ExamGecko
Home / Checkpoint / 156-215.81 / List of questions
Ask Question

Checkpoint 156-215.81 Practice Test - Questions Answers, Page 6

List of questions

Question 51

Report Export Collapse

You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?

fwd
fwd
fwm
fwm
cpd
cpd
cpwd
cpwd
Suggested answer: B
Explanation:

Thefwmprocess is responsible for managing the communication between the SmartConsole and the Security Management Server.It can only be seen on a Management Server12.

Reference:Check Point Processes and Daemons,Check Point CCSA - R81: Practice Test & Explanation

asked 16/09/2024
Rahul Manikpuri
41 questions

Question 52

Report Export Collapse

R80.10 management server can manage gateways with which versions installed?

Versions R77 and higher
Versions R77 and higher
Versions R76 and higher
Versions R76 and higher
Versions R75.20 and higher
Versions R75.20 and higher
Version R75 and higher
Version R75 and higher
Suggested answer: B
Explanation:

The R80.10 management server can manage gateways with versions R76 and higher34. Versions lower than R76 are not supported by the R80.10 management server.

Reference:Check Point R80.10 Release Notes,Free Check Point CCSA Sample Questions and Study Guide

asked 16/09/2024
Tim Wersinger
46 questions

Question 53

Report Export Collapse

You want to verify if there are unsaved changes in GAiA that will be lost with a reboot. What command can be used?

show unsaved
show unsaved
show save-state
show save-state
show configuration diff
show configuration diff
show config-state
show config-state
Suggested answer: D
Explanation:

The commandshow config-statecan be used to verify if there are unsaved changes in GAiA that will be lost with a reboot . The other commands are not valid in GAiA.

Reference: [Check Point GAiA Administration Guide], [Check Point CCSA - R81: Practice Test & Explanation]

asked 16/09/2024
Fatima Giordano
52 questions

Question 54

Report Export Collapse

In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?

SND is a feature to accelerate multiple SSL VPN connections
SND is a feature to accelerate multiple SSL VPN connections
SND is an alternative to IPSec Main Mode, using only 3 packets
SND is an alternative to IPSec Main Mode, using only 3 packets
SND is used to distribute packets among Firewall instances
SND is used to distribute packets among Firewall instances
SND is a feature of fw monitor to capture accelerated packets
SND is a feature of fw monitor to capture accelerated packets
Suggested answer: C
Explanation:

The Secure Network Distributor (SND) is a feature of the Security Gateway that is used to distribute packets among Firewall instances . It improves the performance and scalability of the Firewall by utilizing multiple CPU cores. The other options are not related to SND.

Reference: [Check Point Security Gateway Architecture and Packet Flow], [Free Check Point CCSA Sample Questions and Study Guide]

asked 16/09/2024
Nikhil George
38 questions

Question 55

Report Export Collapse

Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.

Symmetric routing
Symmetric routing
Failovers
Failovers
Asymmetric routing
Asymmetric routing
Anti-Spoofing
Anti-Spoofing
Suggested answer: B
Explanation:

The Sticky Decision Function (SDF) is required to preventfailoversin an Active-Active cluster. The SDF ensures that the same cluster member handles all connections that belong to a certain session.If the SDF is not enabled, different cluster members may handle different connections of the same session, which may cause a failover or a drop12.

Reference:ClusterXL Administration Guide R81,Check Point CCSA - R81: Practice Test & Explanation

asked 16/09/2024
Ayanda Zwane
36 questions

Question 56

Report Export Collapse

What are the steps to configure the HTTPS Inspection Policy?

Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
Go to Application&url filtering blade > Advanced > Https Inspection > Policy
Go to Application&url filtering blade > Advanced > Https Inspection > Policy
Go to Manage&Settings > Blades > HTTPS Inspection > Policy
Go to Manage&Settings > Blades > HTTPS Inspection > Policy
Go to Application&url filtering blade > Https Inspection > Policy
Go to Application&url filtering blade > Https Inspection > Policy
Suggested answer: C
Explanation:

The steps to configure the HTTPS Inspection Policy are as follows34:

Go toManage & Settings>Blades>HTTPS Inspection>Policy.

Click onNew HTTPS Inspection Ruleor select an existing rule and click onEdit Rule.

Define theSource,Destination, andActionfor the rule. The action can be eitherInspect,Bypass, orAsk.

Click onOKand then onInstall Policyto apply the changes.

Reference:HTTPS Inspection R81 Administration Guide,Check Point CCSA - R81: Practice Test & Explanation

asked 16/09/2024
Péter Szittya
50 questions

Question 57

Report Export Collapse

What is the difference between SSL VPN and IPSec VPN?

IPSec VPN does not require installation of a resident VPN client
IPSec VPN does not require installation of a resident VPN client
SSL VPN requires installation of a resident VPN client
SSL VPN requires installation of a resident VPN client
SSL VPN and IPSec VPN are the same
SSL VPN and IPSec VPN are the same
IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser
IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser
Suggested answer: D
Explanation:

The difference between SSL VPN and IPSec VPN is that IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed browser5. IPSec VPN uses a pre-shared key or certificates to authenticate the endpoints and encrypts the data at the network layer. SSL VPN uses SSL/TLS protocols to authenticate the endpoints and encrypts the data at the application layer.

Reference:Check Point Remote Access VPN Administration Guide R81, [Free Check Point CCSA Sample Questions and Study Guide]

asked 16/09/2024
Herr Alexandre Fleider
46 questions

Question 58

Report Export Collapse

Which statement is NOT TRUE about Delta synchronization?

Using UDP Multicast or Broadcast on port 8161
Using UDP Multicast or Broadcast on port 8161
Using UDP Multicast or Broadcast on port 8116
Using UDP Multicast or Broadcast on port 8116
Quicker than Full sync
Quicker than Full sync
Transfers changes in the Kernel tables between cluster members
Transfers changes in the Kernel tables between cluster members
Suggested answer: A
Explanation:

The statement that is not true about Delta synchronization is that it uses UDP Multicast or Broadcast on port8161.The correct port number for Delta synchronization is811612. The other statements are true about Delta synchronization.

Reference:ClusterXL Administration Guide R81,Check Point CCSA - R81: Practice Test & Explanation

asked 16/09/2024
Elena Albu
44 questions

Question 59

Report Export Collapse

Under which file is the proxy arp configuration stored?

$FWDIR/state/proxy_arp.conf on the management server
$FWDIR/state/proxy_arp.conf on the management server
$FWDIR/conf/local.arp on the management server
$FWDIR/conf/local.arp on the management server
$FWDIR/state/_tmp/proxy.arp on the security gateway
$FWDIR/state/_tmp/proxy.arp on the security gateway
$FWDIR/conf/local.arp on the gateway
$FWDIR/conf/local.arp on the gateway
Suggested answer: D
Explanation:

The file that stores the proxy arp configuration is$FWDIR/conf/local.arpon the gateway3. The other files are not related to proxy arp configuration.

Reference:How to configure Proxy ARP for Manual NAT on Security Gateway, [Check Point CCSA - R81: Practice Test & Explanation]

asked 16/09/2024
G C
51 questions

Question 60

Report Export Collapse

Customer's R80 management server needs to be upgraded to R80.10. What is the best upgrade method when the management server is not connected to the Internet?

Export R80 configuration, clean install R80.10 and import the configuration
Export R80 configuration, clean install R80.10 and import the configuration
CPUSE online upgrade
CPUSE online upgrade
CPUSE offline upgrade
CPUSE offline upgrade
SmartUpdate upgrade
SmartUpdate upgrade
Suggested answer: C
Explanation:

The best upgrade method when the management server is not connected to the Internet is CPUSE offline upgrade . This method allows you to download the upgrade package from another source and install it manually on the management server. The other methods require Internet connection or are not supported for R80.10.

Reference: [R80.10 Upgrade Verification and FAQ], [Check Point CCSA - R81: Practice Test & Explanation]

asked 16/09/2024
Franjo Tomurad
34 questions
Total 401 questions
Go to page: of 41