156-215.80 · Question #34
You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?
The correct answer is B. Create a separate Security Policy package for each remote Security Gateway. When managing multiple Security Gateways with many rules, creating a dedicated Security Policy package per gateway allows each gateway to enforce only its relevant rules, reducing complexity. This is the recommended Check Point approach to simplify distributed security…
Question
You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?
Options
- AEliminate all possible contradictory rules such as the Stealth or Cleanup rules.
- BCreate a separate Security Policy package for each remote Security Gateway.
- CCreate network object that restrict all applicable rules to only certain networks.
- DRun separate SmartConsole instances to login and configure each Security Gateway directly.
How the community answered
(35 responses)- A9% (3)
- B83% (29)
- C6% (2)
- D3% (1)
Why each option
When managing multiple Security Gateways with many rules, creating a dedicated Security Policy package per gateway allows each gateway to enforce only its relevant rules, reducing complexity. This is the recommended Check Point approach to simplify distributed security administration.
Eliminating rules like the Stealth or Cleanup rules is a security risk and does not address the administrative complexity of managing many gateways; those rules serve critical protective purposes.
Check Point supports multiple Security Policy packages, each of which can be assigned to specific Security Gateways or gateway clusters. By creating a separate package per remote gateway, administrators scope each policy to only the rules relevant to that site, avoiding a single bloated policy and making changes easier to manage and audit.
Creating network objects that restrict rules to certain networks can help with rule precision but does not reduce the number of rules visible to administrators or simplify per-gateway policy management at scale.
Logging into each gateway directly via separate SmartConsole instances bypasses centralized management, increases administrative overhead, and is contrary to Check Point's centralized management architecture.
Concept tested: Check Point Security Policy package per gateway assignment
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SMAG/Security-Policies.htm
Topics
Community Discussion
No community discussion yet for this question.