156-215.80 · Question #362
When an encrypted packet is decrypted, where does this happen?
The correct answer is A. Security policy. This question tests understanding of where VPN or encrypted packet decryption occurs within Check Point's packet processing flow.
Question
When an encrypted packet is decrypted, where does this happen?
Options
- ASecurity policy
- BInbound chain
- COutbound chain
- DDecryption is not supported
How the community answered
(53 responses)- A72% (38)
- B17% (9)
- C8% (4)
- D4% (2)
Why each option
This question tests understanding of where VPN or encrypted packet decryption occurs within Check Point's packet processing flow.
In Check Point's packet processing architecture, decryption of encrypted VPN traffic occurs at the Security Policy stage. The gateway must decrypt the packet before the Security Policy blades can inspect plaintext content, so decryption is integrated into Security Policy processing - not handled by a separate dedicated chain before or after policy evaluation.
The Inbound chain handles early interface-level packet reception steps, but VPN decryption is not performed there - it is handled further into the processing pipeline at the Security Policy layer.
The Outbound chain processes traffic as it leaves the gateway; incoming encrypted packets are not decrypted at this stage.
Check Point actively supports decryption of VPN and SSL/TLS encrypted traffic, so the claim that decryption is unsupported is factually incorrect.
Concept tested: Check Point VPN encrypted packet decryption processing location
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_VPN_AdminGuide/Content/Topics-VPN/VPN-Packet-Handling.htm
Topics
Community Discussion
No community discussion yet for this question.