156-215.80 · Question #193
Anti-Spoofing is typically set up on which object type?
The correct answer is A. Security Gateway. Anti-spoofing is a feature configured on the Security Gateway object in Check Point, where interface topology is defined to detect and block forged source IP addresses.
Question
Anti-Spoofing is typically set up on which object type?
Options
- ASecurity Gateway
- BHost
- CSecurity Management object
- DNetwork
How the community answered
(19 responses)- A89% (17)
- C5% (1)
- D5% (1)
Why each option
Anti-spoofing is a feature configured on the Security Gateway object in Check Point, where interface topology is defined to detect and block forged source IP addresses.
Anti-spoofing is configured directly on the Security Gateway object in Check Point SmartConsole. Each gateway interface has a topology definition that specifies which networks are valid sources for that interface, allowing the gateway to drop packets arriving from unexpected directions. This enforcement must live on the gateway because it operates at the traffic inspection layer.
Host objects represent individual endpoints and have no interface topology settings required to enforce anti-spoofing.
The Security Management object controls policy distribution but does not inspect or enforce traffic-level protections like anti-spoofing.
Network objects define address ranges for use in policy rules but cannot independently enforce per-interface spoofing checks.
Concept tested: Check Point anti-spoofing configuration on Security Gateways
Source: https://support.checkpoint.com/results/sk/sk39245
Topics
Community Discussion
No community discussion yet for this question.