exam questions

Exam 156-215.80 All Questions

View all questions & answers for the 156-215.80 exam

Exam 156-215.80 topic 1 question 405 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 405
Topic #: 1
[All 156-215.80 Questions]

Which statement is TRUE of anti-spoofing?

  • A. Anti-spoofing is not needed when IPS software blade is enabled
  • B. It is more secure to create anti-spoofing groups manually
  • C. It is BEST Practice to have anti-spoofing groups in sync with the routing table
  • D. With dynamic routing enabled, anti-spoofing groups are updated automatically whenever there is a routing change
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Hernan_Mella
10 months, 3 weeks ago
I think is use the new capability "Network defined by routes"
upvoted 1 times
...
faisal12
1 year ago
Been working with CP firewalls, C is the correct answer..
upvoted 2 times
...
saicosocial
2 years, 3 months ago
I'm not pretty sure that C is the correct one... I can't find any antispoofing official best practices anyway... I would D is BEST practice than the C. Can anyone contradict me?
upvoted 2 times
saicosocial
2 years, 3 months ago
Sorry I meant B is the best choice, not D
upvoted 1 times
...
mauchi
2 years, 3 months ago
I believe that the fact that the anti-spoofing groups are in sync with the routing table implies that when a new route for a new subnet is added, it automatically will be updated to an anti-spoofing group, without any manual work, which you may forget doing by yourself. That's why C is more secure in my eyes
upvoted 2 times
saicosocial
2 years, 3 months ago
I can be understand your point of view and I'm agree with you. But here we are talking about BEST PRACTICE. In the security enviroment the manual control on this kind of defenses should be the best way theoretically. If the network group needs to implement a new subnet, you have just to upgrade manually the anti-spoofing configuration, and it seems a good effort/security compromise. Anyway... It seems impossibile to know what CP thinks about this XD
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...