nerdexam
Check_Point

156-215.80 · Question #149

Provide very wide coverage for all products and protocols, with noticeable performance impact. How could you tune the profile in order to lower the CPU load still maintaining security at good…

The correct answer is B. Set the Performance Impact to Medium or lower. In Check Point Threat Prevention profiles, the Performance Impact setting directly controls the tradeoff between inspection breadth and CPU resource consumption.

Security Policy Management

Question

Provide very wide coverage for all products and protocols, with noticeable performance impact. How could you tune the profile in order to lower the CPU load still maintaining security at good level?Select the BEST answer.

Exhibit

156-215.80 question #149 exhibit

Options

  • ASet High Confidence to Low and Low Confidence to Inactive.
  • BSet the Performance Impact to Medium or lower.
  • CThe problem is not with the Threat Prevention Profile. Consider adding more memory to the
  • DSet the Performance Impact to Very Low Confidence to Prevent.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    75% (18)
  • C
    8% (2)
  • D
    13% (3)

Why each option

In Check Point Threat Prevention profiles, the Performance Impact setting directly controls the tradeoff between inspection breadth and CPU resource consumption.

ASet High Confidence to Low and Low Confidence to Inactive.

Setting High Confidence to Low changes detection confidence thresholds and would not directly reduce CPU load - it alters what actions are taken on detections, not the depth of inspection.

BSet the Performance Impact to Medium or lower.Correct

The Threat Prevention profile's Performance Impact setting determines how aggressively the engine inspects traffic - a setting of Medium or lower restricts the inspection scope to reduce CPU overhead. This directly addresses the 'noticeable performance impact' caused by the wide-coverage profile configuration while still maintaining meaningful threat detection for high-confidence signatures.

CThe problem is not with the Threat Prevention Profile. Consider adding more memory to the

The performance problem is explicitly caused by the Threat Prevention profile's inspection scope settings, not insufficient memory - adding RAM does not resolve CPU-bound inspection overhead.

DSet the Performance Impact to Very Low Confidence to Prevent.

This option conflates the Performance Impact setting with the Confidence Level action setting into a nonsensical configuration that does not represent a valid or effective tuning option.

Concept tested: Check Point Threat Prevention profile performance impact tuning

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPreventionAdminGuide/Content/Topics-TPG/Profiles.htm

Topics

#threat prevention#performance tuning#CPU optimization#IPS profile

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice