nerdexam
Check_Point

156-215.80 · Question #259

As you review this Security Policy, what changes could you make to accommodate Rule 4?

The correct answer is B. Modify the column VPN in Rule 2 to limit access to specific traffic. When Rule 4 is being intercepted or shadowed by Rule 2 due to a broad VPN column setting, narrowing the VPN column in Rule 2 allows Rule 4 to correctly match its intended traffic.

Security Policy Management

Question

As you review this Security Policy, what changes could you make to accommodate Rule 4?

Exhibit

156-215.80 question #259 exhibit

Options

  • ARemove the service HTTP from the column Service in Rule 4.
  • BModify the column VPN in Rule 2 to limit access to specific traffic.
  • CNothing at all
  • DModify the columns Source or Destination in Rule 4

How the community answered

(44 responses)
  • A
    5% (2)
  • B
    68% (30)
  • C
    9% (4)
  • D
    18% (8)

Why each option

When Rule 4 is being intercepted or shadowed by Rule 2 due to a broad VPN column setting, narrowing the VPN column in Rule 2 allows Rule 4 to correctly match its intended traffic.

ARemove the service HTTP from the column Service in Rule 4.

Removing HTTP from Rule 4's service column reduces its coverage rather than resolving the underlying rule ordering or VPN conflict.

BModify the column VPN in Rule 2 to limit access to specific traffic.Correct

In Check Point policy, if Rule 2 has its VPN column set to a broad value such as 'Any VPN' traffic, it can intercept connections that should instead be evaluated by Rule 4. Modifying Rule 2's VPN column to reference only specific VPN communities limits its match scope, preventing it from shadowing Rule 4 and allowing Rule 4 to be reached and applied to the correct traffic.

CNothing at all

Making no changes leaves the policy conflict in place, meaning Rule 4 continues to be unreachable or incorrectly matched.

DModify the columns Source or Destination in Rule 4

Modifying Source or Destination in Rule 4 changes which traffic it targets but does not resolve a VPN column conflict in an earlier rule that shadows it.

Concept tested: Check Point Security Policy rule ordering and VPN column scope

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SMAG/Security-Policies.htm

Topics

#rule base analysis#VPN column#rule optimization#policy review

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice