nerdexam
Check_Point

156-816.61 · Question #36

Which of the following statements is true concerning the default Security Policy of the External Virtual Router?

The correct answer is C. The default policy of the External Virtual Router Denies all traffic going to or coming from it. Option C is correct because, by design, the External Virtual Router (External VR) in a Check Point VSX environment ships with an implicit deny-all default Security Policy - no traffic is permitted to or from it until an administrator explicitly creates and installs a permissive…

Managing Virtual Systems and Virtual Routers

Question

Which of the following statements is true concerning the default Security Policy of the External Virtual Router?

Options

  • AThe External Virtual Router always enforces the same policy as the Management Virtual
  • BAll traffic coming from networks protected by a VSX Gateway is accepted. All other traffic is
  • CThe default policy of the External Virtual Router Denies all traffic going to or coming from it
  • DThe default policy of the External Virtual Router can't be changed
  • EThe External Virtual Router automatically performs Hide NAT behind external interface for all

How the community answered

(29 responses)
  • B
    3% (1)
  • C
    93% (27)
  • E
    3% (1)

Explanation

Option C is correct because, by design, the External Virtual Router (External VR) in a Check Point VSX environment ships with an implicit deny-all default Security Policy - no traffic is permitted to or from it until an administrator explicitly creates and installs a permissive policy. This "closed by default" stance follows the principle of least privilege and forces deliberate, conscious configuration before any traffic flows.

Why the distractors are wrong:

  • A - The External VR and the Management Virtual System are independent entities with separate policies; they do not mirror each other.
  • B - There is no automatic acceptance of traffic from VSX-protected networks; the default is deny-all regardless of source.
  • D - The policy absolutely can be changed; administrators install custom policies on the External VR just like any other virtual device.
  • E - Hide NAT is not automatic; NAT rules must be explicitly defined and installed by the administrator.

Memory tip: Think of the External VR as a locked door out of the box - nothing gets in or out until you hand someone a key. "External" might suggest openness, but in security architecture, anything facing the outside world starts maximally restrictive.

Topics

#External Virtual Router#Default Security Policy#VSX Security#Traffic Filtering

Community Discussion

No community discussion yet for this question.

Full 156-816.61 Practice