156-215.80 · Question #194
What happens if the identity of a user is known?
The correct answer is D. If the user credentials match an Access Role, the rule is applied and traffic is accepted or. In Check Point Identity Awareness, when a user's identity is known and matches an Access Role in a policy rule, that rule is applied and the traffic is accepted or dropped per the rule action.
Question
What happens if the identity of a user is known?
Options
- AIf the user credentials do not match an Access Role, the system displays the Captive Portal.
- BIf the user credentials do not match an Access Role, the system displays a sandbox.
- CIf the user credentials do not match an Access Role, the traffic is automatically dropped.
- DIf the user credentials match an Access Role, the rule is applied and traffic is accepted or
How the community answered
(31 responses)- B3% (1)
- C3% (1)
- D94% (29)
Why each option
In Check Point Identity Awareness, when a user's identity is known and matches an Access Role in a policy rule, that rule is applied and the traffic is accepted or dropped per the rule action.
Captive Portal is triggered when a user's identity is unknown, not when a known identity fails to match a specific Access Role.
Sandbox (threat emulation) is a separate threat prevention feature and is not invoked based on Access Role match failures.
A failure to match an Access Role does not automatically drop traffic; subsequent rules and the default policy action still apply.
Once Identity Awareness resolves a user's identity, the policy engine evaluates that identity against Access Roles defined in security rules. If the user matches an Access Role in a rule, the rule's action - accept, drop, or other - is enforced. This is the core mechanism by which identity-based access control is achieved in Check Point.
Concept tested: Identity Awareness Access Role enforcement behavior
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Default.htm
Topics
Community Discussion
No community discussion yet for this question.