Gateway

Debug logs and diagnostic data are collected using separate tools such as 'fw log', 'cpinfo', or 'cpd_sched_config', not fw fetch.

Concept tested: Check Point fw fetch policy retrieval command behavior

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_CLI_ReferenceGuide/Content/Topics-CLIRG/fw-fetch.htm

Topics

#fw fetch command#policy retrieval#INSPECT code#Security Management Server

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice