156-815.70 · Question #106
Can services other than the predefined global services be created for a Global Policy?
The correct answer is D. They can be specifically defined in the Global SmartDashboard. Checkpoint 156-815.70 Exam
Question
Can services other than the predefined global services be created for a Global Policy?
Options
- AThey must be imported from a preconfigured CMA Security Policy.
- BThey cannot be created. Administrators cannot create services not predefined in the Global
- CThey must be imported from a preconfigured Global Policy.
- DThey can be specifically defined in the Global SmartDashboard.
How the community answered
(42 responses)- A5% (2)
- B7% (3)
- C17% (7)
- D71% (30)
Explanation
Checkpoint 156-815.70 Exam
Topics
Community Discussion
4D is the correct answer. In a Multi-Domain environment, the Global SmartDashboard gives the global administrator the ability to define custom service objects directly within the Global domain, not just consume the predefined set. Those custom global services then propagate to the CMAs when the Global Policy is pushed, which is the whole point of managing shared objects at the global level. Options A and C have the data flow backwards, the Global domain pushes down to CMAs, you are not pulling from them, and option B is simply wrong because the product was designed with extensibility in mind from the start. If you are studying this topic, get comfortable with the distinction between global objects, which live in the Global SmartDashboard and are read-only at the CMA level, and local CMA objects, which cannot be referenced in a Global Policy at all.
Group agrees on D, you define custom services right inside Global SmartDashboard.
Has to be B, my senior told me Global Policy locks those services down hard.
Yusuf, your senior is thinking of the enforcement scope correctly but applying it to the wrong object here, because Global Policy assigns a policy package and enforces shared rules, but the actual service restriction in this scenario is handled at the gateway level via the local security policy, which is exactly what D describes. B would matter if we were talking about restricting administrator access across all domains, not service-level traffic control on the gateway.