nerdexam
Check_Point

156-215.80 · Question #269

Your company enforces a strict change control policy. Which of the following would be MOST effective for quickly dropping an attacker's specific active connection?

The correct answer is B. Block Intruder feature of SmartView Tracker. Under strict change control, the Block Intruder feature in SmartView Tracker provides the fastest method to terminate a specific active attacker connection without requiring a full policy installation.

Security Gateway Troubleshooting

Question

Your company enforces a strict change control policy. Which of the following would be MOST effective for quickly dropping an attacker's specific active connection?

Options

  • AChange the Rule Base and install the Policy to all Security Gateways
  • BBlock Intruder feature of SmartView Tracker
  • CIntrusion Detection System (IDS) Policy install
  • DSAM - Suspicious Activity Rules feature of SmartView Monitor

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    82% (18)
  • C
    9% (2)
  • D
    5% (1)

Why each option

Under strict change control, the Block Intruder feature in SmartView Tracker provides the fastest method to terminate a specific active attacker connection without requiring a full policy installation.

AChange the Rule Base and install the Policy to all Security Gateways

Changing the Rule Base and installing the policy to all Security Gateways requires a full policy installation cycle, which is time-consuming and introduces a formal change control event rather than an emergency in-session block.

BBlock Intruder feature of SmartView TrackerCorrect

The Block Intruder feature in SmartView Tracker allows an administrator to immediately terminate a specific active connection visible in the live log without installing a new policy or modifying the Rule Base. This bypasses the formal change control process since it is an on-demand, session-level action rather than a policy change. It targets the exact connection rather than applying broad rules across all gateways.

CIntrusion Detection System (IDS) Policy install

An IDS Policy install deploys intrusion detection signatures to sensors and does not provide a mechanism to immediately terminate a specific active attacker session.

DSAM - Suspicious Activity Rules feature of SmartView Monitor

SAM rules in SmartView Monitor create criteria-based blocks for future matching connections but do not instantly drop a currently active, specific session the way Block Intruder does.

Concept tested: Block Intruder immediate session termination in SmartView Tracker

Source: https://sc1.checkpoint.com/documents/R80/CP_R80_LoggingAndMonitoring_AdminGuide/html_frameset.htm

Topics

#Block Intruder#SmartView Tracker#active connections#change control

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice