156-215.80 · Question #221
Which rule is responsible for the user authentication failure?
The correct answer is C. Rule 3. In a Check Point rulebase, rules are evaluated top-to-bottom and the first matching rule is applied; Rule 3 matches the user's traffic and applies a blocking action before any authentication rule can be reached.
Question
Which rule is responsible for the user authentication failure?
Exhibit
Options
- ARule 4
- BRule 6
- CRule 3
- DRule 5
How the community answered
(52 responses)- A25% (13)
- B13% (7)
- C56% (29)
- D6% (3)
Why each option
In a Check Point rulebase, rules are evaluated top-to-bottom and the first matching rule is applied; Rule 3 matches the user's traffic and applies a blocking action before any authentication rule can be reached.
Rule 4 is evaluated after Rule 3, so it is never reached for this traffic flow because the rulebase stops processing at the first matching rule.
Rule 6 appears later in the rulebase and is never evaluated because Rule 3 already matched and acted on the traffic.
Rule 3 is the first rule in the rulebase that matches the user's traffic and applies a Drop or Reject action, causing authentication to fail before the user can be challenged. In Check Point policy, the rulebase is evaluated sequentially, so a deny action in Rule 3 terminates further rule processing. This prevents the user from reaching any rule that would initiate an authentication challenge.
Rule 5 is below Rule 3 in the rulebase and is also never reached for this traffic due to first-match processing.
Concept tested: Check Point rulebase first-match order and authentication
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SMAG/Access-Control-Policies.htm
Topics
Community Discussion
No community discussion yet for this question.
