156-727.77 · Question #7
When adding IPS to a gateway, which profile will be set?
The correct answer is C. Default_Protection. See the full explanation below for the reasoning.
Question
When adding IPS to a gateway, which profile will be set?
Options
- ADefault_Protection, but with all actions set to "Detect only"
- BDefault_Protection, but with all actions set to "Prevent"
- CDefault_Protection
- DRecommended_Protection
How the community answered
(46 responses)- A2% (1)
- B9% (4)
- C85% (39)
- D4% (2)
Community Discussion
7The correct answer is C, Default_Protection. When you first add IPS to a gateway in Check Point, the software assigns the Default_Protection profile automatically, and it comes with its factory settings intact, meaning the actions are whatever the profile defines by default, not forcibly overridden to Detect only or Prevent across the board. Option A and B are tempting if you confuse initial profile assignment with what happens when you run the IPS wizard or manually tune a profile, but the assignment step itself does not modify the actions. Option D trips people up because Recommended_Protection sounds like the sensible out-of-the-box choice, but that profile is not what gets applied automatically to the gateway during the initial IPS enablement.
Saw this exact wording, almost picked D because "Recommended" sounds logical, but the default profile assigned is Default_Protection, no modifications.
This one actually tripped me up for a second on my exam because I second-guessed myself and almost picked A, thinking Check Point would default to something more cautious like Detect only, but then I remembered that when you add IPS to a gateway it just assigns Default_Protection as-is, no action modifications. Went with C and got it right, so trust the clean answer when the other options are describing tweaked versions of the same profile.
The only thing I would add is that Default_Protection ships with a mix of actions depending on severity and confidence, so it is not uniformly Prevent across the board, which is exactly why memorizing the profile assignment behavior separately from the action logic saves you on the trickier follow-up questions they sometimes stack right after.
Confirmed C on my exam, the default profile drops in untouched, no action overrides.
Good to know, and just to add one wrinkle, some practice sets I have seen pair that exact setup with a follow-on question about what changes once you attach a custom policy afterward, so nailing the clean default baseline really sets you up for those too.
Default_Protection is set as-is, not pre-tuned to Detect or Prevent, so C.