156-215.80 · Question #61
What are the three conflict resolution rules in the Threat Prevention Policy Layers?
The correct answer is C. Conflict on settings, conflict on address, and conflict on exception. Check Point Threat Prevention Policy Layers resolve profile conflicts using three defined rules: conflict on settings, conflict on address, and conflict on exception.
Question
What are the three conflict resolution rules in the Threat Prevention Policy Layers?
Options
- AConflict on action, conflict on exception, and conflict on settings
- BConflict on scope, conflict on settings, and conflict on exception
- CConflict on settings, conflict on address, and conflict on exception
- DConflict on action, conflict on destination, and conflict on settings
How the community answered
(44 responses)- A2% (1)
- B7% (3)
- C89% (39)
- D2% (1)
Why each option
Check Point Threat Prevention Policy Layers resolve profile conflicts using three defined rules: conflict on settings, conflict on address, and conflict on exception.
This incorrectly substitutes 'conflict on action' and 'conflict on scope' for the address-based and settings-based categories - Threat Prevention conflict resolution does not define an 'action' conflict category.
This includes 'conflict on scope' rather than 'conflict on address' - the correct address-related conflict resolution rule is scoped to specific addresses, not a generic scope category, and 'conflict on settings' appears correctly but the other two entries do not match the defined rules.
When multiple Threat Prevention profiles apply to overlapping traffic, Check Point resolves the conflict via three specific mechanisms: conflict on settings (which profile's protection configuration takes precedence), conflict on address (how overlapping source or destination scopes are reconciled), and conflict on exception (how exception rules from competing profiles are merged or prioritized). Together these three rules ensure deterministic enforcement when profiles overlap.
This incorrectly names 'conflict on action' and 'conflict on destination' as conflict resolution rules - neither is defined in Check Point Threat Prevention conflict resolution; destination-specific logic is covered under 'conflict on address.'
Concept tested: Threat Prevention Policy Layer conflict resolution rules
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TPG/Policy-Layers.htm
Topics
Community Discussion
No community discussion yet for this question.