156-215.80 · Question #204
Which of the following is NOT defined by an Access Role object?
The correct answer is D. Source Server. Access Role objects in Check Point Identity Awareness define source networks, machines, and users - not servers, which are destination objects.
Question
Which of the following is NOT defined by an Access Role object?
Options
- ASource Network
- BSource Machine
- CSource User
- DSource Server
How the community answered
(30 responses)- A7% (2)
- C3% (1)
- D90% (27)
Why each option
Access Role objects in Check Point Identity Awareness define source networks, machines, and users - not servers, which are destination objects.
Source Network is a valid Access Role component, allowing the role to be scoped to traffic originating from one or more specific IP network ranges.
Source Machine is a valid Access Role component, enabling machine-identity enforcement by specifying which registered endpoint devices are included in the role.
Source User is a valid and primary Access Role component, specifying which Active Directory users or user groups the identity-aware policy applies to.
Check Point Access Role objects are identity-aware constructs used in the source column of Access Control Policy rules, and their valid components are limited to Networks, Machines, and Users. 'Source Server' is not a valid Access Role attribute because servers are typically destination resources in a policy, not identity-based source principals. Attempting to define a server as a source access role component is conceptually incorrect within the Identity Awareness framework.
Concept tested: Check Point Identity Awareness Access Role object valid attributes
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IAG/Access-Roles.htm
Topics
Community Discussion
No community discussion yet for this question.