nerdexam
Check_Point

156-215.80 · Question #386

When logging in for the first time to a Security management Server through SmartConsole, a fingerprint is saved to the:

The correct answer is D. SmartConsole cache is available for future Security Management Server authentications. On first login to a Security Management Server, SmartConsole saves the server's certificate fingerprint in its local client-side cache for use in validating future connections.

Deployment and Configuration

Question

When logging in for the first time to a Security management Server through SmartConsole, a fingerprint is saved to the:

Options

  • ASecurity Management Server's /home/.fgpt file and is available for future SmartConsole
  • BWindows registry is available for future Security Management Server authentications.
  • Cthere is no memory used for saving a fingerprint anyway.
  • DSmartConsole cache is available for future Security Management Server authentications.

How the community answered

(53 responses)
  • B
    2% (1)
  • C
    4% (2)
  • D
    94% (50)

Why each option

On first login to a Security Management Server, SmartConsole saves the server's certificate fingerprint in its local client-side cache for use in validating future connections.

ASecurity Management Server's /home/.fgpt file and is available for future SmartConsole

The fingerprint is not stored on the Security Management Server in a .fgpt file; it is stored on the SmartConsole client machine so the client can independently validate the server's identity on future sessions.

BWindows registry is available for future Security Management Server authentications.

SmartConsole does not use the Windows registry to store the fingerprint; it uses its own application-level cache for this purpose.

Cthere is no memory used for saving a fingerprint anyway.

A fingerprint is absolutely saved - omitting this step would eliminate the trust anchor needed to detect a spoofed or unauthorized management server on subsequent connections.

DSmartConsole cache is available for future Security Management Server authentications.Correct

SmartConsole stores the Security Management Server's certificate fingerprint in its local application cache after the administrator accepts it on first login. On subsequent connections, SmartConsole compares the server's presented fingerprint against this cached value to detect potential man-in-the-middle attacks, functioning similarly to SSH host key verification.

Concept tested: SmartConsole fingerprint caching for server authentication

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Logging-in-to-SmartConsole.htm

Topics

#fingerprint#SmartConsole login#SIC#first-time authentication

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice