nerdexam
Check_Point

156-215.80 · Question #34

You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?

The correct answer is B. Create a separate Security Policy package for each remote Security Gateway. When managing multiple Security Gateways with many rules, creating a dedicated Security Policy package per gateway allows each gateway to enforce only its relevant rules, reducing complexity. This is the recommended Check Point approach to simplify distributed security…

Security Policy Management

Question

You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?

Options

  • AEliminate all possible contradictory rules such as the Stealth or Cleanup rules.
  • BCreate a separate Security Policy package for each remote Security Gateway.
  • CCreate network object that restrict all applicable rules to only certain networks.
  • DRun separate SmartConsole instances to login and configure each Security Gateway directly.

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    83% (29)
  • C
    6% (2)
  • D
    3% (1)

Why each option

When managing multiple Security Gateways with many rules, creating a dedicated Security Policy package per gateway allows each gateway to enforce only its relevant rules, reducing complexity. This is the recommended Check Point approach to simplify distributed security administration.

AEliminate all possible contradictory rules such as the Stealth or Cleanup rules.

Eliminating rules like the Stealth or Cleanup rules is a security risk and does not address the administrative complexity of managing many gateways; those rules serve critical protective purposes.

BCreate a separate Security Policy package for each remote Security Gateway.Correct

Check Point supports multiple Security Policy packages, each of which can be assigned to specific Security Gateways or gateway clusters. By creating a separate package per remote gateway, administrators scope each policy to only the rules relevant to that site, avoiding a single bloated policy and making changes easier to manage and audit.

CCreate network object that restrict all applicable rules to only certain networks.

Creating network objects that restrict rules to certain networks can help with rule precision but does not reduce the number of rules visible to administrators or simplify per-gateway policy management at scale.

DRun separate SmartConsole instances to login and configure each Security Gateway directly.

Logging into each gateway directly via separate SmartConsole instances bypasses centralized management, increases administrative overhead, and is contrary to Check Point's centralized management architecture.

Concept tested: Check Point Security Policy package per gateway assignment

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SMAG/Security-Policies.htm

Topics

#Security Policy package#multiple gateways#policy management#administration

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice