{"id":21593,"date":"2026-09-25T06:26:27","date_gmt":"2026-09-25T06:26:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21593"},"modified":"2026-09-25T06:26:27","modified_gmt":"2026-09-25T06:26:27","slug":"checkpoint-156-536-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/checkpoint-156-536-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Checkpoint 156-536 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/156-536-exam-dumps\"><b>Checkpoint 156-536 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 121. Which rule controls traffic reaching an endpoint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Outbound rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inbound rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deployment rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compliance rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Inbound rule<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Inbound Firewall rules control network traffic that attempts to reach the endpoint computer. Harmony Endpoint Firewall evaluates connection information such as IP addresses, ports, services, and protocols before allowing or blocking the traffic. Outbound rules perform the opposite function by controlling connections initiated from the endpoint. Separating inbound and outbound policy allows administrators to define different security requirements depending on traffic direction. For example, an endpoint might be allowed to initiate web connections while unsolicited inbound traffic remains blocked.<\/span><\/p>\n<p><b>Question 122. What is the default outbound Firewall rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block all outbound<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow DNS only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow Trusted Zone only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow any outbound<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Allow any outbound<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The default outbound rule in the Harmony Endpoint Firewall policy is <\/span><span style=\"font-weight: 400;\">Allow any outbound<\/span><span style=\"font-weight: 400;\">. Its destination is Any, its service is Any, and its action is Allow. No tracking is configured by default for this rule. Administrators can replace or modify this behavior if the organization requires tighter control over endpoint-initiated connections. Check Point also provides an alternative predefined outbound action that allows all traffic to trusted zones while permitting common internet protocols to the Internet Zone.<\/span><\/p>\n<p><b>Question 123. What belongs to the Internet Zone?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Objects not in the Trusted Zone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Domain controllers only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Loopback addresses only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Managed laptops only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Objects not in the Trusted Zone<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Any network location that is not included in the Trusted Zone automatically belongs to the Internet Zone. Access Zones therefore divide network destinations into trusted and untrusted categories that the Firewall policy can reference. Administrators should carefully define the Trusted Zone so only required corporate resources and approved network objects receive trusted treatment. The Internet Zone acts as the automatic classification for everything else, simplifying policy design because administrators do not need to manually list every untrusted network location.<\/span><\/p>\n<p><b>Question 124. How many Trusted Zones can one endpoint enforce?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unlimited<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Two<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Four<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. One<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A computer can enforce only one Trusted Zone at a time. If several Access Zones rules apply to the same computer and more than one Trusted Zone would otherwise match, Check Point states that only the last applicable Trusted Zone is enforced. Administrators should therefore design Access Zones rules carefully so overlapping assignments do not produce unexpected results. Understanding this behavior is particularly important in environments where different endpoint groups require distinct definitions of trusted corporate networks and resources.<\/span><\/p>\n<p><b>Question 125. Which address is trusted by default?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">8.8.8.8<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">0.0.0.0<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">255.255.255.255<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">127.0.0.1<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. <\/b><b>127.0.0.1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The LocalMachine_Loopback object, representing <\/span><span style=\"font-weight: 400;\">127.0.0.1<\/span><span style=\"font-weight: 400;\">, is included in the initial Trusted Zone. The endpoint must always be able to communicate with its own loopback interface because applications frequently use it for local inter-process communication and services. Check Point warns that users should not run software that changes or hides the local loopback address, such as some personal proxy applications. Keeping the loopback address trusted ensures that local endpoint communications required by applications can continue to function correctly.<\/span><\/p>\n<p><b>Question 126. Which object is initially in the Trusted Zone?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DMZ_Only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All_Internet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> External_Hosts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unknown_Networks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. All_Internet<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The initial Access Zones policy includes the <\/span><span style=\"font-weight: 400;\">All_Internet<\/span><span style=\"font-weight: 400;\"> object in the Trusted Zone. This object represents all legal IP addresses. However, the Access Zones policy is not enforced by itself; it provides zone definitions that are used by Firewall policy. Administrators are expected to adjust the Trusted Zone according to organizational security requirements rather than assume the initial configuration is appropriate for production. Check Point specifically recommends including only those network objects with which endpoint programs genuinely need to interact.<\/span><\/p>\n<p><b>Question 127. How are Firewall rules evaluated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Top to bottom<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Randomly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bottom to top<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alphabetically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Top to bottom<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Harmony Endpoint Firewall rules are enforced from the top of the Rule Base toward the bottom. Rule priority is therefore important because traffic is evaluated according to rule sequence. A more specific rule usually needs to appear before a broader rule that could otherwise match the same connection. The final rule is typically a Cleanup Rule that blocks traffic not explicitly accepted earlier. Correct rule ordering prevents broad allow or block rules from unintentionally overriding more specific security requirements.<\/span><\/p>\n<p><b>Question 128. Which rule is usually last?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow PPTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow DHCP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cleanup Rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Cleanup Rule<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Cleanup Rule is normally placed at the end of the Firewall Rule Base. Its purpose is to handle traffic that did not match any previous rule. In the default Harmony Endpoint inbound configuration, the Cleanup Rule matches Any source and Any service, blocks the traffic, and logs the event. This follows the common security principle of explicitly allowing necessary traffic and then denying everything else that remains unmatched. Administrators should therefore be careful when adding rules above the Cleanup Rule because only earlier matches can bypass its final block action.<\/span><\/p>\n<p><b>Question 129. What does the default inbound Cleanup Rule do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Blocks and logs traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allows all traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Blocks without logging<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alerts without blocking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Blocks and logs traffic<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The default inbound Cleanup Rule uses Any as the source, Any as the service, Block as the action, and Log as the tracking setting. It therefore blocks inbound traffic that failed to match an earlier allow rule and records the enforcement event. This provides both security and visibility because unauthorized traffic is denied while administrators can still review what was blocked. Cleanup logging is particularly useful during policy tuning because it shows which connections are being rejected by the final rule.<\/span><\/p>\n<p><b>Question 130. What does Allow Trusted Zone permit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PPTP only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any service from the Trusted Zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Any service from the Trusted Zone<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The default <\/span><span style=\"font-weight: 400;\">Allow Trusted Zone<\/span><span style=\"font-weight: 400;\"> inbound rule uses Trusted_Zone as its source, Any as its service, and Allow as its action. This means incoming traffic from objects classified as trusted can reach the endpoint regardless of service unless a customized policy changes that behavior. Because this default is broad, administrators should define Trusted Zone membership carefully. Adding unnecessary networks to the Trusted Zone can indirectly expand which systems are permitted to initiate inbound communications with protected endpoints.<\/span><\/p>\n<p><b>Question 131. What does Allow IP obtaining permit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTPS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSH<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP-related services<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SMTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. DHCP-related services<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The default <\/span><span style=\"font-weight: 400;\">Allow IP obtaining<\/span><span style=\"font-weight: 400;\"> inbound rule permits DHCP-related services from the Internet Zone. Check Point lists services such as <\/span><span style=\"font-weight: 400;\">bootp<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">dhcp-relay<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">dhcp-req-local<\/span><span style=\"font-weight: 400;\">, and <\/span><span style=\"font-weight: 400;\">dhcp-rep-local<\/span><span style=\"font-weight: 400;\">. These services allow the endpoint to obtain and maintain network addressing even when the surrounding network is classified as untrusted. Without appropriate DHCP communication, endpoints may fail to receive IP configuration and lose network connectivity. The default rule therefore permits essential address-assignment traffic while other unsolicited inbound connections remain subject to additional rules and the Cleanup Rule.<\/span><\/p>\n<p><b>Question 132. Which protocol appears in the default Allow PPTP rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSH<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> GRE<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SMTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. GRE<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The default <\/span><span style=\"font-weight: 400;\">Allow PPTP<\/span><span style=\"font-weight: 400;\"> inbound rule includes GRE along with <\/span><span style=\"font-weight: 400;\">pptp-tcp<\/span><span style=\"font-weight: 400;\"> and L2TP services. These protocols support VPN-related connectivity. The rule applies to traffic from the Internet Zone and permits the listed services. Administrators should understand why such predefined rules exist before modifying or deleting them because removing required VPN-related traffic can interrupt remote connectivity. At the same time, organizations that do not require these protocols may choose to tailor the Firewall Rule Base according to their own security policy.<\/span><\/p>\n<p><b>Question 133. Why is inbound Destination fixed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The destination is always the endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The destination is always the gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The destination is always DNS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The destination is always the Internet Zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The destination is always the endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For inbound Firewall traffic, the destination is always the protected endpoint computer. Because of this, the inbound rule structure does not require administrators to choose arbitrary remote destination objects. Instead, administrators mainly define where the incoming traffic originates, which service it uses, and what action should be taken. This simplifies endpoint Firewall policy by treating the local computer as the fixed inbound destination. The same concept is reversed for outbound traffic, where the local endpoint is the fixed source.<\/span><\/p>\n<p><b>Question 134. Why is outbound Source fixed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic originates from the endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic originates from DNS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic originates from the Internet Zone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic originates from the gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Traffic originates from the endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For outbound Firewall rules, the source of the traffic is always the endpoint computer or the applicable local computer, user, or group. Administrators therefore focus on the outbound destination, service, action, and tracking configuration. Inbound rules work in the opposite direction because the endpoint is always the destination. Understanding these fixed perspectives makes the Firewall Rule Base easier to interpret and helps prevent administrators from confusing remote network objects with the local endpoint being protected.<\/span><\/p>\n<p><b>Question 135. What does Track = Log do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Displays only a popup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Records enforcement in the Client Log Viewer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Blocks all traffic automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables tracking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Records enforcement in the Client Log Viewer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a Firewall rule uses the Log tracking action, rule enforcement is recorded in the Endpoint Security Client Log Viewer. This gives administrators visibility into connections that matched the rule without necessarily presenting a message to the endpoint user. Logging is useful when troubleshooting connectivity or confirming whether policy behaves as expected. Check Point distinguishes Log from Alert, which both records the event and displays a user message. None creates neither log entries nor alert messages for matching traffic.<\/span><\/p>\n<p><b>Question 136. What does Track = Alert do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Records silently only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allows without tracking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shows a message and records the event<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes the rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Shows a message and records the event<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Alert tracking action both displays a message on the endpoint computer and records the Firewall rule enforcement in the Endpoint Security Client Log Viewer. This is more visible than Log, which records the event without displaying an alert message. Administrators should use alerts selectively because frequent user messages can become distracting. Check Point also requires the relevant Client Settings options to permit Network Protection alerts when Firewall alerts are expected to appear on endpoint computers.<\/span><\/p>\n<p><b>Question 137. What does Track = None create?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only an alert<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No log or alert<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a log<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A forensic report<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. No log or alert<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When tracking is set to None, the matching Firewall traffic is enforced according to the rule&#8217;s action, but no log or user alert is generated. This setting can reduce unnecessary logging for routine high-volume traffic where administrators do not need additional visibility. However, using None on important security rules may make troubleshooting or incident review more difficult because matching events are not recorded through Firewall tracking. Administrators should therefore decide carefully which rules require Log, Alert, or no tracking.<\/span><\/p>\n<p><b>Question 138. What can a Firewall Source or Destination reference?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only usernames<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only IP addresses<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only domain controllers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network objects or security zones<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Network objects or security zones<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall Source and Destination fields can reference network objects defined through Access Zones as well as Trusted or Internet Zone objects. Depending on the rule direction, one side represents the local endpoint while the other identifies the relevant remote network location. Check Point supports zone definitions based on object types such as hosts, networks, network groups, domains, and address ranges. This gives administrators flexibility to create policies based on meaningful network structures rather than writing every rule with individual IP addresses.<\/span><\/p>\n<p><b>Question 139. What should be configured before Firewall policy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full Disk Encryption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Appscan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Zones<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat Extraction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Access Zones<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Check Point recommends configuring Access Zones before configuring the Endpoint Firewall because Firewall rules can reference the Trusted Zone and Internet Zone. Access Zones determine which network locations are trusted and automatically place all other locations into the Internet Zone. Defining these zones first gives Firewall rules meaningful network context. If the zone definitions are inaccurate or overly broad, Firewall behavior can also become broader than intended, so Access Zones should be planned carefully before enforcement rules are finalized.<\/span><\/p>\n<p><b>Question 140. What is a good Trusted Zone practice?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Include only required trusted network objects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust every IP address permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Add all unknown networks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable zone classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Include only required trusted network objects<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Trusted Zone should include only network objects that endpoint programs genuinely need to interact with as trusted resources. Check Point specifically recommends limiting membership and provides examples such as management servers, domain controllers, DNS servers, file servers, print servers, corporate WANs, VPN gateway ranges, and required local subnets. Overly broad Trusted Zones weaken Firewall segmentation because rules such as Allow Trusted Zone may permit extensive inbound communication. A carefully scoped Trusted Zone supports least-privilege network access while preserving required business connectivity.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps. Question 121. Which rule controls traffic reaching an endpoint? Outbound rule Inbound rule Deployment rule Compliance rule Correct Answer: 2. Inbound rule Explanation: Inbound Firewall rules control network traffic that attempts to reach the endpoint computer. Harmony Endpoint Firewall evaluates connection information such as IP [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21593"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21593"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21593\/revisions"}],"predecessor-version":[{"id":21594,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21593\/revisions\/21594"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}