156-215.80 · Question #228
Your boss wants you to closely monitor an employee suspected of transferring company secrets to the competition. The IT department discovered the suspect installed a WinSCP client in order to use…
The correct answer is A. Use SmartView Tracker to follow his actions by filtering log entries that feature the WinSCP. SmartView Tracker is the correct Check Point tool for investigating a specific user's traffic because it provides detailed, filterable log records of all connections passing through the Security Gateway.
Question
Your boss wants you to closely monitor an employee suspected of transferring company secrets to the competition. The IT department discovered the suspect installed a WinSCP client in order to use encrypted communication. Which of the following methods is BEST to accomplish this task?
Options
- AUse SmartView Tracker to follow his actions by filtering log entries that feature the WinSCP
- BUse SmartDashboard to add a rule in the firewall Rule Base that matches his IP address, and
- CWatch his IP in SmartView Monitor by setting an alert action to any packet that matches your
- DSend the suspect an email with a keylogging Trojan attached, to get direct information about his
How the community answered
(33 responses)- A85% (28)
- B3% (1)
- C9% (3)
- D3% (1)
Why each option
SmartView Tracker is the correct Check Point tool for investigating a specific user's traffic because it provides detailed, filterable log records of all connections passing through the Security Gateway.
SmartView Tracker records all connections transiting the Security Gateway and exposes powerful filtering by source IP, user identity, application, and service, making it possible to isolate and review all log entries associated with the suspect's WinSCP sessions. It provides forensic-quality evidence of network activity without requiring firewall rule changes or additional software deployment. This is the standard investigative method for user activity auditing in a Check Point environment.
SmartDashboard is a policy configuration tool used to build and manage the firewall Rule Base, not to monitor or investigate individual user traffic activity.
SmartView Monitor provides real-time network performance and bandwidth graphs, and is not designed for per-user forensic log review or detailed connection auditing.
Deploying a keylogging Trojan is illegal, violates computer fraud statutes and corporate policy, and constitutes unauthorized access to the employee's system regardless of investigative intent.
Concept tested: Check Point SmartView Tracker for user activity log investigation
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_Logging_and_Monitoring/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.