What is the benefit of “tw monitor” over “tcpdump”?
A.
“fw monitor” reveals Layer 2 information, while “tcpdump” acts at Layer 3.
B.
“fw monitor” is also available for 64-Bit operating systems.
C.
With “fw monitor”, you can see the inspection points, which cannot be seen in “tcpdump”
D.
“fw monitor” can be used from the CLI of the Management Server to collect information from multiple gateways.
The Answer Is:
C
This question includes an explanation.
Explanation:
The benefit of fw monitor over tcpdump is that with fw monitor, you can see the inspection points, which cannot be seen in tcpdump. Inspection points are the locations in the firewall kernel where packets are inspected by the security policy and other software blades. Fw monitor allows you to capture packets at different inspection points and see how they are processed by the firewall. Tcpdump, on the other hand, is a generic packet capture tool that only shows the packets as they enter or leave the network interface. References: Check Point Security Expert R81 Course, fw monitor, tcpdump
156-315.81 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"