ExamGecko
Home Home / Checkpoint / 156-315.81

Checkpoint 156-315.81 Practice Test - Questions Answers, Page 42

Question list
Search
Search

What are the available options for downloading Check Point hotfixes in Gala WebUI (CPUSE)?

A.
Manually, Scheduled, Automatic
A.
Manually, Scheduled, Automatic
Answers
B.
Manually, Automatic, Disabled
B.
Manually, Automatic, Disabled
Answers
C.
Manually, Scheduled, Disabled
C.
Manually, Scheduled, Disabled
Answers
D.
Manually, Scheduled, Enabled
D.
Manually, Scheduled, Enabled
Answers
Suggested answer: A

Explanation:

The available options for downloading Check Point hotfixes in Gaia WebUI (CPUSE) are Manually, Scheduled, and Automatic. These options can be configured in the CPUSE Settings tab of the Gaia Portal. The Manual option lets you download hotfixes manually from the Check Point Cloud or a local Deployment Agent when you need them. The Scheduled option lets you download hotfixes automatically at a specified time interval (daily, weekly, or monthly). The Automatic option lets you download hotfixes automatically as soon as they are available.

html_frameset.htm?topic=documents/R77/CP_R77_Gaia_AdminWebAdminGuide/112109

The WebUI offers several methods for downloading hotfixes via CPUSE except:

A.
Automatic
A.
Automatic
Answers
B.
Force override
B.
Force override
Answers
C.
Manually
C.
Manually
Answers
D.
Scheduled
D.
Scheduled
Answers
Suggested answer: B

Explanation:

The WebUI offers three methods for downloading hotfixes via CPUSE: Automatic, Manually, and Scheduled. Force override is not a valid method for downloading hotfixes. Force override is an option that can be used when installing a hotfix to override the compatibility check and force the installation of the hotfix.

Reference:CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)

In Advanced Permanent Tunnel Configuration, to set the amount of time the tunnel test runs without a response before the peer host is declared 'down', you would set the_________?

A.
life sign polling interval
A.
life sign polling interval
Answers
B.
life sign timeout
B.
life sign timeout
Answers
C.
life_sign_polling_interval
C.
life_sign_polling_interval
Answers
D.
life_sign_timeout
D.
life_sign_timeout
Answers
Suggested answer: D

Explanation:

In Advanced Permanent Tunnel Configuration, the life_sign_timeout parameter sets the amount of time the tunnel test runs without a response before the peer host is declared 'down'. The life_sign_polling_interval parameter sets the interval between each tunnel test packet sent to the peer host.

topic=documents/R77/CP_R77_VPN_AdminGuide/14018

:Advanced Permanent Tunnel Configuration

Matt wants to upgrade his old Security Management server to R81.x using the Advanced Upgrade with Database Migration. What is one of the requirements for a successful upgrade?

A.
Size of the /var/log folder of the source machine must be at least 25% of the size of the /var/log directory on the target machine
A.
Size of the /var/log folder of the source machine must be at least 25% of the size of the /var/log directory on the target machine
Answers
B.
Size of the /var/log folder of the target machine must be at least 25% of the size of the /var/log directory on the source machine
B.
Size of the /var/log folder of the target machine must be at least 25% of the size of the /var/log directory on the source machine
Answers
C.
Size of the $FWDIR/log folder of the target machine must be at least 30% of the size of the $FWDIR/log directory on the source machine
C.
Size of the $FWDIR/log folder of the target machine must be at least 30% of the size of the $FWDIR/log directory on the source machine
Answers
D.
Size of the /var/log folder of the target machine must be at least 25GB or more
D.
Size of the /var/log folder of the target machine must be at least 25GB or more
Answers
Suggested answer: B

Explanation:

One of the requirements for a successful upgrade using the Advanced Upgrade with Database Migration is that the size of the /var/log folder of the target machine must be at least 25% of the size of the /var/log directory on the source machine. This is to ensure that there is enough space to copy the log files from the source machine to the target machine during the upgrade process.

Reference:Advanced Upgrade with Database Migration

While using the Gaia CLI. what is the correct command to publish changes to the management server?

A.
json publish
A.
json publish
Answers
B.
mgmt publish
B.
mgmt publish
Answers
C.
mgmt_cli commit
C.
mgmt_cli commit
Answers
D.
commit
D.
commit
Answers
Suggested answer: B

Explanation:

While using the Gaia CLI, the correct command to publish changes to the management server is mgmt publish. This command publishes all changes made by all administrators since the last publish operation. The json publish command is not valid in Gaia CLI. The mgmt_cli commit command is used to publish changes made by a specific administrator session. The commit command is used to save configuration changes in Gaia CLI.

Reference:Publishing Changes

Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?

A.
Run cprestart from clish
A.
Run cprestart from clish
Answers
B.
After upgrading the hardware, increase the number of kernel instances using cpconfig
B.
After upgrading the hardware, increase the number of kernel instances using cpconfig
Answers
C.
Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores
C.
Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores
Answers
D.
Hyperthreading must be enabled in the bios to use CoreXL
D.
Hyperthreading must be enabled in the bios to use CoreXL
Answers
Suggested answer: B

Explanation:

: After installing a new multicore CPU to replace the existing single core CPU, the administrator is required to perform one additional task, which is to increase the number of kernel instances using cpconfig. This is because by default, only one kernel instance is enabled on a Security Gateway. To take advantage of multiple cores, the administrator needs to configure more kernel instances according to the number of cores available on the CPU.

Reference:Configuring CoreXL

Which 3 types of tracking are available for Threat Prevention Policy?

A.
SMS Alert, Log, SNMP alert
A.
SMS Alert, Log, SNMP alert
Answers
B.
Syslog, None, User-defined scripts
B.
Syslog, None, User-defined scripts
Answers
C.
None, Log, Syslog
C.
None, Log, Syslog
Answers
D.
Alert, SNMP trap, Mail
D.
Alert, SNMP trap, Mail
Answers
Suggested answer: D

Explanation:

The three types of tracking available for Threat Prevention Policy are Alert, SNMP trap, and Mail. These tracking options can be configured in the Threat Prevention tab of the SmartConsole, under the Policy section. The tracking options determine how the system notifies the administrator of events that match the policy rules.

Reference:Configuring Threat Prevention Policy

If SecureXL is disabled which path is used to process traffic?

A.
Passive path
A.
Passive path
Answers
B.
Medium path
B.
Medium path
Answers
C.
Firewall path
C.
Firewall path
Answers
D.
Accelerated path
D.
Accelerated path
Answers
Suggested answer: C

Explanation:

If SecureXL is disabled, which means that packet acceleration is not available, the traffic is processed by the Firewall path. The Firewall path is the slowest path in the Check Point architecture, as it involves a full inspection of each packet by the Firewall kernel and all the enabled Software Blades. The Firewall path is also known as the F2F (Firewall to Firewall) path or the INSPECT path.

Reference:Check Point Architecture

Within the Check Point Firewall Kernel resides Chain Modules, which are individually responsible for the inspection of a specific blade or feature that has been enabled in the configuration of the gateway. For Wire mode configuration, chain modules marked with _______ will not apply.

A.
ffffffff
A.
ffffffff
Answers
B.
00000001
B.
00000001
Answers
C.
00000002
C.
00000002
Answers
D.
00000003
D.
00000003
Answers
Suggested answer: B

Explanation:

For Wire mode configuration, chain modules marked with 00000001 will not apply. Wire mode is a special configuration that allows a Security Gateway to pass traffic without inspection, acting as a bridge between two network segments. In Wire mode, only chain modules that are essential for basic functionality are applied, such as VPN, QoS, ClusterXL, and SecureXL. Chain modules that are related to inspection-based Software Blades, such as Firewall, IPS, Application Control, and so on, are skipped. The chain modules that are skipped are marked with 00000001 in the output of fw ctl chain command.

Reference:Wire Mode

Which of the following is NOT an attribute of packet acceleration?

A.
Source address
A.
Source address
Answers
B.
Protocol
B.
Protocol
Answers
C.
Destination port
C.
Destination port
Answers
D.
VLAN Tag
D.
VLAN Tag
Answers
Suggested answer: D

Explanation:

VLAN Tag is not an attribute of packet acceleration. Packet acceleration is a feature of SecureXL that allows certain packets to bypass the Firewall kernel and be processed by a more efficient mechanism. Packet acceleration is based on templates that match packets based on four attributes: Source IP address, Destination IP address, Protocol, and Destination port. If a packet matches an existing template, it is accelerated; otherwise, it is sent to the Firewall path for inspection.

Reference: [SecureXL Mechanism]

Total 626 questions
Go to page: of 63