156-215.80 · Question #197
You are conducting a security audit. While reviewing configuration files and logs, you notice logs accepting POP3 traffic, but you do not see a rule allowing POP3 traffic in the Rule Base. Which of…
The correct answer is C. The POP3 rule is hidden. In Check Point, hidden rules are still enforced by the gateway but do not appear in the standard Rule Base view, making them invisible during a normal audit.
Question
You are conducting a security audit. While reviewing configuration files and logs, you notice logs accepting POP3 traffic, but you do not see a rule allowing POP3 traffic in the Rule Base. Which of the following is the most likely cause?
Options
- AThe POP3 rule is disabled.
- BPOP3 is accepted in Global Properties.
- CThe POP3 rule is hidden.
- DPOP3 is one of 3 services (POP3, IMAP, and SMTP) accepted by the default mail object in R77.
How the community answered
(58 responses)- A3% (2)
- B19% (11)
- C71% (41)
- D7% (4)
Why each option
In Check Point, hidden rules are still enforced by the gateway but do not appear in the standard Rule Base view, making them invisible during a normal audit.
A disabled rule is not enforced by the gateway at all, so it would not cause POP3 traffic to be accepted and logged.
Check Point Global Properties does not include a default acceptance of POP3 traffic; it controls features like NAT, authentication, and VPN settings rather than application-layer mail protocols.
Hidden rules in Check Point SmartDashboard exist as active, enforced policy entries that the gateway processes normally. They are deliberately concealed from the standard Rule Base display using the 'Hide' feature, which explains why POP3 traffic is logged and accepted despite no visible rule. An auditor must explicitly choose to show hidden rules to discover them.
The default mail object in R77 does not automatically accept POP3 traffic on its own - it requires an explicit rule in the Rule Base referencing it to permit that traffic.
Concept tested: Check Point hidden rules in Rule Base
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_WebAdmin/Content/Topics/Hidden_Rules.htm
Topics
Community Discussion
No community discussion yet for this question.