Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CheckPoint 156-590 Exam - Topic 6 Question 9 Discussion

What is necessary to activate the exception to all Security Gateways?
B) You have to re-install the Threat Prevention policy.
A) Install Database is sufficient.
C) You have to re-install the Access Control policy.
D) The changes will be applied immediately, so no need to do anything.

CheckPoint 156-590 Exam - Topic 6 Question 9 Discussion

Actual exam question for CheckPoint's 156-590 exam
Question #: 9
Topic #: 6
[All 156-590 Questions]

What is necessary to activate the exception to all Security Gateways?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is B. You have to re-install the Threat Prevention policy. Threat Prevention exceptions are policy constructs, so they must be compiled and installed to the relevant Security Gateways before they affect enforcement. Check Point documentation for creating IPS exceptions shows the workflow: create or configure the exception rule, click OK, and then Install Policy. The Custom Threat Prevention guide also explains that Threat Prevention blades have a dedicated Threat Prevention policy and that this policy can be installed separately from Access Control. It explicitly recommends installing only the Threat Prevention policy to minimize performance impact on Security Gateways.

This is why Install Database is not sufficient. Install Database updates management-side objects and databases, but it does not enforce a new Threat Prevention exception on gateways. Installing Access Control policy is also the wrong policy domain because Anti-Virus, Anti-Bot, IPS, Threat Emulation, and Threat Extraction exceptions belong to Threat Prevention. The change is not immediately active because Security Gateways enforce compiled policy, not unpublished or uninstalled SmartConsole changes. Reference topics: Threat Prevention Exceptions, IPS Exceptions, policy installation targets, dedicated Threat Prevention policy, exception enforcement lifecycle.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel