nerdexam
Check_Point

156-215.80 · Question #234

You find a suspicious connection from a problematic host. You decide that you want to block everything from that whole network, not just the problematic host. You want to block this for an hour…

The correct answer is C. Create a Suspicious Activity Rule in Smart Monitor. Suspicious Activity Rules in SmartView Monitor allow administrators to create temporary, time-limited blocks on hosts or networks without modifying the permanent Rule Base.

Monitoring and Reporting

Question

You find a suspicious connection from a problematic host. You decide that you want to block everything from that whole network, not just the problematic host. You want to block this for an hour while you investigate further, but you do not want to add any rules to the Rule Base. How do you achieve this?

Options

  • AUse dbedit to script the addition of a rule directly into the Rule Bases_5_0.fws configuration file.
  • BSelect Block intruder from the Tools menu in SmartView Tracker.
  • CCreate a Suspicious Activity Rule in Smart Monitor.
  • DAdd a temporary rule using SmartDashboard and select hide rule.

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    78% (29)
  • D
    14% (5)

Why each option

Suspicious Activity Rules in SmartView Monitor allow administrators to create temporary, time-limited blocks on hosts or networks without modifying the permanent Rule Base.

AUse dbedit to script the addition of a rule directly into the Rule Bases_5_0.fws configuration file.

Directly editing Rule_Bases_5_0.fws with dbedit is unsupported and dangerous - it bypasses management server validation and can corrupt the policy database.

BSelect Block intruder from the Tools menu in SmartView Tracker.

Block Intruder in SmartView Tracker blocks a single specific source IP address, not an entire network subnet, and does not support time-limited expiration.

CCreate a Suspicious Activity Rule in Smart Monitor.Correct

SmartView Monitor's Suspicious Activity Rules (SAR) feature lets an administrator define a temporary blocking rule scoped to a specific source, destination, or subnet, with a configurable expiration time such as one hour. Because SARs are applied dynamically by the gateway and are not written to the policy Rule Base, no rule is permanently added and no policy push is required. This is the correct method for rapid, time-bounded blocking during an active investigation.

DAdd a temporary rule using SmartDashboard and select hide rule.

Adding a rule via SmartDashboard and hiding it still writes a permanent rule into the Rule Base, which violates the stated requirement of not adding any rules to the Rule Base.

Concept tested: SmartView Monitor Suspicious Activity Rules for temporary blocking

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_SmartViewMonitor_AdminGuide/html_frameset.htm

Topics

#Suspicious Activity Rules#SmartMonitor#block without rule change#incident response

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice