Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CheckPoint 156-590 Exam - Topic 5 Question 5 Discussion

What action is taken by Threat Prevention for traffic that does not match any Threat Prevention rules?
C) Accept
A) Reject
B) Drop
D) Detect

CheckPoint 156-590 Exam - Topic 5 Question 5 Discussion

Actual exam question for CheckPoint's 156-590 exam
Question #: 5
Topic #: 5
[All 156-590 Questions]

What action is taken by Threat Prevention for traffic that does not match any Threat Prevention rules?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C. Accept. Threat Prevention is applied only to traffic that has already been accepted by the Access Control policy, and then the Threat Prevention rulebase determines which protection profile, blade behavior, and tracking settings apply. When traffic does not match a Threat Prevention rule, no Threat Prevention profile is selected for that connection, so the traffic is not blocked by Threat Prevention simply because of a non-match. Check Point documentation explains that Threat Prevention policy layers calculate their actions according to rule matching, and in a single-layer policy the enforced rule is the first matched rule.

This distinction is critical for certification and real operations. Threat Prevention is not a replacement for the Access Control decision; it is a follow-up inspection layer for already accepted traffic. A non-match in Threat Prevention means the traffic is outside the configured protected scope or rule conditions, so the Threat Prevention engine does not apply a prevent/drop/reject action to it. Reject and Drop are enforcement outcomes for matched malicious or blocked traffic, not for unmatched Threat Prevention traffic. Detect is a logging/enforcement mode for matched protections, not the default result of no rule match. Reference topics: Threat Prevention Policy, ordered layer behavior, protected scope, first-match rule logic, unmatched traffic handling.


Contribute your Thoughts:

0/2000 characters
Venita
14 hours ago
But what if it’s just harmless traffic? C) Accept makes sense.
upvoted 0 times
...
Kayleigh
6 days ago
I feel like it should be A) Reject.
upvoted 0 times
...
Bette
11 days ago
I think it's B) Drop.
upvoted 0 times
...
Carlee
16 days ago
Surprised it's not detected instead!
upvoted 0 times
...
Aja
21 days ago
Wait, are you sure it doesn't just reject?
upvoted 0 times
...
Rima
26 days ago
Definitely a drop, no doubt about it.
upvoted 0 times
...
Ona
1 month ago
I thought it was accepted by default?
upvoted 0 times
...
Jonell
1 month ago
It's usually dropped if no rules match.
upvoted 0 times
...
Shawna
1 month ago
I thought the default action was to detect and log the traffic, but I'm not positive about that.
upvoted 0 times
...
Peggie
2 months ago
I'm a bit confused; I feel like it could either be dropped or rejected, but I can't recall the exact difference.
upvoted 0 times
...
Solange
2 months ago
I remember a practice question about this, and I think it was about accepting the traffic if it doesn't match.
upvoted 0 times
...
Stephaine
2 months ago
I think traffic that doesn't match any rules is usually dropped, but I'm not completely sure.
upvoted 0 times
...

Save Cancel