nerdexam
Check_Point

156-215.80 · Question #524

What is the purpose of a Stealth Rule?

The correct answer is C. To drop any traffic destined for the firewall that is not otherwise explicitly allowed. The Stealth Rule is a security policy rule that protects the firewall itself by dropping all traffic destined directly for the firewall that has not been explicitly permitted by a preceding rule.

Security Policy Management

Question

What is the purpose of a Stealth Rule?

Options

  • AA rule used to hide a server's IP address from the outside world.
  • BA rule that allows administrators to access SmartDashboard from any device.
  • CTo drop any traffic destined for the firewall that is not otherwise explicitly allowed.
  • DA rule at the end of your policy to drop any traffic that is not explicitly allowed.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    90% (27)

Why each option

The Stealth Rule is a security policy rule that protects the firewall itself by dropping all traffic destined directly for the firewall that has not been explicitly permitted by a preceding rule.

AA rule used to hide a server's IP address from the outside world.

Hiding a server's IP address from external networks is accomplished through NAT (Network Address Translation) rules, not the Stealth Rule.

BA rule that allows administrators to access SmartDashboard from any device.

Administrator access to SmartDashboard or SmartConsole is controlled by explicit allow rules or management access settings, not the Stealth Rule, which drops rather than grants access.

CTo drop any traffic destined for the firewall that is not otherwise explicitly allowed.Correct

The Stealth Rule is placed early in the rulebase and targets the firewall's own IP address as the destination, ensuring that any connection attempt directed at the firewall - such as unauthorized management access or direct attacks - is silently dropped unless a specific preceding rule explicitly permits it, thus shielding the firewall from direct exposure.

DA rule at the end of your policy to drop any traffic that is not explicitly allowed.

A rule at the end of the policy that drops all traffic not explicitly permitted is called the Cleanup Rule - the Stealth Rule is distinct in that it specifically protects the firewall's own address and is placed near the top of the rulebase.

Concept tested: Check Point Stealth Rule firewall self-protection policy

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Stealth-rule.htm

Topics

#Stealth Rule#firewall protection#rule base

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice