156-215.80 · Question #234
You find a suspicious connection from a problematic host. You decide that you want to block everything from that whole network, not just the problematic host. You want to block this for an hour…
The correct answer is C. Create a Suspicious Activity Rule in Smart Monitor. Suspicious Activity Rules in SmartView Monitor allow administrators to create temporary, time-limited blocks on hosts or networks without modifying the permanent Rule Base.
Question
You find a suspicious connection from a problematic host. You decide that you want to block everything from that whole network, not just the problematic host. You want to block this for an hour while you investigate further, but you do not want to add any rules to the Rule Base. How do you achieve this?
Options
- AUse dbedit to script the addition of a rule directly into the Rule Bases_5_0.fws configuration file.
- BSelect Block intruder from the Tools menu in SmartView Tracker.
- CCreate a Suspicious Activity Rule in Smart Monitor.
- DAdd a temporary rule using SmartDashboard and select hide rule.
How the community answered
(37 responses)- A5% (2)
- B3% (1)
- C78% (29)
- D14% (5)
Why each option
Suspicious Activity Rules in SmartView Monitor allow administrators to create temporary, time-limited blocks on hosts or networks without modifying the permanent Rule Base.
Directly editing Rule_Bases_5_0.fws with dbedit is unsupported and dangerous - it bypasses management server validation and can corrupt the policy database.
Block Intruder in SmartView Tracker blocks a single specific source IP address, not an entire network subnet, and does not support time-limited expiration.
SmartView Monitor's Suspicious Activity Rules (SAR) feature lets an administrator define a temporary blocking rule scoped to a specific source, destination, or subnet, with a configurable expiration time such as one hour. Because SARs are applied dynamically by the gateway and are not written to the policy Rule Base, no rule is permanently added and no policy push is required. This is the correct method for rapid, time-bounded blocking during an active investigation.
Adding a rule via SmartDashboard and hiding it still writes a permanent rule into the Rule Base, which violates the stated requirement of not adding any rules to the Rule Base.
Concept tested: SmartView Monitor Suspicious Activity Rules for temporary blocking
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_SmartViewMonitor_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.