Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 156-215.80 topic 1 question 192 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 192
Topic #: 1
[All 156-215.80 Questions]

What CLI utility allows an administrator to capture traffic along the firewall inspection chain?

  • A. show interface (interface) ג€"chain
  • B. tcpdump
  • C. tcpdump /snoop
  • D. fw monitor
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Levis
Highly Voted 3 years, 9 months ago
fw monitor is additional to tcpdump, it tells you where did inspection drop the packet or allowed it etc.
upvoted 5 times
...
Nikolas
Highly Voted 3 years, 7 months ago
D is correct, from CCSE R80 guide: fw monitor captures packets as they enter and leave the Firewall kernel and when the packet enters and leaves the Inbound and Outbound chains.
upvoted 5 times
...
djreymix
Most Recent 2 years, 10 months ago
From de admin guide. Introduction Check Point's FW Monitor is a powerful built-in tool for capturing network traffic at the packet level. The FW Monitor utility captures network packets at multiple capture points along the FireWall inspection chains. These captured packets can be inspected later using the WireShark (available for free from www.wireshark.org). D is correct
upvoted 4 times
...
lucacin
2 years, 11 months ago
Tcpdump is a command line utility that allows you to capture and analyze network traffic going through your system. It is often used to help troubleshoot network issues, as well as a security tool.
upvoted 1 times
...
D is correct. https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_PerformanceTuning_AdminGuide/Content/Topics-PTG/CLI/fw-monitor.htm
upvoted 4 times
...
Snowwhite
3 years, 10 months ago
Can some1 clarify why its D and not B? Tcpdump is also uses for packet capture.
upvoted 1 times
stenofaaa
3 years, 9 months ago
question says "firewall inspection chain" and not only capture traffic
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...