nerdexam
Check_Point

156-215.80 · Question #467

When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?

The correct answer is A. Access Role. An Access Role is the correct object type for representing LDAP groups in a Check Point Security Policy with Identity Awareness, as it is purpose-built to combine user identity, machine identity, and network location into a single enforceable policy object.

User Management and Authentication

Question

When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?

Options

  • AAccess Role
  • BUser Group
  • CSmartDirectory Group
  • DGroup Template

How the community answered

(43 responses)
  • A
    84% (36)
  • B
    7% (3)
  • C
    7% (3)
  • D
    2% (1)

Why each option

An Access Role is the correct object type for representing LDAP groups in a Check Point Security Policy with Identity Awareness, as it is purpose-built to combine user identity, machine identity, and network location into a single enforceable policy object.

AAccess RoleCorrect

Access Role objects are the native Identity Awareness construct in Check Point that can encapsulate LDAP users and groups, Active Directory machines, and network locations into a single reusable security rule object. They integrate directly with the Identity Awareness blade to enforce group-based access controls, and are the recommended and most complete mechanism for applying LDAP group membership in security policy rules.

BUser Group

User Group is a local Check Point object for grouping internally defined users and is not designed to represent or sync with LDAP directory groups in an Identity Awareness deployment.

CSmartDirectory Group

SmartDirectory Group is not a recognized standard object type used in security policy rules for Identity Awareness-based access control.

DGroup Template

Group Template is a construct for creating multiple similar group definitions and is not a directly instantiable policy object representing a specific LDAP group.

Concept tested: Identity Awareness Access Role for LDAP group-based policy

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Default.htm

Topics

#Identity Awareness#LDAP#Access Role#group-based access

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice