{"id":22557,"date":"2026-09-26T06:14:54","date_gmt":"2026-09-26T06:14:54","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22557"},"modified":"2026-09-26T06:14:54","modified_gmt":"2026-09-26T06:14:54","slug":"checkpoint-156-590-practice-test-questions-and-exam-dumps-part-2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/checkpoint-156-590-practice-test-questions-and-exam-dumps-part-2-q21-40\/","title":{"rendered":"Checkpoint 156-590 Practice Test Questions and Exam Dumps Part 2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/156-590-exam-dumps\"><b>Checkpoint 156-590 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 21. Which Check Point component is responsible for managing security policies and configuring Security Gateways?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ThreatCloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Management Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identity Awareness<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Security Management Server<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Security Management Server is responsible for centralized management of Check Point security policies and Security Gateway configurations. Administrators use SmartConsole to connect to the Security Management Server and create, modify, install, and monitor security policies. The Security Gateway enforces the installed policies and inspects network traffic, while ThreatCloud provides threat intelligence. Identity Awareness provides identity-related information that can be used in security policies. Separating management from enforcement allows organizations to centrally administer multiple Security Gateways. Therefore, the Security Management Server is the component responsible for centralized security-policy management and gateway configuration.<\/span><\/p>\n<p><b>Question 22. What is the primary function of a Check Point Security Gateway?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide only DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To store administrator passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create SmartConsole objects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To enforce security policies and inspect network traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. To enforce security policies and inspect network traffic<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Check Point Security Gateway enforces security policies and inspects network traffic according to the configured Software Blades and installed policy. It can provide capabilities such as firewalling, VPN, IPS, Anti-Virus, Anti-Bot, Application Control, and other protections depending on the licensed and enabled Software Blades. The Security Management Server centrally manages policies and configuration, while the Security Gateway performs the enforcement and traffic-inspection functions. DNS resolution and administrator credential storage are not its primary roles. Therefore, enforcing security policies and inspecting network traffic is the fundamental function of a Check Point Security Gateway.<\/span><\/p>\n<p><b>Question 23. Which application is the primary management interface for configuring Check Point Security Management Server policies in modern Check Point deployments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SmartConsole<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PuTTY<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wireshark<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SecureCRT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. SmartConsole<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SmartConsole is the primary graphical management application used to configure and administer Check Point Security Management environments in modern deployments. Administrators can use SmartConsole to create security objects, configure policies, manage gateways, review logs, and perform other management tasks according to their permissions. PuTTY and SecureCRT are terminal applications, while Wireshark is a packet-analysis tool. SmartConsole communicates with the Security Management Server and provides centralized access to management functions. Therefore, SmartConsole is the appropriate application for configuring Check Point security policies and management objects.<\/span><\/p>\n<p><b>Question 24. What is the purpose of installing a security policy on a Check Point Security Gateway?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To change the gateway&#8217;s physical hardware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To synchronize external DNS servers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To transfer the configured policy from management to the gateway for enforcement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To erase all security rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To transfer the configured policy from management to the gateway for enforcement<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Installing a security policy transfers the configured policy from the Security Management Server to the selected Security Gateway or gateways so that the gateway can enforce the policy. Administrators typically make changes in SmartConsole and then install the policy when they are ready for those changes to become active on the relevant gateways. Policy installation does not change physical hardware, erase all rules, or synchronize external DNS servers. The exact policy components installed can depend on the selected policy package and deployment architecture. Therefore, transferring the configured policy to the gateway for enforcement is the primary purpose of policy installation.<\/span><\/p>\n<p><b>Question 25. Which Check Point object represents a Security Gateway in SmartConsole?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network Object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Gateway object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service Group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Security Gateway object<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Gateway object represents a managed Check Point Security Gateway within the management database. The object contains information needed to manage the gateway, including its identity, communication parameters, and enabled Software Blades, depending on the configuration. Network and host objects generally represent network entities, while service groups organize service objects. Creating the gateway object is an important part of establishing the relationship between the Security Management Server and the gateway. Once configured and trusted appropriately, the management server can install policies and perform administrative operations on the gateway. Therefore, a Security Gateway object is the correct answer.<\/span><\/p>\n<p><b>Question 26. What is the main purpose of a Host object in Check Point SmartConsole?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To represent an individual IP-addressed device or host<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To configure an entire VPN community automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace the Security Management Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define a Threat Prevention profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To represent an individual IP-addressed device or host<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Host object represents an individual network host in the Check Point management database. It normally contains information such as the host&#8217;s IPv4 or IPv6 address and can be used as a source or destination in security rules and other configurations. Administrators can create objects for servers, workstations, management systems, or other individual devices. A Host object does not replace the Security Management Server, define a Threat Prevention profile, or automatically create an entire VPN community. Object-based policy design makes security rules easier to understand and maintain. Therefore, representing an individual IP-addressed device is the primary purpose of a Host object.<\/span><\/p>\n<p><b>Question 27. Which SmartConsole object is used to represent a group of network objects?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network Group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPN community<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Network Group<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Group is used to group multiple network-related objects, such as host or network objects, into a logical collection. The group can then be referenced in security policy rules, reducing the need to list every individual object separately. For example, a group could represent all application servers or all internal office networks. A Service object represents a network service, a Security Gateway object represents a managed gateway, and a VPN community represents a collection or relationship of VPN peers. Therefore, Network Group is the appropriate object type for organizing multiple network objects into a single logical group.<\/span><\/p>\n<p><b>Question 28. Which Check Point object type represents a TCP or UDP service such as HTTPS or DNS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Service<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Service object represents a network service that can be referenced in Check Point security policies. Service objects can define characteristics such as protocol and port number, allowing administrators to create rules that control specific types of traffic. For example, HTTPS commonly uses TCP port 443, while DNS commonly uses UDP port 53, although DNS can also use TCP in certain circumstances. Host objects represent individual devices, Network objects represent IP networks, and Security Gateway objects represent managed gateways. Therefore, the Service object is the appropriate object type for representing TCP or UDP services used in security policy rules.<\/span><\/p>\n<p><b>Question 29. What is the purpose of a Network object in Check Point SmartConsole?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To represent an IP network or subnet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define an administrator&#8217;s password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To configure an IPS signature<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To represent a physical switch port<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To represent an IP network or subnet<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network object represents an IP network or subnet in the Check Point management database. Administrators can use Network objects as sources or destinations in security policy rules and other configurations. For example, an object could represent an internal subnet such as <\/span><span style=\"font-weight: 400;\">10.10.20.0\/24<\/span><span style=\"font-weight: 400;\">. Using named objects makes policies easier to read and maintain than repeatedly entering raw IP addresses and masks. Network objects do not define administrator passwords, IPS signatures, or physical switch ports. Therefore, representing an IP network or subnet is the primary purpose of a Network object.<\/span><\/p>\n<p><b>Question 30. Which rule component specifies the devices or networks from which traffic originates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Destination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Source<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Source column in a Check Point Access Control rule identifies the originating hosts, networks, users, or other relevant source entities for the traffic being evaluated. The Destination column identifies where the traffic is going, Service specifies the type of traffic or application criteria, and Action determines what the gateway should do when the rule matches. Defining a source allows administrators to create policies based on where traffic originates, such as permitting employees from an internal network to access approved services. Therefore, Source is the rule component that identifies where the traffic originates.<\/span><\/p>\n<p><b>Question 31. Which rule component identifies the destination host or network to which traffic is directed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Destination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Track<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Destination<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Destination field in a Check Point Access Control rule identifies the host, network, group, or other object to which the traffic is directed. It works together with Source, Services and Applications, and other rule columns to determine whether a connection matches the rule. For example, an administrator can create a rule allowing an internal network to access a specific web-server network. Action defines whether matching traffic is allowed, blocked, or otherwise handled, while Track controls logging and tracking behavior. Therefore, Destination is the rule component used to identify the intended target of the traffic.<\/span><\/p>\n<p><b>Question 32. What does the Service column in a traditional Check Point Access Control rule specify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The source IP address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The administrator who created the rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The type of network service or traffic being matched<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The gateway&#8217;s management IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The type of network service or traffic being matched<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Service column specifies the network service or traffic characteristics that a traditional Access Control rule should match. Examples include HTTP, HTTPS, DNS, SSH, and other TCP or UDP services represented by service objects. The Source column identifies where traffic originates, Destination identifies where it is going, and Action determines how matching traffic is handled. Modern Check Point policies can also use application and identity criteria, but service matching remains an important policy mechanism. Therefore, the Service column is used to identify the type of network traffic or service to which the rule applies.<\/span><\/p>\n<p><b>Question 33. What is the purpose of the Action column in a Check Point Access Control rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To specify the response when traffic matches the rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify the destination IP address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define the administrator&#8217;s role<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To configure the gateway&#8217;s hostname<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To specify the response when traffic matches the rule<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Action column determines what the Security Gateway should do when traffic matches the conditions of a rule. Common actions include Accept and Drop, while other actions may be available depending on the rule type and Check Point configuration. The action is evaluated after the traffic matches the relevant rule criteria, such as source, destination, service, application, and identity. The Action column does not identify the destination address or configure administrator roles or gateway hostnames. Therefore, specifying the response to matching traffic is the purpose of the Action column.<\/span><\/p>\n<p><b>Question 34. What does the Track option in a Check Point Access Control rule control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The gateway&#8217;s routing protocol<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether matching traffic is logged or tracked<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The source network&#8217;s subnet mask<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The encryption algorithm used by VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Whether matching traffic is logged or tracked<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Track option controls whether and how traffic matching a rule is logged or tracked. Logging provides administrators with visibility into accepted, dropped, or otherwise relevant connections and can support troubleshooting, monitoring, and security investigations. Depending on the configuration and Check Point version, tracking options can include logging, accounting, alerts, or other forms of event handling. Track does not define routing, subnet masks, or VPN encryption algorithms. Proper logging is important because a security policy without appropriate visibility can make investigation more difficult. Therefore, controlling whether matching traffic is logged or tracked is the primary purpose of the Track option.<\/span><\/p>\n<p><b>Question 35. How does Check Point Access Control generally evaluate rules in a rulebase?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> All matching rules are always executed simultaneously<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rules are evaluated from bottom to top only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rules are generally evaluated from top to bottom until a matching rule determines the outcome<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the last rule is evaluated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Rules are generally evaluated from top to bottom until a matching rule determines the outcome<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Check Point Access Control rules are generally evaluated from the top of the rulebase toward the bottom. When traffic matches the conditions of a rule, the configured action is applied and the rulebase evaluation normally stops for that connection. This makes rule order important: a broad rule placed above a more specific rule can prevent the specific rule from being reached. Administrators should therefore place more specific rules appropriately and avoid unnecessary broad rules that could shadow later entries. The exact processing can depend on rule type and policy architecture, but top-down evaluation is the fundamental rulebase concept.<\/span><\/p>\n<p><b>Question 36. What is the purpose of the Cleanup Rule in a Check Point Access Control policy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide a final action for traffic that did not match earlier rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To restart the Security Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To delete all unused objects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To synchronize ThreatCloud intelligence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To provide a final action for traffic that did not match earlier rules<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cleanup Rule is placed at the end of an Access Control policy to define how traffic that does not match earlier rules should be handled. It commonly uses a Drop action and logging, depending on the organization&#8217;s security requirements. The cleanup rule provides a predictable final behavior instead of leaving unmatched traffic without an explicitly configured policy action. It does not restart the gateway, delete unused objects, or synchronize ThreatCloud information. Administrators should review the cleanup rule carefully because it can affect any connection that does not match a preceding rule. Therefore, its primary purpose is to provide a final action for unmatched traffic.<\/span><\/p>\n<p><b>Question 37. Which object type is commonly used to group multiple Service objects for easier policy management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service Group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway Cluster<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Service Group<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Service Group is used to combine multiple Service objects into a logical collection. This allows administrators to reference several related services in a single Access Control rule instead of adding each service individually. For example, a group could contain several approved application services that need the same security treatment. Host Groups are used for hosts, Network objects represent networks, and Gateway Clusters represent groups of gateways in a cluster configuration. Grouping objects can make policies more concise and easier to maintain. Therefore, Service Group is the appropriate object type for organizing multiple service objects.<\/span><\/p>\n<p><b>Question 38. Which Check Point policy is primarily responsible for controlling network access based on sources, destinations, services, and applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access Control Policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat Prevention Policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mobile Access Policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> QoS Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Access Control Policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Access Control Policy is primarily responsible for controlling network access using criteria such as source, destination, services, applications, users, and other supported policy attributes. Rules can accept, drop, or otherwise handle matching traffic according to the configured action. Threat Prevention Policy controls how Threat Prevention protections are applied, while Mobile Access Policy is associated with remote-access capabilities and QoS Policy addresses traffic prioritization and bandwidth management where supported. Access Control therefore serves as the central policy framework for deciding whether network traffic is permitted or blocked based on defined security criteria.<\/span><\/p>\n<p><b>Question 39. Which Check Point feature can identify users and associate their identities with network activity for policy enforcement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat Extraction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identity Awareness<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anti-Bot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat Emulation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Identity Awareness<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity Awareness provides Check Point Security Gateways with information about user identities so policies can be based on users and groups rather than only IP addresses. This can allow administrators to create rules that apply to particular users, departments, or directory groups. Identity information can be obtained through supported identity sources and mechanisms depending on the deployment. Threat Extraction sanitizes files, Anti-Bot focuses on malicious bot communication, and Threat Emulation analyzes suspicious files in an isolated environment. Therefore, Identity Awareness is the feature designed to associate users with network activity for identity-based security policy enforcement.<\/span><\/p>\n<p><b>Question 40. What is the purpose of an Access Control rule that uses an Accept action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To discard matching traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To disable all security blades<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To permit matching traffic according to the rule conditions and enabled protections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To delete the matching network object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To permit matching traffic according to the rule conditions and enabled protections<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Access Control rule using the Accept action permits traffic that matches the rule&#8217;s defined conditions, subject to other applicable security protections and policy processing. The rule may specify sources, destinations, services, applications, users, and other criteria. Accept does not mean that every security inspection is bypassed; other enabled protections can still inspect the permitted connection according to the relevant configuration. A Drop action discards matching traffic, while disabling security blades or deleting objects are unrelated operations. Therefore, the purpose of an Accept rule is to permit matching traffic under the conditions defined by the security policy.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Checkpoint 156-590 Exam Dumps and Practice Test Dumps &nbsp; Question 21. Which Check Point component is responsible for managing security policies and configuring Security Gateways? ThreatCloud Security Management Server Security Gateway Identity Awareness Correct Answer: 2. Security Management Server Explanation :- The Security Management Server is responsible for centralized management of Check Point [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22557"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22557"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22557\/revisions"}],"predecessor-version":[{"id":22558,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22557\/revisions\/22558"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}