nerdexam
Check_Point

156-215.80 · Question #186

John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus…

The correct answer is B. The firewall admin should install the Security Policy. After enabling Identity Awareness and updating the Rule Base to reference identity objects, the Security Policy must be installed on the gateway before any new rules take effect.

Security Policy Management

Question

John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus, gateway policy permits access only from Join's desktop which is assigned an IP address 10.0.0.19 via DHCP. John received a laptop and wants to access the HR Web Server from anywhere in the organization. The IT department gave the laptop a static IP address, but the limits him to operating it only from his desk. The current Rule Base contains a rule that lets John Adams access the HR Web Server from his laptop. He wants to move around the organization and continue to have access to the HR Web Server. To make this scenario work, the IT administrator: 1) Enables Identity Awareness on a gateway, selects AD Query as one of the Identity Sources. 2) Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web Server from any machine and from any location. John plugged in his laptop to the network on a different network segment and he is not able to connect. How does he solve this problem?

Options

  • AJohn should install the identity Awareness Agent
  • BThe firewall admin should install the Security Policy
  • CJohn should lock and unlock the computer
  • DInvestigate this as a network connectivity issue

How the community answered

(22 responses)
  • B
    86% (19)
  • C
    5% (1)
  • D
    9% (2)

Why each option

After enabling Identity Awareness and updating the Rule Base to reference identity objects, the Security Policy must be installed on the gateway before any new rules take effect.

AJohn should install the identity Awareness Agent

Installing the Identity Awareness Agent on John's laptop is a client-side component that assists with identity acquisition, but it is not the required next step after the admin has already configured Identity Awareness and the Rule Base.

BThe firewall admin should install the Security PolicyCorrect

In Check Point, changes made to the Rule Base in SmartDashboard or SmartConsole do not become active on the enforcing gateway until the Security Policy is compiled and pushed via 'Install Policy.' Without this step, the gateway continues enforcing the previously installed policy, so John's identity-based access rule would have no effect. Installing the Security Policy propagates all Rule Base changes, including Identity Awareness rules, to the gateway.

CJohn should lock and unlock the computer

Locking and unlocking the computer is a Windows session action and has no bearing on whether the gateway enforces an identity-based network access rule.

DInvestigate this as a network connectivity issue

The scenario describes a deliberate policy configuration task following an Identity Awareness deployment, not an underlying network connectivity problem that requires investigation.

Concept tested: Check Point Identity Awareness policy installation requirement

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_IdentityAwareness_AdminGuide/html_frameset.htm

Topics

#Security Policy installation#Identity Awareness#access rules#policy push

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice