nerdexam
Check_Point

156-215.80 · Question #226

What must a Security Administrator do to comply with a management requirement to log all traffic accepted through the perimeter Security Gateway?

The correct answer is A. In Global Properties > Reporting Tools check the box Enable tracking all rules (including rules. To log all accepted traffic including implied rules through a Check Point Security Gateway, the administrator must enable the global tracking option in Global Properties rather than modifying individual gateway objects.

Monitoring and Reporting

Question

What must a Security Administrator do to comply with a management requirement to log all traffic accepted through the perimeter Security Gateway?

Options

  • AIn Global Properties > Reporting Tools check the box Enable tracking all rules (including rules
  • BInstall the View Implicit Rules package using SmartUpdate.
  • CDefine two log servers on the R77 Gateway object. Lof Implied Rules on the first log server.
  • DCheck the Log Implied Rules Globally box on the R77 Gateway object.

How the community answered

(49 responses)
  • A
    82% (40)
  • B
    12% (6)
  • C
    4% (2)
  • D
    2% (1)

Why each option

To log all accepted traffic including implied rules through a Check Point Security Gateway, the administrator must enable the global tracking option in Global Properties rather than modifying individual gateway objects.

AIn Global Properties > Reporting Tools check the box Enable tracking all rules (including rulesCorrect

Check Point implied rules (covering traffic such as anti-spoofing accepts and default control connections) operate outside the explicit Rule Base and do not generate logs by default. Enabling 'Enable tracking all rules (including rules with Track set to None)' in Global Properties - Reporting Tools forces logging for every matched rule, satisfying the management requirement to capture a complete audit trail of all accepted traffic. This is the only mechanism that uniformly applies to both explicit and implied rule matches.

BInstall the View Implicit Rules package using SmartUpdate.

SmartUpdate is a software and license management tool used to push updates to gateways, and has no capability to configure traffic logging behavior.

CDefine two log servers on the R77 Gateway object. Lof Implied Rules on the first log server.

Configuring multiple log servers on a gateway object controls log destination redundancy and failover, not whether implied rules or all accepted traffic is logged.

DCheck the Log Implied Rules Globally box on the R77 Gateway object.

There is no 'Log Implied Rules Globally' checkbox on the individual R77 Gateway object; this setting is managed exclusively through Global Properties.

Concept tested: Check Point Global Properties implied rule logging configuration

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_SecurityManagement_AdminGuide/html_frameset.htm

Topics

#implied rules#log all traffic#Global Properties#traffic logging

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice