Geo-Updatable Objects

Hi I'm a new Check Point user with a recently deployed R80 gateway cluster.  I'm looking into implementing Geo-updatable objects instead of the traditional geo policy.  I work for a local municipality in the US so really, all traffic should be domestic.  I'd like to validate - Would I just need to apply a block rule from "any" to all countries except US and Canada and another corresponding block rule to any from all countries except US.  These rules would go just above my stealth rule, correct?

That's the basic idea, yes:

Screen Shot 2020-12-02 at 11.02.01 AM.png

However, you can get even more granular and allow access to, say, your website from anywhere but block everything else.

