Which method below is NOT one of the ways to communicate using the Management API’s?
When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?
True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway
Which of the following statements about Site-to-Site VPN Domain-based is NOT true?
Route-based— The Security Gateways will have a Virtual Tunnel Interface (VTI) for each VPN Tunnel with a peer VPN Gateway. The Routing Table can have routes to forward traffic to these VTls. Any traffic routed through a VTI is automatically identified as VPN Traffic and is passed through the VPN Tunnel associated with the VTI.
To ensure that VMAC mode is enabled, which CLI command you should run on all cluster members? Choose the best answer.
John is the administrator of a R80 Security Management server managing r R77.30 Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators, and to save the database before installing a policy, what must John do?
What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?
You are going to perform a major upgrade. Which back up solution should you use to ensure your database can be restored on that device?
Which option in tracking allows you to see the amount of data passed in the connection?
The default shell of the Gaia CLI is cli.sh. How do you change from the cli.sh shell to the advanced shell to run Linux commands?
Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is _____.
You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?
Which of the completed statements is NOT true? The WebUI can be used to manage Operating System user accounts and
Which Check Point software blade provides Application Security and identity control?
Fill in the blanks: A Security Policy is created in_____, stored in the_____ and Distributed to the various
Which software blade enables Access Control policies to accept, drop, or limit web site access based on user, group, and/or machine?
Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?
Which of the following situations would not require a new license to be generated and installed?
AdminA and AdminB are both logged into SmartConsole. What does it mean if AdminB sees a lock icon on a rule? Choose the BEST answer.
In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Which of the following options can you add to each Log, Detailed Log and Extended Log?
You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to accept your Terms of Service, and cannot access the Internet. How can you fix this?

When configuring Spoof Tracking, which tracking actions can an administrator select to be done when spoofed packets are detected?
Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? (Choose the best answer.)
Fill in the blank: In Security Gateways R75 and above, SIC uses ______________ for encryption.
Access roles allow the firewall administrator to configure network access according to:
Fill in the blank: When a policy package is installed, ________ are also distributed to the target installation Security Gateways.
Identify the ports to which the Client Authentication daemon listens on by default?
When changes are made to a Rule base, it is important to _______________ to enforce changes.
Identity Awareness allows easy configuration for network access and auditing based on what three items?
In order to see real-time and historical graph views of Security Gateway statistics in SmartView Monitor, what feature needs to be enabled on the Security Gateway?
Which of the following is used to extract state related information from packets and store that information in state tables?
Session unique identifiers are passed to the web api using which http header option?
Which deployment adds a Security Gateway to an existing environment without changing IP routing?
Which one of these features is NOT associated with the Check Point URL Filtering and Application Control Blade?
The purpose of the Communication Initialization process is to establish a trust between the Security Management Server and the Check Point gateways. Which statement best describes this Secure Internal
Communication (SIC)?
Which of the following is a new R80.10 Gateway feature that had not been available in R77.X and older?
If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed:
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?
Which part of SmartConsole allows administrators to add, edit delete, and clone objects?
Which repositories are installed on the Security Management Server by SmartUpdate?
Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?
An administrator wishes to use Application objects in a rule in their policy but there are no Application objects listed as options to add when clicking the " + " to add new items to the " Services & Applications " column of a rule. What should be done to fix this?
When you upload a package or license to the appropriate repository in SmartUpdate. where is the package or license stored?
Which type of Endpoint Identity Agent includes packet tagging and computer authentication?
Which SmartConsole application shows correlated logs and aggregated data to provide an overview of potential threats and attack patterns?
What needs to be configured if the NAT property ‘Translate destination on client side’ is not enabled in Global properties?
Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?
When a gateway requires user information for authentication, what order does it query servers for user information?
Which of the following technologies extracts detailed information from packets and stores that information in state tables?
Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?
When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition?
Which is NOT an encryption algorithm that can be used in an IPSEC Security Association (Phase 2)?
What data MUST be supplied to the SmartConsole System Restore window to restore a backup?
When a Security Gateway communicates about its status to an IP address other than its own, which deployment option was chosen?
Gaia has two default user accounts that cannot be deleted. What are those user accounts?
Which of the following is NOT a method used by Identity Awareness for acquiring identity?
Can multiple administrators connect to a Security Management Server at the same time?
Name the utility that is used to block activities that appear to be suspicious.
Fill in the blank: The_____is used to obtain identification and security information about network users.
Which information is included in the “Extended Log” tracking option, but is not included in the “Log” tracking option?
Which option, when applied to a rule, allows traffic to VPN gateways in specific VPN communities?
What are two basic rules Check Point recommending for building an effective security policy?
Fill in the blank: A(n)_____rule is created by an administrator and configured to allow or block traffic based on specified criteria.
Fill in the blank: It is Best Practice to have a _____ rule at the end of each policy layer.
To view the policy installation history for each gateway, which tool would an administrator use?
After trust has been established between the Check Point components, what is TRUE about name and IP-address changes?
In Unified SmartConsole Gateways and Servers tab you can perform the following functions EXCEPT ________.
Tom has connected to the Management Server remotely using SmartConsole and is in the process of making some Rule Base changes, when he suddenly loses connectivity. Connectivity is restored shortly afterward. What will happen to the changes already made?
Which of the following is considered to be the more secure and preferred VPN authentication method?
Fill in the blank: The position of an implied rule is manipulated in the __________________ window.
Which of the following is used to initially create trust between a Gateway and Security Management Server?
You have successfully backed up your Check Point configurations without the OS information. What command would you use to restore this backup?
What are valid authentication methods for mutual authenticating the VPN gateways?
In the Check Point Security Management Architecture, which component(s) can store logs?
When a Security Gateway sends its logs to an IP address other than its own, which deployment option is installed?
In a Distributed deployment, the Security Gateway and the Security Management software are installed on what platforms?
Fill in the blank: Each cluster, at a minimum, should have at least ___________ interfaces.
Which is a main component of the Check Point security management architecture?
You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?
Which of the following is NOT a policy type available for each policy package?