nerdexam
Check_Point

156-215.75 · Question #503

John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus, the…

The correct answer is D. The firewall admin should install the Security Policy. See the full explanation below for the reasoning.

Question

John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus, the gateway policy permits access only from John's desktop which is assigned a static IP address 10.0.0.19. John received a laptop and wants to access the HR Web Server from anywhere in the organization. The IT department gave the laptop a static IP address, but that limits him to operating it only from his desk. The current Rule Base contains a rule that lets John Adams access the HR Web Server from his laptop with a static IP (10.0.0.19). He wants to move around the organization and continue to have access to the HR Web Server. To make this scenario work, the IT administrator: 1) Enables Identity Awareness on a gateway, selects AD Query as one of the Identity Sources installs the policy. 2) Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web Server from any machine and from any location. John plugged in his laptop to the network on a different network segment and he is not able to connect. How does he solve this problem?

Options

  • AJohn should lock and unlock the computer
  • BInvestigate this as a network connectivity issue
  • CJohn should install the Identity Awareness Agent
  • DThe firewall admin should install the Security Policy

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    8% (2)
  • C
    4% (1)
  • D
    76% (19)

Community Discussion

8
Yusuf A.Yusuf A.Feb 13, 2026

The answer is D, the firewall admin needs to reinstall the Security Policy after adding the access role object, because without pushing the updated policy to the gateway the new Identity Awareness rules never actually take effect on the enforcing device. AD Query and access roles do nothing in the real world until that policy install pushes the changes down.

11
Prof. SaraProf. SaraFeb 16, 2026

Almost picked C, then caught that the new rule was never installed.

4
Dejan C.Dejan C.Feb 17, 2026

Right, and that trap is exactly why you verify with fw stat on the gateway itself before trusting the green checkmark in SmartConsole, because the GUI shows what was last pushed, not what is currently active in the kernel tables.

0
Lena V.Lena V.Feb 6, 2026

I initially thought C was the answer since John is on a new segment and an agent would help identify him, but then I remembered that step 2 says the admin already added the access role to the Rule Base, and a policy change does not take effect until the admin pushes it to the gateway. D is correct because without installing the updated Security Policy on the gateway, the new rule allowing John to roam by identity simply does not exist on the enforcing device yet.

3
Carlos M.Carlos M.Jan 23, 2026

D is right. After the admin adds the access role object to the Rule Base, the updated Security Policy has to be pushed to the gateway before it takes effect, so John will stay blocked until that install happens.

2
Yusuf A.Yusuf A.Jan 25, 2026

Right, and the senior I shadow always reminds me that the admin also has to publish the session in SmartConsole first, because if those changes are still in a private session they cannot even be selected for the policy install to begin.

0
Dejan C.Dejan C.Feb 2, 2026

Thought C first, but AD Query needs a fresh policy push after role config, so D.

2
Prof. SaraProf. SaraFeb 4, 2026

Solid call, and worth anchoring this to the GP processing order mnemonic "Role Before Refresh" because the exam consistently uses C as a distractor for anyone who forgets that AD query results reflect the current policy state at pull time, not the pending role config.

0
Full 156-215.75 Practice