nerdexam
Check_Point

156-215.80 · Question #548

What object type would you use to grant network access to an LDAP user group?

The correct answer is B. User Group. In Check Point, a User Group object represents a collection of users including those sourced from an LDAP directory, and is referenced in security rules to grant or restrict network access.

User Management and Authentication

Question

What object type would you use to grant network access to an LDAP user group?

Options

  • AAccess Role
  • BUser Group
  • CSmartDirectory Group
  • DGroup Template

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    90% (37)
  • C
    2% (1)
  • D
    5% (2)

Why each option

In Check Point, a User Group object represents a collection of users including those sourced from an LDAP directory, and is referenced in security rules to grant or restrict network access.

AAccess Role

An Access Role is used in the Identity Awareness blade to define access based on a combination of identity attributes such as user, machine, and network location, and is not the direct object type that represents an LDAP user group itself.

BUser GroupCorrect

A User Group object in Check Point can be configured to include or reference users and groups fetched from a connected LDAP directory server via SmartDirectory. This object is then placed directly into security rules to grant or deny network access, making it the correct object type for mapping LDAP user groups to access policies.

CSmartDirectory Group

SmartDirectory Group is not a recognized standalone object type in Check Point; SmartDirectory is the name of the LDAP integration feature, and the resulting user collections are managed as User Group objects.

DGroup Template

Group Template is not a standard Check Point object type for granting network access to LDAP user groups.

Concept tested: Check Point User Group object for LDAP access control

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Default.htm

Topics

#LDAP#user groups#network access#access control objects

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice