nerdexam
Check_Point

156-215.80 · Question #443

What is the purpose of the Clean-up Rule?

The correct answer is A. To log all traffic that is not explicitly allowed or denied in the Rule Base. The Clean-up Rule is the final rule in a Check Point Rule Base that drops and logs all traffic not explicitly matched by any preceding rule.

Security Policy Management

Question

What is the purpose of the Clean-up Rule?

Options

  • ATo log all traffic that is not explicitly allowed or denied in the Rule Base.
  • BTo clean up policies found inconsistent with the compliance blade reports.
  • CTo remove all rules that could have a conflict with other rules in the database.
  • DTo eliminate duplicate log entries in the Security Gateway

How the community answered

(43 responses)
  • A
    95% (41)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The Clean-up Rule is the final rule in a Check Point Rule Base that drops and logs all traffic not explicitly matched by any preceding rule.

ATo log all traffic that is not explicitly allowed or denied in the Rule Base.Correct

The Clean-up Rule sits at the bottom of the Rule Base and acts as a catch-all, implicitly dropping any connection not permitted or denied by an earlier rule. Logging this traffic is critical for security auditing because it surfaces unauthorized access attempts and policy gaps. Without it, unmatched traffic would be silently dropped with no record.

BTo clean up policies found inconsistent with the compliance blade reports.

The Clean-up Rule has no relationship to the Compliance Software Blade or its reports; those are separate policy audit functions.

CTo remove all rules that could have a conflict with other rules in the database.

The Clean-up Rule does not modify, remove, or resolve conflicts between other rules; it only handles traffic that falls through all other rules.

DTo eliminate duplicate log entries in the Security Gateway

The Clean-up Rule generates new log entries for dropped unmatched traffic; it does not deduplicate or manage existing log entries.

Concept tested: Check Point firewall Clean-up Rule function

Source: https://sc1.checkpoint.com/documents/latest/AdminGuides/Firewall/EN/html_frameset.htm

Topics

#cleanup rule#rule base#traffic logging#implicit deny

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice