nerdexam
Check_Point

156-215.80 · Question #281

John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus, the…

The correct answer is C. The access should be changed to authenticate the user instead of the PC. This question tests understanding of Check Point Identity Awareness, which shifts access control from IP-based to user-based authentication, allowing users to access resources from any location.

User Management and Authentication

Question

John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus, the gateway policy permits access only from John's desktop which is assigned a static IP address 10.0.0.19. John received a laptop and wants to access the HR Web Server from anywhere in the organization. The IT department gave the laptop a static IP address, but that limits him to operating it only from his desk. The current Rule Base contains a rule that lets John Adams access the HR Web Server from his desktop with a static IP (10.0.0.19). He wants to move around the organization and continue to have access to the HR Web Server. To make this scenario work, the IT administrator: 1) Enables Identity Awareness on a gateway, selects AD Query as one of the Identity Sources installs the policy. 2) Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web Server from any machine and from any location. 3) Changes from static IP address to DHCP for the client PC. What should John request when he cannot access the web server from his laptop?

Options

  • AJohn should lock and unlock his computer
  • BInvestigate this as a network connectivity issue
  • CThe access should be changed to authenticate the user instead of the PC
  • DJohn should install the Identity Awareness Agent

How the community answered

(14 responses)
  • B
    7% (1)
  • C
    79% (11)
  • D
    14% (2)

Why each option

This question tests understanding of Check Point Identity Awareness, which shifts access control from IP-based to user-based authentication, allowing users to access resources from any location.

AJohn should lock and unlock his computer

Locking and unlocking a computer has no effect on firewall rules or IP-based access control policies.

BInvestigate this as a network connectivity issue

John's inability to roam is a deliberate policy restriction tied to a static IP rule, not a network connectivity fault.

CThe access should be changed to authenticate the user instead of the PCCorrect

When access is granted based on a static IP address, the user is locked to a specific machine at a specific desk. Enabling Identity Awareness and reconfiguring the rule to authenticate the user identity (rather than the PC's IP) allows John to access the HR Web Server from any machine or location within the organization. This is the policy-level change the IT administrator must make to decouple the access grant from the IP address.

DJohn should install the Identity Awareness Agent

Installing the Identity Awareness Agent is an end-user client action, not the IT administrator policy change required; also, the agent alone without a policy rule change does not solve the problem.

Concept tested: Check Point Identity Awareness user-based access control

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_IdentityAwareness_AdminGuide/html_frameset.htm

Topics

#identity awareness#user authentication#IP-based access control#static IP limitation

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice