nerdexam
Check_Point

156-215.80 · Question #4

Review the following screenshot and select the BEST answer.

The correct answer is C. If a connection is dropped in Network Layer, it will not be matched against the rules in Data Center. In Check Point's layered Access Control Policy, a drop action in one layer terminates inspection entirely - the connection is not evaluated against any subsequent inline layer.

Security Policy Management

Question

Review the following screenshot and select the BEST answer.

Options

  • AData Center Layer is an inline layer in the Access Control Policy.
  • BBy default all layers are shared with all policies.
  • CIf a connection is dropped in Network Layer, it will not be matched against the rules in Data Center
  • DIf a connection is accepted in Network-layer, it will not be matched against the rules in Data Center

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    84% (38)
  • D
    9% (4)

Why each option

In Check Point's layered Access Control Policy, a drop action in one layer terminates inspection entirely - the connection is not evaluated against any subsequent inline layer.

AData Center Layer is an inline layer in the Access Control Policy.

The Data Center Layer being an inline layer is a configuration detail visible in the screenshot, but it does not address the key behavioral outcome of drop vs. accept actions between layers.

BBy default all layers are shared with all policies.

Layers are not shared with all policies by default - sharing must be explicitly configured per layer in the policy settings.

CIf a connection is dropped in Network Layer, it will not be matched against the rules in Data CenterCorrect

When a rule in the Network Layer issues a drop action, the traffic is blocked immediately and the connection does not continue to be evaluated against the Data Center layer. This is the fundamental behavior of inline layers in the Access Control Policy - a drop terminates the entire inspection chain for that connection. Only an explicit accept action allows the connection to proceed to the next inline layer.

DIf a connection is accepted in Network-layer, it will not be matched against the rules in Data Center

When a connection is accepted in the Network Layer it IS evaluated against the Data Center layer rules, because acceptance passes the connection forward to subsequent inline layers.

Concept tested: Check Point Access Control Policy inline layer drop behavior

Source: https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Topics-SECMG/Policies-and-Layers.htm

Topics

#inline layers#policy layers#Data Center layer#Access Control Policy

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice