
Welcome to lesson 11! If you remember, in lesson 7 we mentioned that Check Point has three types of Security Policy. These are:
- Access Control;
- Threat Prevention;
- Desktop Security.
We have already covered most of the blades in the Access Control policy, the main task of which is to control traffic or content. The Firewall, Application Control, URL Filtering, and Content Awareness blades reduce the attack surface by blocking unnecessary elements. In this lesson, we will discuss the policy Threat Prevention, which aims to inspect the content that has already passed through Access Control.
Threat Prevention Policy
The Threat Prevention policy includes the following blades:
- IPS — intrusion prevention system;
- Anti-Bot — botnet detection (traffic to C&C servers);
- Anti-Virus — file and URL scanning;
- Threat Emulation — file emulation (sandbox);
- Threat Extraction — cleaning files of active content.
This topic is VERY extensive and unfortunately our course does not include a detailed examination of each blade. This is already beyond the scope for beginners. Although for many, Threat Prevention might be one of the main topics. However, we will cover the process of applying the Threat Prevention policy. We will also conduct a small, yet very useful and demonstrative test. Below, as usual, is the video lesson.
For a more detailed understanding of the blades in Threat Prevention, I recommend our previously published courses for review:
- Check Point to the Max;
- Check Point SandBlast.
You can find them .
Video lesson

Stay tuned for more and join our 🙂
Source: habr.com
