|
Section 1:
Introduction to Quantum Security
|
Weight:
- |
Key Concepts:
- Check Point Three-Tier Architecture (Security Management Server, Security Gateway, SmartConsole)
- Gaia Portal and Gaia Command Line Interface (CLI)
- SmartConsole navigation (GATEWAYS & SERVERS, SECURITY POLICIES, LOGS & EVENTS, MANAGE & SETTINGS Views).
What You Need to Know/Be Able to Do:
- Identify and explain the primary components of the Check Point Three-Tier Architecture and their interoperation.
- Navigate and perform basic exploration of Gaia on various Check Point components (SMS, Log Server, Gateway Cluster Members).
- Connect to and effectively navigate the SmartConsole interface.
Associated Lab Exercises:
- Explore Gaia on the Security Management Server, Dedicated Log Server, and Security Gateway Cluster Members
- Connect to SmartConsole and navigate its various views.
Common Pitfalls:
- Misunderstanding the distinct roles of the Management Server and Security Gateway.
- Initial connectivity issues between SmartConsole and the Management Server.
- Difficulty navigating the different SmartConsole views efficiently.
|
|
Section 2:
Administrator Account Management
|
Weight:
- |
Key Concepts:
- Purpose and types of SmartConsole administrator accounts
- Administrator collaboration features: session management, concurrent administration, concurrent policy installation
- Administrator profiles and permissions
What You Need to Know/Be Able to Do:
- Explain the purpose and functionality of SmartConsole administrator accounts.
- Create new administrators and assign appropriate profiles.
- Manage concurrent administrator sessions, including taking over and verifying session status
Associated Lab Exercises:
- Create New Administrators and Assign Profiles.
- Test Administrator Profile Assignments.
- Manage Concurrent Administrator Sessions.
- Take Over Another Session and Verify Session Status.
Common Pitfalls:
- Incorrectly assigning permissions, leading to access issues
- Challenges with concurrent administration, such as session conflicts or understanding changes.
- Leaving active sessions by forgetting to log out properly.
|
|
Section 3:
Object Management
|
Weight:
- |
Key Concepts:
- Purpose and importance of SmartConsole Objects.
- Types of SmartConsole Objects: Physical (e.g., Gateways & Servers) and Logical (e.g., Network Objects, Service Objects).
- Object properties and configuration.
What You Need to Know/Be Able to Do:
- Explain the role of SmartConsole Objects in building security policies
- Identify and differentiate between various physical and logical object types
- View, modify, and manage existing GATEWAYS & SERVERS, Network, and Service Objects.
Associated Lab Exercises:
- View and Modify GATEWAYS & SERVERS Objects
- View and Modify Network Objects
- View and Modify Service Objects
Common Pitfalls:
- Creating redundant or incorrectly configured objects.
- Misunderstanding the impact of object changes on existing policies.
- Difficulty locating desired objects within a large environment.
|
|
Section 4:
Security Policy Management
|
Weight:
- |
Key Concepts:
- Purpose and fundamental elements of Security Policies.
- Security Rule Base structure, order, and processing.
- Features and capabilities that enhance policy configuration and management (e.g., rule comments, sections).
- Policy installation process and verification.
What You Need to Know/Be Able to Do:
- Explain the role of Security Policies in controlling network traffic.
- Identify essential elements of a security policy (source, destination, service, action, track).
- Verify, modify, install, and test the Standard Security Policy.
Associated Lab Exercises:
- Verify the Security Policy.
- Modify Security Policies.
- Install the Standard Security Policy.
- Test the Security Policy.
Common Pitfalls:
- Incorrect rule order leading to unintended traffic flow.
- Failing to verify policy before installation, causing issues.
- Policy installation failures
|
|
Section 5:
Policy Layers
|
Weight:
- |
Key Concepts:
- Check Point policy layer concept (Ordered Layers, Shared Inline Layers).
- How policy layers affect traffic inspection and rule processing.
- Benefits of using policy layers for modularity and organization.
What You Need to Know/Be Able to Do:
- Demonstrate a clear understanding of the policy layer concept.
- Explain the traffic inspection flow through different policy layers.
- Add, configure, deploy, and test rules within Ordered Layers and create/test Inline DMZ Layers.
Associated Lab Exercises:
- Add an Ordered Layer.
- Configure and Deploy the Ordered Layer Rules.
- Test the Ordered Layer Policy.
- Create an Inline DMZ Layer.
- Test the Inline DMZ Layer
Common Pitfalls:
- Misunderstanding the order of inspection between layers.
- Incorrectly linking or unlinking shared layers.
- Unexpected traffic behavior due to layer misconfiguration.
|
|
Section 6:
Security Operations Monitoring
|
Weight:
- |
Key Concepts:
- Purpose of Security Operations Monitoring (SmartLog, SmartEvent, Monitoring Blade).
- Log Server configuration and tuning.
- Predefined and custom queries for log filtering.
- Monitoring the state and performance of Check Point systems.
What You Need to Know/Be Able to Do:
- Explain the importance of monitoring security operations.
- Configure Log Management and tune Log Server settings.
- Effectively use predefined and custom queries to analyze logging results.
- Monitor the status and health of Check Point systems via the Monitoring Blade.
Associated Lab Exercises:
- Configure Log Management.
- Enhance Rulebase View, Rules, and Logging.
- Review Logs and Search for Data.
- Configure the Monitoring Blade.
- Monitor the Status of the Systems.
Common Pitfalls:
- Overlooking critical alerts due to poor log filtering.
- Performance issues on the Log Server due to improper tuning.
- Difficulty interpreting system status indicators.
|
|
Section 7:
Identity Awareness
|
Weight:
- |
Key Concepts:
- Purpose and benefits of the Identity Awareness solution.
- Essential elements of Identity Awareness (Identity Collector, User Access Roles).
- Integration with security policies.
What You Need to Know/Be Able to Do:
- Explain how Identity Awareness enhances security by integrating user and computer identities into the security policy.
- Identify the key components and their roles in the Identity Awareness solution.
- Adjust the Security Policy for Identity Awareness, configure the Identity Collector, define User Access Roles, and test functionality.
Associated Lab Exercises:
- Adjust the Security Policy for Identity Awareness.
- Configure the Identity Collector.
- Define the User Access Role.
- Test Identity Awareness.
Common Pitfalls:
- Improperly configured Identity Sources preventing user identification.
- Rules not enforcing correctly due to misconfigured user access roles.
- Configuration and communication issues with user authentication and identity retrieval systems.
|
|
Section 8:
HTTPS Inspection
|
Weight:
- |
Key Concepts:
- Purpose and necessity of the HTTPS Inspection solution.
- Essential elements of HTTPS Inspection (certificates, trusted CAs).
- Impact on traffic analysis and security
What You Need to Know/Be Able to Do:
- Explain why HTTPS Inspection is crucial for deep packet inspection of encrypted traffic.
- Identify the components required for successful HTTPS Inspection.
- Enable HTTPS Inspection, adjust Access Control Rules, deploy the Security Gateway Certificate, and test/analyze policy with HTTPS Inspection.
Associated Lab Exercises:
- Enable HTTPS Inspection.
- Adjust Access Control Rules.
- Deploy the Security Gateway Certificate.
- Test and Analyze Policy with HTTPS Inspection.
Common Pitfalls:
- Certificate trust issues causing browser warnings.
- Performance degradation due to improper configuration.
- Application failures from https inspection interference.
|
|
Section 9:
Application Control and URL Filtering
|
Weight:
- |
Key Concepts:
- Purpose and benefits of Application Control and URL Filtering solutions.
- Essential elements: Application objects, URL categories, custom URL lists.
- Integration with Access Control Policy.
What You Need to Know/Be Able to Do:
- Explain how Application Control and URL Filtering enhance granular control over web traffic.
- Identify the key components and functionalities of both solutions.
- Adjust the Access Control Policy, create and adjust Application Control and URL Filtering Rules, and test their effectiveness.
Associated Lab Exercises:
- Adjust the Access Control Policy.
- Create and Adjust Application Control and URL Filtering Rules.
- Test and Adjust the Application Control and URL Filtering Rules.
Common Pitfalls:
- Overly restrictive policies blocking legitimate applications/websites.
- Performance impact from extensive rule sets.
- Application and Website misidentification.
|
|
Section 10:
Threat Prevention Fundamentals
|
Weight:
- |
Key Concepts:
- Purpose and importance of the Threat Prevention solution.
- Essential elements of Autonomous Threat Prevention (e.g., Anti-Bot, Anti-Virus, IPS, SandBlast Emulation/ Extraction).
- Threat profiles and their application.
What You Need to Know/Be Able to Do:
- Understand the comprehensive capabilities of Check Point’s Threat Prevention.
- Identify the core components of Autonomous Threat Prevention.
- Enable and test Autonomous Threat Prevention features.
Associated Lab Exercises:
- Enable Autonomous Threat Prevention.
- Test Autonomous Threat Prevention
Common Pitfalls:
- High false-positive rates disrupting legitimate traffic.
- Performance impact due to aggressive threat prevention profiles. •
- Out of date signatures and engines.
|
|
Info
|
|