ExamGecko
Home Home / Checkpoint / 156-315.81

Checkpoint 156-315.81 Practice Test - Questions Answers, Page 32

Question list
Search
Search

List of questions

Search

View the rule below. What does the lock-symbol in the left column mean? (Choose the BEST answer.)

A.
The current administrator has read-only permissions to Threat Prevention Policy.
A.
The current administrator has read-only permissions to Threat Prevention Policy.
Answers
B.
Another user has locked the rule for editing.
B.
Another user has locked the rule for editing.
Answers
C.
Configuration lock is present. Click the lock symbol to gain read-write access.
C.
Configuration lock is present. Click the lock symbol to gain read-write access.
Answers
D.
The current administrator is logged in as read-only because someone else is editing the policy.
D.
The current administrator is logged in as read-only because someone else is editing the policy.
Answers
Suggested answer: B

Explanation:

The lock symbol in the left column of the rule means that another user has locked the rule for editing. This is to prevent multiple users from editing the same rule at the same time and causing conflicts.

Reference: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TP-Policy/TP-Policy-Edit-Rules.htm

By default, which port does the WebUI listen on?

A.
80
A.
80
Answers
B.
4434
B.
4434
Answers
C.
443
C.
443
Answers
D.
8080
D.
8080
Answers
Suggested answer: C

Explanation:

The default port for the Gaia WebUI Portal is HTTPS 443. This is the standard port for secure web communication over SSL/TLS. Changing the port may cause inconsistency with the settings on the SmartConsole and is not recommended unless necessary. To change the port, you can use the CLISH commandset web ssl-port and save the configuration.

Reference:13

Which VPN routing option uses VPN routing for every connection a satellite gateway handles?

A.
To satellites through center only
A.
To satellites through center only
Answers
B.
To center only
B.
To center only
Answers
C.
To center and to other satellites through center
C.
To center and to other satellites through center
Answers
D.
To center, or through the center to other satellites, to Internet and other VPN targets
D.
To center, or through the center to other satellites, to Internet and other VPN targets
Answers
Suggested answer: D

Explanation:

This VPN routing option uses VPN routing for every connection a satellite gateway handles, regardless of the destination. This means that all traffic from the satellite gateway will go through the VPN tunnel to the center gateway, and then be routed to the appropriate destination, whether it is another satellite, the Internet, or another VPN target. This option provides the highest level of security and control, but also consumes more bandwidth and processing power.

Kofi, the administrator of the ALPHA Corp network wishes to change the default Gaia WebUI Portal port number currently set on the default HTTPS port. Which CLISH commands are required to be able to change this TCP port?

A.
set web ssl-port <new port number>
A.
set web ssl-port <new port number>
Answers
B.
set Gaia-portal port <new port number>
B.
set Gaia-portal port <new port number>
Answers
C.
set Gaia-portal https-port <new port number>
C.
set Gaia-portal https-port <new port number>
Answers
D.
set web https-port <new port number>
D.
set web https-port <new port number>
Answers
Suggested answer: A

Explanation:

The CLISH command to change the default Gaia WebUI Portal port number isset web ssl-port <new port number>. This command will change the port that the WebUI listens on for HTTPS connections. After changing the port, you need to save the configuration withsave configand verify that the change was applied withshow web ssl-port. You also need to update the Main URL in the Platform Portal section of the gateway object in SmartConsole and install the policy.

Joey want to configure NTP on R81 Security Management Server. He decided to do this via WebUI. What is the correct address to access the Web UI for Gaia platform via browser?

A.
https://<Device_IP_Adress>
A.
https://<Device_IP_Adress>
Answers
B.
http://<Device IP_Address>:443
B.
http://<Device IP_Address>:443
Answers
C.
https://<Device_IP_Address>:10000
C.
https://<Device_IP_Address>:10000
Answers
D.
https://<Device_IP_Address>:4434
D.
https://<Device_IP_Address>:4434
Answers
Suggested answer: A

Explanation:

The correct address to access the Web UI for Gaia platform via browser is https://<Device_IP_Adress>. This will open the Gaia Portal login page, where you can enter your username and password to access the Gaia configuration options. By default, the Web UI listens on port 443 for HTTPS connections, but you can change it using the CLISH commandset web ssl-port .

The ''Hit count'' feature allows tracking the number of connections that each rule matches. Will the Hit count feature work independently from logging and Track the hits if the Track option is set to ''None''?

A.
No, it will work independently. Hit Count will be shown only for rules Track option set as Log or alert.
A.
No, it will work independently. Hit Count will be shown only for rules Track option set as Log or alert.
Answers
B.
Yes it will work independently as long as ''analyze all rules'' tick box is enabled on the Security Gateway.
B.
Yes it will work independently as long as ''analyze all rules'' tick box is enabled on the Security Gateway.
Answers
C.
No, it will not work independently because hit count requires all rules to be logged.
C.
No, it will not work independently because hit count requires all rules to be logged.
Answers
D.
Yes it will work independently because when you enable Hit Count, the SMS collects the data from supported Security Gateways.
D.
Yes it will work independently because when you enable Hit Count, the SMS collects the data from supported Security Gateways.
Answers
Suggested answer: D

Explanation:

The Hit Count feature allows tracking the number of connections that each rule matches, regardless of the Track option set for the rule. When you enable Hit Count, the Security Management Server collects the data from supported Security Gateways and displays it in SmartConsole. You can use the Hit Count feature to optimize your rule base by identifying unused or rarely used rules, or rules that match too many connections.

Fill in the blank: Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or ______ .

A.
On all satellite gateway to satellite gateway tunnels
A.
On all satellite gateway to satellite gateway tunnels
Answers
B.
On specific tunnels for specific gateways
B.
On specific tunnels for specific gateways
Answers
C.
On specific tunnels in the community
C.
On specific tunnels in the community
Answers
D.
On specific satellite gateway to central gateway tunnels
D.
On specific satellite gateway to central gateway tunnels
Answers
Suggested answer: C

Explanation:

Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or on specific tunnels in the community. Permanent VPN tunnels are always active and prevent VPN tunnel negotiation failures due to idle time or traffic volume. You can configure permanent VPN tunnels in SmartConsole by selecting the Permanent Tunnel option in the VPN Community Properties window.

True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway.

A.
True, CLI is the prefer method for Licensing
A.
True, CLI is the prefer method for Licensing
Answers
B.
False, Central License are handled via Security Management Server
B.
False, Central License are handled via Security Management Server
Answers
C.
False, Central Licenses are installed via Gaia on Security Gateways
C.
False, Central Licenses are installed via Gaia on Security Gateways
Answers
D.
True, Central License can be installed with CPLIC command on a Security Gateway
D.
True, Central License can be installed with CPLIC command on a Security Gateway
Answers
Suggested answer: D

Explanation:

In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway using the CPLIC command. The CPLIC command allows you to add, delete, or list Central Licenses on a Security Gateway from the command line. You need to provide the IP address of the Security Management Server and the license string as parameters for the CPLIC command.

In which VPN community is a satellite VPN gateway not allowed to create a VPN tunnel with another satellite VPN gateway?

A.
Pentagon
A.
Pentagon
Answers
B.
Combined
B.
Combined
Answers
C.
Meshed
C.
Meshed
Answers
D.
Star
D.
Star
Answers
Suggested answer: D

Explanation:

A star VPN community is a type of VPN community that allows a central gateway to create VPN tunnels with multiple satellite gateways or hosts, but does not allow satellite gateways or hosts to create VPN tunnels with each other. This type of community is suitable for hub-and-spoke topologies, where the central gateway acts as the hub and the satellite gateways or hosts act as the spokes. The central gateway can initiate or terminate VPN traffic to any satellite member, but the satellite members can only initiate or terminate VPN traffic to the central gateway.

When a packet arrives at the gateway, the gateway checks it against the rules in the hop Policy Layer, sequentially from top to bottom, and enforces the first rule that matches a packet. Which of the following statements about the order of rule enforcement is true?

A.
If the Action is Accept, the gateway allows the packet to pass through the gateway.
A.
If the Action is Accept, the gateway allows the packet to pass through the gateway.
Answers
B.
If the Action is Drop, the gateway continues to check rules in the next Policy Layer down.
B.
If the Action is Drop, the gateway continues to check rules in the next Policy Layer down.
Answers
C.
If the Action is Accept, the gateway continues to check rules in the next Policy Layer down.
C.
If the Action is Accept, the gateway continues to check rules in the next Policy Layer down.
Answers
D.
If the Action is Drop, the gateway applies the Implicit Clean-up Rule for that Policy Layer.
D.
If the Action is Drop, the gateway applies the Implicit Clean-up Rule for that Policy Layer.
Answers
Suggested answer: C

Explanation:

When a packet arrives at the gateway, the gateway checks it against the rules in the top Policy Layer, sequentially from top to bottom, and enforces the first rule that matches the packet. The order of rule enforcement depends on the action of the matching rule. If the action is Accept, the gateway allows the packet to pass through the gateway, but also continues to check rules in the next Policy Layer down. If the action is Drop, Reject, or Encrypt, the gateway applies that action to the packet and stops checking rules in that Policy Layer and any subsequent Policy Layers. If there is no matching rule in a Policy Layer, the gateway applies the Implicit Clean-up Rule for that Policy Layer, which is usually Drop.

Total 626 questions
Go to page: of 63