ExamGecko
Home Home / Checkpoint / 156-215.81

Checkpoint 156-215.81 Practice Test - Questions Answers, Page 2

Question list
Search
Search

Which Check Point software blade provides Application Security and identity control?

A.
Identity Awareness
A.
Identity Awareness
Answers
B.
Data Loss Prevention
B.
Data Loss Prevention
Answers
C.
URL Filtering
C.
URL Filtering
Answers
D.
Application Control
D.
Application Control
Answers
Suggested answer: D

Explanation:

The Check Point software blade that provides Application Security and identity control is Application Control3.Application Control enables network administrators to identify, allow, block, or limit usage of thousands of applications and millions of websites3. Therefore, the correct answer is D.Application Control

How are the backups stored in Check Point appliances?

A.
Saved as*.tar under /var/log/CPbackup/backups
A.
Saved as*.tar under /var/log/CPbackup/backups
Answers
B.
Saved as*tgz under /var/CPbackup
B.
Saved as*tgz under /var/CPbackup
Answers
C.
Saved as*tar under /var/CPbackup
C.
Saved as*tar under /var/CPbackup
Answers
D.
Saved as*tgz under /var/log/CPbackup/backups
D.
Saved as*tgz under /var/log/CPbackup/backups
Answers
Suggested answer: B

Explanation:

The backups are stored in Check Point appliances as *.tgz files under /var/CPbackup. This is the default location for backup files created by the backup command. Therefore, the correct answer is B. Saved as *.tgz under /var/CPbackup

You are going to perform a major upgrade. Which back up solution should you use to ensure your database can be restored on that device?

A.
backup
A.
backup
Answers
B.
logswitch
B.
logswitch
Answers
C.
Database Revision
C.
Database Revision
Answers
D.
snapshot
D.
snapshot
Answers
Suggested answer: D

Explanation:

The back up solution that should be used to ensure your database can be restored on that device is snapshot . A snapshot creates a binary image of the entire root (lv_current) disk partition. This includes Check Point products, configuration, and operating system. A snapshot can be used to restore a Security Gateway or Security Management Server to its previous state at any time . Therefore, the correct answer is D. snapshot.

Fill in the blank: The position of an implied rule is manipulated in the __________________ window.

A.
NAT
A.
NAT
Answers
B.
Firewall
B.
Firewall
Answers
C.
Global Properties
C.
Global Properties
Answers
D.
Object Explorer
D.
Object Explorer
Answers
Suggested answer: C

Explanation:

The position of an implied rule is manipulated in the Global Properties window. Implied rules are predefined rules that are not displayed in the rule base. They allow or block traffic for essential services such as communication with Check Point servers, logging, and VPN traffic.The position of an implied rule can be changed in the Global Properties > Firewall > Implied Rules section56.

Reference:How to view Implied Rules in R80.x / R81.x SmartConsole,Implied Rules

How can the changes made by an administrator before publishing the session be seen by a superuser administrator?

A.
By impersonating the administrator with the 'Login as...' option
A.
By impersonating the administrator with the 'Login as...' option
Answers
B.
They cannot be seen
B.
They cannot be seen
Answers
C.
From the SmartView Tracker audit log
C.
From the SmartView Tracker audit log
Answers
D.
From Manage and Settings > Sessions, right click on the session and click 'View Changes...'
D.
From Manage and Settings > Sessions, right click on the session and click 'View Changes...'
Answers
Suggested answer: D

Explanation:

The changes made by an administrator before publishing the session can be seen by a superuser administrator from Manage and Settings > Sessions, right click on the session and click 'View Changes...'.This option allows the superuser to review the changes made by another administrator in a pending session1.

Reference:Check Point R81 Security Management Administration Guide

Which Check Point software blade monitors Check Point devices and provides a picture of network and security performance?

A.
Application Control
A.
Application Control
Answers
B.
Threat Emulation
B.
Threat Emulation
Answers
C.
Logging and Status
C.
Logging and Status
Answers
D.
Monitoring
D.
Monitoring
Answers
Suggested answer: D

Explanation:

The Check Point software blade that monitors Check Point devices and provides a picture of network and security performance is Monitoring. The Monitoring Software Blade presents a complete picture of network and security performance, enabling fast responses to changes in traffic patterns or security events.It centrally monitors Check Point devices and alerts security administrators to changes to gateways, endpoints, tunnels, remote users and security activities234.

Reference:Monitoring Software Blade,Check Point Integrated Security Architecture,Support, Support Requests, Training, Documentation, and Knowledge base for Check Point products and services

Your internal networks 10.1.1.0/24, 10.2.2.0/24 and 192.168.0.0/16 are behind the Internet Security Gateway. Considering that Layer 2 and Layer 3 setup is correct, what are the steps you will need to do in SmartConsole in order to get the connection working?

A.
1. Define an accept rule in Security Policy.2. Define Security Gateway to hide all internal networks behind the gateway's external IP.3. Publish and install the policy.
A.
1. Define an accept rule in Security Policy.2. Define Security Gateway to hide all internal networks behind the gateway's external IP.3. Publish and install the policy.
Answers
B.
1. Define an accept rule in Security Policy.2. Define automatic NAT for each network to NAT the networks behind a public IP.3. Publish the policy.
B.
1. Define an accept rule in Security Policy.2. Define automatic NAT for each network to NAT the networks behind a public IP.3. Publish the policy.
Answers
C.
1. Define an accept rule in Security Policy.2. Define automatic NAT for each network to NAT the networks behind a public IP.3. Publish and install the policy.
C.
1. Define an accept rule in Security Policy.2. Define automatic NAT for each network to NAT the networks behind a public IP.3. Publish and install the policy.
Answers
D.
1. Define an accept rule in Security Policy.2. Define Security Gateway to hide all internal networks behind the gateway's external IP.3. Publish the policy.
D.
1. Define an accept rule in Security Policy.2. Define Security Gateway to hide all internal networks behind the gateway's external IP.3. Publish the policy.
Answers
Suggested answer: C

Explanation:

The steps you will need to do in SmartConsole in order to get the connection working behind the Internet Security Gateway are:

Define an accept rule in Security Policy. This rule allows the traffic from your internal networks to pass through the Security Gateway.

Define automatic NAT for each network to NAT the networks behind a public IP. This option translates the private IP addresses of your internal networks to a public IP address assigned by your ISP router. This way, your internal networks can communicate with the Internet using a valid IP address.

Publish and install the policy. This step applies the changes you made to the Security Gateway and activates the security and NAT rules.

True or False: The destination server for Security Gateway logs depends on a Security Management Server configuration.

A.
False, log servers are configured on the Log Server General Properties
A.
False, log servers are configured on the Log Server General Properties
Answers
B.
True, all Security Gateways will only forward logs with a SmartCenter Server configuration
B.
True, all Security Gateways will only forward logs with a SmartCenter Server configuration
Answers
C.
True, all Security Gateways forward logs automatically to the Security Management Server
C.
True, all Security Gateways forward logs automatically to the Security Management Server
Answers
D.
False, log servers are enabled on the Security Gateway General Properties
D.
False, log servers are enabled on the Security Gateway General Properties
Answers
Suggested answer: B

Explanation:

The destination server for Security Gateway logs depends on a Security Management Server configuration. This is true because the Security Management Server defines the log servers that receive logs from the Security Gateways.The log servers can be either the Security Management Server itself or a dedicated Log Server12.

Reference:Check Point R81 Logging and Monitoring Administration Guide,Check Point R81 Quantum Security Gateway Guide

Consider the Global Properties following settings:

The selected option ''Accept Domain Name over UDP (Queries)'' means:

A.
UDP Queries will be accepted by the traffic allowed only through interfaces with external anti-spoofing topology and this will be done before first explicit rule written by Administrator in a Security Policy.
A.
UDP Queries will be accepted by the traffic allowed only through interfaces with external anti-spoofing topology and this will be done before first explicit rule written by Administrator in a Security Policy.
Answers
B.
All UDP Queries will be accepted by the traffic allowed through all interfaces and this will be done before first explicit rule written by Administrator in a Security Policy.
B.
All UDP Queries will be accepted by the traffic allowed through all interfaces and this will be done before first explicit rule written by Administrator in a Security Policy.
Answers
C.
No UDP Queries will be accepted by the traffic allowed through all interfaces and this will be done before first explicit rule written by Administrator in a Security Policy.
C.
No UDP Queries will be accepted by the traffic allowed through all interfaces and this will be done before first explicit rule written by Administrator in a Security Policy.
Answers
D.
All UDP Queries will be accepted by the traffic allowed by first explicit rule written by Administrator in a Security Policy.
D.
All UDP Queries will be accepted by the traffic allowed by first explicit rule written by Administrator in a Security Policy.
Answers
Suggested answer: A

Explanation:

The selected option ''Accept Domain Name over UDP (Queries)'' means that UDP Queries will be accepted by the traffic allowed only through interfaces with external anti-spoofing topology and this will be done before first explicit rule written by Administrator in a Security Policy. This option enables the Security Gateway to accept DNS queries from external hosts and forward them to internal DNS servers. The queries are accepted by an implied rule that is applied before the explicit rules in the Security Policy. The implied rule only allows queries from interfaces that have external anti-spoofing groups defined .

Reference: Check Point R81 Quantum Security Gateway Guide, Implied Rules

How is communication between different Check Point components secured in R80? As with all questions, select the best answer.

A.
By using IPSEC
A.
By using IPSEC
Answers
B.
By using SIC
B.
By using SIC
Answers
C.
By using ICA
C.
By using ICA
Answers
D.
By using 3DES
D.
By using 3DES
Answers
Suggested answer: B

Explanation:

The communication between different Check Point components is secured in R80 by using SIC. SIC stands for Secure Internal Communication and it is a mechanism that ensures the authenticity and confidentiality of communication between Check Point components, such as Security Gateways, Security Management Servers, Log Servers, etc.SIC uses certificates issued by the Internal CA (ICA) and encryption algorithms such as AES-25634.

Reference:Check Point R81 Quantum Security Gateway Guide,Check Point R81 Quantum Security Management Administration Guide

Total 401 questions
Go to page: of 41