A security administrator manages a distributed Check Point deployment where four Security Gateways send logs to a dedicated Log Server. The administrator needs to grant a junior colleague read-only access to logs and objects in SmartConsole without allowing policy installation or object modification. Which configuration should the administrator apply?
Creating an administrator with a read-only permission profile grants visibility to logs and objects while denying write operations such as policy installation or object modification. Permission profiles in SmartConsole define granular access, and a read-only profile restricts the user to viewing data only, which matches the requirement precisely without over-provisioning rights.
Why this answer
Granting least-privilege access in a distributed deployment is done by creating an administrator account and assigning a permission profile that limits the user to viewing logs and objects. A read-only profile enforces this at the management layer, so the colleague can inspect data without the ability to install policy or change objects, which is exactly what the scenario requires.
Exam trap
The trap here is assuming that connectivity controls such as trusted clients also control what an authenticated administrator is permitted to do.