156-215.80 · Question #60
Choose the BEST describes the Policy Layer Traffic Inspection?
The correct answer is B. If a packet matches an inline layer, it will continue matching the next layer. In Check Point Policy Layer inspection, when a packet matches an inline layer, processing continues to the next ordered policy layer rather than terminating.
Question
Choose the BEST describes the Policy Layer Traffic Inspection?
Options
- AIf a packet does not match any of the inline layers, the matching continues to the next Layer.
- BIf a packet matches an inline layer, it will continue matching the next layer.
- CIf a packet does not match any of the inline layers, the packet will be matched against the Implicit
- DIf a packet does not match a Network Policy Layer, the matching continues to its inline layer.
How the community answered
(37 responses)- A14% (5)
- B76% (28)
- C8% (3)
- D3% (1)
Why each option
In Check Point Policy Layer inspection, when a packet matches an inline layer, processing continues to the next ordered policy layer rather than terminating.
This incorrectly describes the non-match case and its consequence - failing to match any inline layer rule causes the packet to hit the inline layer's implicit cleanup rule, not to continue to the next outer ordered layer directly.
In Check Point's policy layer architecture, inline layers are sub-layers nested within a parent policy layer rule. When a packet matches a rule that invokes an inline layer, it is fully processed by that inline layer, and upon completion the packet continues matching against the next ordered policy layer. This design enables modular, stacked policy enforcement across multiple inspection stages without terminating the match cycle.
This mischaracterizes the non-match path - a packet that does not match inline layer rules hits the inline layer's own implicit cleanup rule, not a separate construct simply called 'the Implicit.'
This reverses the hierarchy - inline layers are nested inside Network Policy Layer rules, not the other way around; a non-match in a Network Policy Layer does not route the packet down into an inline layer.
Concept tested: Check Point Policy Layer inline layer traffic inspection flow
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Policy-Layers.htm
Topics
Community Discussion
No community discussion yet for this question.