Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CheckPoint 156-590 Exam - Topic 6 Question 9 Discussion

What is necessary to activate the exception to all Security Gateways?
B) You have to re-install the Threat Prevention policy.
A) Install Database is sufficient.
C) You have to re-install the Access Control policy.
D) The changes will be applied immediately, so no need to do anything.

CheckPoint 156-590 Exam - Topic 6 Question 9 Discussion

Actual exam question for CheckPoint's 156-590 exam
Question #: 9
Topic #: 6
[All 156-590 Questions]

What is necessary to activate the exception to all Security Gateways?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is B. You have to re-install the Threat Prevention policy. Threat Prevention exceptions are policy constructs, so they must be compiled and installed to the relevant Security Gateways before they affect enforcement. Check Point documentation for creating IPS exceptions shows the workflow: create or configure the exception rule, click OK, and then Install Policy. The Custom Threat Prevention guide also explains that Threat Prevention blades have a dedicated Threat Prevention policy and that this policy can be installed separately from Access Control. It explicitly recommends installing only the Threat Prevention policy to minimize performance impact on Security Gateways.

This is why Install Database is not sufficient. Install Database updates management-side objects and databases, but it does not enforce a new Threat Prevention exception on gateways. Installing Access Control policy is also the wrong policy domain because Anti-Virus, Anti-Bot, IPS, Threat Emulation, and Threat Extraction exceptions belong to Threat Prevention. The change is not immediately active because Security Gateways enforce compiled policy, not unpublished or uninstalled SmartConsole changes. Reference topics: Threat Prevention Exceptions, IPS Exceptions, policy installation targets, dedicated Threat Prevention policy, exception enforcement lifecycle.


Contribute your Thoughts:

0/2000 characters
Edda
3 days ago
I’m not so sure about that, sounds a bit off.
upvoted 0 times
...
Junita
8 days ago
Definitely B, can't skip the Threat Prevention policy.
upvoted 0 times
...
Brigette
13 days ago
No way, the changes apply immediately? That seems too easy!
upvoted 0 times
...
Chaya
19 days ago
I thought you had to re-install the Threat Prevention policy?
upvoted 0 times
...
Jess
24 days ago
A) Install Database is sufficient.
upvoted 0 times
...
Cherelle
29 days ago
I believe we discussed that re-installing the Threat Prevention policy is necessary, so I would lean towards B.
upvoted 0 times
...
Isaac
1 month ago
I vaguely recall something about changes applying immediately, but I can't remember if that's true for all situations.
upvoted 0 times
...
Bambi
1 month ago
I feel like we had a similar question in practice about re-installing policies. I think it might be B or C.
upvoted 0 times
...
Veronica
1 month ago
I think I remember that just installing the database isn't enough, but I'm not sure what else is needed.
upvoted 0 times
...

Save Cancel