nerdexam
Check_Point

156-215.80 · Question #242

You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.

The correct answer is B. Another rule that accepts HTTP without authentication exists in the Rule Base. Check Point processes rules top-to-bottom with a first-match policy, so a permissive HTTP rule above the User Authentication rule will silently allow traffic without triggering authentication.

User Management and Authentication

Question

You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.

Options

  • AYou checked the cache password on desktop option in Global Properties.
  • BAnother rule that accepts HTTP without authentication exists in the Rule Base.
  • CYou have forgotten to place the User Authentication Rule before the Stealth Rule.
  • DUsers must use the SecuRemote Client, to use the User Authentication Rule.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    80% (35)
  • C
    14% (6)
  • D
    5% (2)

Why each option

Check Point processes rules top-to-bottom with a first-match policy, so a permissive HTTP rule above the User Authentication rule will silently allow traffic without triggering authentication.

AYou checked the cache password on desktop option in Global Properties.

The 'cache password on desktop' option affects credential caching for subsequent connections after an initial successful authentication, not whether users are prompted in the first place.

BAnother rule that accepts HTTP without authentication exists in the Rule Base.Correct

Check Point's rule base uses a first-match algorithm - if a rule accepting HTTP traffic without any authentication action exists above the User Authentication rule, connections match that rule first and are permitted without prompting for credentials. The User Authentication rule is never reached for that traffic.

CYou have forgotten to place the User Authentication Rule before the Stealth Rule.

The Stealth Rule protects the firewall gateway itself from direct access; its position relative to the User Authentication rule does not affect whether users are prompted when accessing web servers.

DUsers must use the SecuRemote Client, to use the User Authentication Rule.

User Authentication operates as a proxy-based mechanism for standard HTTP and does not require the SecuRemote client; SecuRemote is used for encrypted VPN tunnels and Client Authentication scenarios.

Concept tested: Check Point rule base first-match order and User Authentication

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_AdminGuide/html_frameset.htm

Topics

#user authentication#HTTP#rule ordering#rule base

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice