- Products
- Learn
- Local User Groups
- Partners
- More
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hello, Colleagues!
I just tryed to pass practice CCSA test on official site:
https://www.checkpoint.com/training/ccsa/chapter3/#
I think there is a mistake in 5th question, listed on the screen below. Can anyone explain me, why 1st statement is incorrect? About 4th statement, there is no option about implicit clean-up in Global Properties in R80.20.
I'd say that the last answer (Global Properties) would be more correct under R77.30 and earlier management as implied rules of any kind (which would include the implicit cleanup rule) could only be modified through the Global Properties, but the first answer (Policy Layer) would be more correct under R80+ management due to the ability to set the action of the implicit cleanup rule per-layer that was added in R80+.
Agree, this looks like an incorrect answer.
Paging @shay_solomon
I think the question and the answers are not clear😀.
Security Management R80.20 Administration Guide:
CUT>>>
Implied rules
The default rules that are available as part of the Global properties configuration and cannot be edited. You can only select the implied rules and configure their position in the Rule Base:
- First - Applied first, before all other rules in the Rule Base - explicit or implied
- Last - Applied last, after all other rules in the Rule Base - explicit or implied, but before the Implicit Cleanup Rule
- Before Last - Applied before the last explicit rule in the Rule Base
Implied rules are configured to allow connections for different services that the Security Gateway uses. For example, the Accept Control Connections rules allow packets that control these services:
- Installation of the security policy on a Security Gateway
- Sending logs from a Security Gateway to the Security Management Server
- Connecting to third party application servers, such as RADIUS and TACACS authentication servers
Implicit cleanup rule
The default "catch-all" rule for the Layer that deals with traffic that does not match any explicit or implied rules in the Layer. It is made automatically when you create a Layer.
Implicit cleanup rules do not show in the Rule Base.
For R80.10 later version Security Gateways, the default implicit cleanup rule action is Drop. This is because most Policies have Whitelist rules (the Accept action). If the Layer has Blacklist rules (the Drop action), you can change the action of the implicit cleanup rule to Accept in the Layer Editor.
For R77.30 or earlier versions Security Gateways, the action of the implicit rule depends on the Ordered Layer:
Drop - for the Network Layer
Accept - for a Layer with Applications and URL Filtering enabled
Note - If you change the default values, the policy installation will fail on R77.30 or earlier versions Security Gateways.
<<<CUT
PS: I had two questions in my CCSM VUE exam with commands that no longer existed.
I'd say that the last answer (Global Properties) would be more correct under R77.30 and earlier management as implied rules of any kind (which would include the implicit cleanup rule) could only be modified through the Global Properties, but the first answer (Policy Layer) would be more correct under R80+ management due to the ability to set the action of the implicit cleanup rule per-layer that was added in R80+.
Thank you very much for explaination, it's clear now. So, I think, this question and 4th answer is a some kind of 77.30 legacy. But i still don't know, how should the one answer to the question like this in real exam? 🙂
Can't really answer your question, only @Jason_Tugwell could...
For the purpose of the exam, the answer in the screen shot with the green check, is the correct answer.
This question will be one of ones that I am looking to have re-evaluated because as Heiko stated, it is not exactly clear, IMO.
Thanks,
Tug
Agreed Dameon, hence my use of the term "most correct" or its corollary "choose the BEST answer" as I believe it is stated on the exam. 🙂
Hi guys,
I agree with Dameon's and Timothy's answer.
I think the question and answer is not good for a learner.
I'd make the answer clear😀.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY