ExamGecko
Question list
Search
Search

Question 248 - 156-315.81 discussion

Report
Export

What must you do first if ''fwm sic_reset'' could not be completed?

A.
Cpstop then find keyword ''certificate'' in objects_5_0.C and delete the section
Answers
A.
Cpstop then find keyword ''certificate'' in objects_5_0.C and delete the section
B.
Reinitialize SIC on the security gateway then run ''fw unloadlocal''
Answers
B.
Reinitialize SIC on the security gateway then run ''fw unloadlocal''
C.
Reset SIC from Smart Dashboard
Answers
C.
Reset SIC from Smart Dashboard
D.
Change internal CA via cpconfig
Answers
D.
Change internal CA via cpconfig
Suggested answer: D

Explanation:

The first thing that must be done if ''fwm sic_reset'' could not be completed is to change internal CA via cpconfig. Fwm sic_reset is a command that allows administrators to reset Secure Internal Communication (SIC) between Security Management Server and Security Gateways or other Check Point modules. SIC is a mechanism that ensures secure and authenticated communication between Check Point components by using certificates issued by an internal Certificate Authority (ICA). If fwm sic_reset fails, it means that there is a problem with the ICA or the certificates that prevents SIC from being reset. To resolve this problem, administrators need to change internal CA via cpconfig, which is a command that allows administrators to configure various settings on Security Gateways or Management Servers, including the ICA. Changing internal CA via cpconfig will create a new ICA with a new certificate, and allow SIC to be reset with the new certificate.

asked 16/09/2024
Avadhesh Dubey
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first