nerdexam
Check_Point

156-215.80 · Question #268

What happens if the identity of a user is known?

The correct answer is C. If the user credentials do not match an Access Role, the gateway moves onto the next rule. When a user's identity is known but does not match any Access Role in a rule, Check Point Identity Awareness causes the gateway to skip that rule and evaluate the next one in the policy.

User Management and Authentication

Question

What happens if the identity of a user is known?

Options

  • AIf the user credentials do not match an Access Role, the traffic is automatically dropped.
  • BIf the user credentials do not match an Access Role, the system displays a sandbox.
  • CIf the user credentials do not match an Access Role, the gateway moves onto the next rule.
  • DIf the user credentials do not match an Access Role, the system displays the Captive Portal.

How the community answered

(32 responses)
  • A
    3% (1)
  • C
    94% (30)
  • D
    3% (1)

Why each option

When a user's identity is known but does not match any Access Role in a rule, Check Point Identity Awareness causes the gateway to skip that rule and evaluate the next one in the policy.

AIf the user credentials do not match an Access Role, the traffic is automatically dropped.

Traffic is not automatically dropped just because a user does not match an Access Role in one rule - the gateway must reach an explicit Drop rule or the default policy action before dropping.

BIf the user credentials do not match an Access Role, the system displays a sandbox.

A sandbox is not a standard response to an Access Role mismatch - sandboxing applies to file inspection (Threat Emulation), not identity policy evaluation.

CIf the user credentials do not match an Access Role, the gateway moves onto the next rule.Correct

Check Point Identity Awareness enforces Access Roles as match conditions within a rule. If the gateway has identified the user but that user does not satisfy the Access Role defined in a rule, the rule is treated as a non-match and the gateway continues processing subsequent rules in order - the same way any other non-matching rule condition (source IP, destination, service) is handled.

DIf the user credentials do not match an Access Role, the system displays the Captive Portal.

The Captive Portal is displayed when the user's identity is unknown and needs to be authenticated, not when the identity is already known but does not match a specific Access Role.

Concept tested: Check Point Identity Awareness Access Role rule matching behavior

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_IdentityAwareness_AdminGuide/html_frameset.htm

Topics

#Identity Awareness#Access Role#rule matching#user credentials

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice