156-215.80 · Question #548
What object type would you use to grant network access to an LDAP user group?
The correct answer is B. User Group. In Check Point, a User Group object represents a collection of users including those sourced from an LDAP directory, and is referenced in security rules to grant or restrict network access.
Question
What object type would you use to grant network access to an LDAP user group?
Options
- AAccess Role
- BUser Group
- CSmartDirectory Group
- DGroup Template
How the community answered
(41 responses)- A2% (1)
- B90% (37)
- C2% (1)
- D5% (2)
Why each option
In Check Point, a User Group object represents a collection of users including those sourced from an LDAP directory, and is referenced in security rules to grant or restrict network access.
An Access Role is used in the Identity Awareness blade to define access based on a combination of identity attributes such as user, machine, and network location, and is not the direct object type that represents an LDAP user group itself.
A User Group object in Check Point can be configured to include or reference users and groups fetched from a connected LDAP directory server via SmartDirectory. This object is then placed directly into security rules to grant or deny network access, making it the correct object type for mapping LDAP user groups to access policies.
SmartDirectory Group is not a recognized standalone object type in Check Point; SmartDirectory is the name of the LDAP integration feature, and the resulting user collections are managed as User Group objects.
Group Template is not a standard Check Point object type for granting network access to LDAP user groups.
Concept tested: Check Point User Group object for LDAP access control
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Default.htm
Topics
Community Discussion
No community discussion yet for this question.