156-215.80 · Question #68
Fill in the blank: To build an effective Security Policy, use a ________ and _______ rule.
The correct answer is A. Cleanup; stealth. An effective Check Point Security Policy requires a stealth rule to protect the gateway itself and a cleanup rule to explicitly drop all unmatched traffic at the bottom of the policy.
Question
Fill in the blank: To build an effective Security Policy, use a ________ and _______ rule.
Options
- ACleanup; stealth
- BStealth; implicit
- CCleanup; default
- DImplicit; explicit
How the community answered
(38 responses)- A89% (34)
- B3% (1)
- C8% (3)
Why each option
An effective Check Point Security Policy requires a stealth rule to protect the gateway itself and a cleanup rule to explicitly drop all unmatched traffic at the bottom of the policy.
The stealth rule is placed near the top of the rulebase and denies all connections destined directly to the Security Gateway, preventing attackers from targeting the firewall itself. The cleanup rule sits at the bottom and drops all traffic not matched by any preceding rule, ensuring no traffic implicitly passes and providing a logged catch-all for unmatched sessions.
Implicit rules are auto-generated by Check Point and are not manually authored as part of the recommended baseline policy design; pairing stealth with an implicit rule does not constitute best practice.
'Default' is not the standard Check Point term for the final catch-all rule; the correct terminology is the 'cleanup' rule.
Implicit and explicit describe rule origin categories, not the specific named constructs (stealth and cleanup) required to build a secure policy baseline.
Concept tested: Check Point Security Policy stealth and cleanup rule design
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.