Question 1
A financial services company is experiencing intermittent connectivity loss to a critical trading partner's API. The connection uses HTTPS over a Site-to-Site VPN. Initial checks show the VPN tunnel is stable. The administrator suspects a specific Threat Prevention blade is incorrectly flagging legitimate traffic. To get the most detailed, real-time information about which specific protection within the IPS blade is causing the drop, what is the most appropriate debug command to run on the Security Gateway?
Answer and explanation
Correct answer: C
The command fw ctl debug -m IPS + all enables the most comprehensive debug flags specifically for the IPS module. This will provide granular details in the kernel debug output (fw ctl kdebug) about IPS inspection, including which specific protection is being triggered and why. fw ctl zdebug drop is useful for seeing drops but may not specify which IPS protection caused it. fw monitor shows packet flow but lacks the internal processing details of the IPS blade. vpn debug is irrelevant as the tunnel itself is stable.