156-215.80 · Question #186
John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus…
The correct answer is B. The firewall admin should install the Security Policy. After enabling Identity Awareness and updating the Rule Base to reference identity objects, the Security Policy must be installed on the gateway before any new rules take effect.
Question
Options
- AJohn should install the identity Awareness Agent
- BThe firewall admin should install the Security Policy
- CJohn should lock and unlock the computer
- DInvestigate this as a network connectivity issue
How the community answered
(22 responses)- B86% (19)
- C5% (1)
- D9% (2)
Why each option
After enabling Identity Awareness and updating the Rule Base to reference identity objects, the Security Policy must be installed on the gateway before any new rules take effect.
Installing the Identity Awareness Agent on John's laptop is a client-side component that assists with identity acquisition, but it is not the required next step after the admin has already configured Identity Awareness and the Rule Base.
In Check Point, changes made to the Rule Base in SmartDashboard or SmartConsole do not become active on the enforcing gateway until the Security Policy is compiled and pushed via 'Install Policy.' Without this step, the gateway continues enforcing the previously installed policy, so John's identity-based access rule would have no effect. Installing the Security Policy propagates all Rule Base changes, including Identity Awareness rules, to the gateway.
Locking and unlocking the computer is a Windows session action and has no bearing on whether the gateway enforces an identity-based network access rule.
The scenario describes a deliberate policy configuration task following an Identity Awareness deployment, not an underlying network connectivity problem that requires investigation.
Concept tested: Check Point Identity Awareness policy installation requirement
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_IdentityAwareness_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.