Free 156-585 Exam Braindumps (page: 3)

Page 2 of 19

Where do Protocol parsers register themselves for IPS?

  1. Passive Streaming Library
  2. Other handlers register to Protocol parser
  3. Protections database
  4. Context Management Infrastructure

Answer(s): A



Which command do you need to execute to insert fw monitor after TCP streaming (out) in the outbound chain using absolute position? Given the chain was 1ffffe0, choose the correct answer.

  1. fw monitor ­po -0x1ffffe0
  2. fw monitor ­p0 ox1ffffe0
  3. fw monitor ­po 1ffffe0
  4. fw monitor ­p0 ­ox1ffffe0

Answer(s): A

Explanation:

https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Perform anceTuning_AdminGuide/Content/Topics-PTG/CLI/fw-monitor.htm



What are the four ways to insert an FW Monitor into the firewallkernel chain?

  1. Relative position using location, relativepositionusing alias, absolute position, all positions
  2. Absolute position using location, absolute position using alias, relative position, all positions
  3. Absolute position using location, relative position using alias, general position, all positions
  4. Relative position using geolocation relative position using inertial navigation, absolute position all positions

Answer(s): D



Rules within the Threat Prevention policy use the Malware database and network objects. Which directory is used for the Malware database?

  1. $FWDIR/conf/install_manager_tmp/ANTIMALWARE/conf/
  2. $CPDIR/conf/install_manager_lmp/ANTIMALWARE/conf/
  3. $FWDlR/conf/install_firewall_imp/ANTIMALWARE/conf/
  4. $FWDlR/log/install_manager_tmp/ANTIMALWARBlog?

Answer(s): D






Post your Comments and Discuss Checkpoint 156-585 exam with other Community members:

156-585 Discussions & Posts