156-215.80 · Question #506
What is the purpose of the Stealth Rule?
The correct answer is A. To prevent users from directly connecting to a Security Gateway. The Stealth Rule is a Security Policy rule placed near the top of the rule base that explicitly drops all traffic destined for the Security Gateway itself, preventing unauthorized direct access to the firewall.
Question
What is the purpose of the Stealth Rule?
Options
- ATo prevent users from directly connecting to a Security Gateway.
- BTo reduce the number of rules in the database.
- CTo reduce the amount of logs for performance issues.
- DTo hide the gateway from the Internet.
How the community answered
(43 responses)- A93% (40)
- B2% (1)
- D5% (2)
Why each option
The Stealth Rule is a Security Policy rule placed near the top of the rule base that explicitly drops all traffic destined for the Security Gateway itself, preventing unauthorized direct access to the firewall.
The Stealth Rule specifies the Security Gateway as the destination and sets the action to Drop, ensuring that no user or host can initiate a direct connection to the firewall outside of authorized management channels. This protects the gateway from attacks, unauthorized management attempts, and reconnaissance by making it unreachable through the policy - not by hiding its IP address, but by enforcing a deny action on all direct connection attempts.
The Stealth Rule is a specific security control for gateway protection and has no effect on the total number of rules stored in the policy database.
The Stealth Rule is not a logging or performance optimization; its sole purpose is to block direct access to the gateway.
The Stealth Rule does not conceal the gateway's IP address from the Internet; it drops traffic destined for that IP, which is a different mechanism from IP hiding or NAT.
Concept tested: Check Point Stealth Rule function and placement
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Security-Policy-Best-Practices.htm
Topics
Community Discussion
No community discussion yet for this question.