<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conflict on Exception - Why is the most liberal action taken? in Training and Certification</title>
    <link>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121089#M1747</link>
    <description>&lt;P&gt;Thinking about it logically, an exception is generally to give you the option to reduce the level of enforcement for a specific protection, not increase it.&lt;BR /&gt;Therefore, to me at least, it would make sense that if there was a conflict for an exception, the least restrictive one would apply.&amp;nbsp;&lt;BR /&gt;Not sure that's the official reason, but that's my take.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jun 2021 04:10:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-06-14T04:10:08Z</dc:date>
    <item>
      <title>Conflict on Exception - Why is the most liberal action taken?</title>
      <link>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121082#M1746</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Hi there guys,&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I'm currently looking over some material for the CCSA (have been particularly aided by ExamTopics - excellent for practice exam questions and &lt;EM&gt;actually&lt;/EM&gt; free, thank God) and have come across a questions regarding conflict resolution within Security Policies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"What are the three conflict resolution rules in the Threat Prevention Policy Layers?"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Answer&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;"Conflict on action, conflict on exception, and conflict on settings"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Description&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;After doing a bit of reading up on these conflict resolution rules, I was particularly perplexed by the description for the Conflict on Exception which reads (&lt;SPAN&gt;CCSA R80.10 guide page 407 - I know this is a bit outdated as we're at R81.10 now... maybe this has changed?):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Conflict on exception: The exceptions for a specified scope is different between layers. The action taken will be the most liberal, or least restrictive."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Any Ideas?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone explain why, if the conflict on action opts for the &lt;EM&gt;most&lt;/EM&gt; restrictive option when a conflict occurs, the conflict on exception vouches for the &lt;EM&gt;least&lt;/EM&gt; restrictive option? This seems to me like it might dangerously expose the system? Any insight is greatly appreciated.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;Thanks Check Mates,&lt;/FONT&gt;&amp;nbsp;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":clinking_beer_mugs:"&gt;🍻&lt;/span&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Vivus&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 00:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121082#M1746</guid>
      <dc:creator>Vivus</dc:creator>
      <dc:date>2021-06-14T00:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Conflict on Exception - Why is the most liberal action taken?</title>
      <link>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121089#M1747</link>
      <description>&lt;P&gt;Thinking about it logically, an exception is generally to give you the option to reduce the level of enforcement for a specific protection, not increase it.&lt;BR /&gt;Therefore, to me at least, it would make sense that if there was a conflict for an exception, the least restrictive one would apply.&amp;nbsp;&lt;BR /&gt;Not sure that's the official reason, but that's my take.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 04:10:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121089#M1747</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-14T04:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Conflict on Exception - Why is the most liberal action taken?</title>
      <link>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121415#M1751</link>
      <description>&lt;P&gt;Hi PhoneBoy, thanks for the response. I had considered that, but then thought that if there was a lack of exception in one rule base it would imply that there may be reason to keep 'exceptional individuals' out, which compromises security if the two rule bases are merged and the least restrictive option is held.&lt;/P&gt;&lt;P&gt;I don't really know, maybe I'm overthinking it, haha.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 03:52:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121415#M1751</guid>
      <dc:creator>Vivus</dc:creator>
      <dc:date>2021-06-17T03:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Conflict on Exception - Why is the most liberal action taken?</title>
      <link>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121458#M1752</link>
      <description>&lt;P&gt;As a FYI, the source material is not up to date as that&amp;nbsp;question is no longer on the exam.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tug&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 12:18:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Training-and-Certification/Conflict-on-Exception-Why-is-the-most-liberal-action-taken/m-p/121458#M1752</guid>
      <dc:creator>Jason_Tugwell</dc:creator>
      <dc:date>2021-06-17T12:18:40Z</dc:date>
    </item>
  </channel>
</rss>

