156-315.81 Check Point Certified Security Expert R81.20 ( 156-315.81.20 ) Questions and Answers
Which of the following is NOT a VPN routing option available in a star community?
You need to change the number of firewall Instances used by CoreXL. How can you achieve this goal?
Which tool provides a list of trusted files to the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?
Which file gives you a list of all security servers in use, including port number?
When SecureXL is enabled, all packets should be accelerated, except packets that match the following conditions:
What key is used to save the current CPView page in a filename format cpview_”cpview process ID”.cap”number of captures”?
On R81.20 when configuring Third-Party devices to read the logs using the LEA (Log Export API) the default Log Server uses port:
Fill in the blank. Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is ________ .
Check Point APIs allow system engineers and developers to make changes to their organization’s security policy with CLI tools and Web Services for all the following except:
You notice that your firewall is under a DDoS attack and would like to enable the Penalty Box feature, which command you use?
How many images are included with Check Point TE appliance in Recommended Mode?
When requiring certificates for mobile devices, make sure the authentication method is set to one of the following, Username and Password, RADIUS or ________.
Session unique identifiers are passed to the web api using which http header option?
The CPD daemon is a Firewall Kernel Process that does NOT do which of the following?
The fwd process on the Security Gateway sends logs to the fwd process on the Management Server via which 2 processes?
Which method below is NOT one of the ways to communicate using the Management API’s?
Which one of these features is NOT associated with the Check Point URL Filtering and Application Control Blade?
The fwd process on the Security Gateway sends logs to the fwd process on the Management Server, where it is forwarded to___________via____________
What will be the effect of running the following command on the Security Management Server?

What is the most ideal Synchronization Status for Security Management Server High Availability deployment?
When attempting to start a VPN tunnel, in the logs the error “no proposal chosen” is seen numerous times. No other VPN-related entries are present.
Which phase of the VPN negotiations has failed?
After the initial installation on Check Point appliance, you notice that the Management-interface and default gateway are incorrect.
Which commands could you use to set the IP to 192.168.80.200/24 and default gateway to 192.168.80.1.
Alice & Bob are going to use Management Data Plane Separation and therefore the routing separation needs to be enabled. Which of the following command is true for enabling the Ma n agement Data Plane Separation (MDPS):
Vanessa is expecting a very important Security Report. The Document should be sent as an attachment via e-mail. An e-mail with Security_report.pdf file was delivered to her e-mail inbox. When she opened the PDF file, she noticed that the file is basically empty and only few lines of text are in it. The report is missing some graphs, tables and links.
Which component of SandBlast protection is her company using on a Gateway?
An administrator wishes to enable Identity Awareness on the Check Point firewalls. However, they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?
Which Check Point process provides logging services, such as forwarding logs from Gateway to Log Server, providing Log Export API (LEA) & Event Logging API (EL-A) services.
The Check Point Central Deployment Tool (CDT) communicates with the Security Gateway(s) over Check Point SIC via:
Which Check Point software blade provides visibility of users, groups and machines while also providing access control through identity-based policies?
After some changes in the firewall policy you run into some issues. You want to test if the policy from two weeks ago have the same issue. You don ' t want to lose the changes from the last weeks. What is the best way to do it?
According to out of the box SmartEvent policy, which blade will automatically be correlated into events?
What is the recommended configuration when the customer requires SmartLog indexing for 14 days and SmartEvent to keep events for 180 days?
You have used the SmartEvent GUI to create a custom Event policy. What is the best way to display the correlated Events generated by SmartEvent Policies?
According to the policy installation flow the transfer state (CPTA) is responsible for the code generated by the FWM. On the Security Gateway side a process receives them and first stores them Into a temporary directory. Which process is true for receiving these Tiles;
True or False: In R81, more than one administrator can login to the Security Management Server with write permission at the same time.
Alice wants to upgrade the current security management machine from R80.40 to R81.20 and she wants to check the Deployment Agent status over the GAIA CLISH. Which of the following GAIACLISH command is true?
In which deployment is the security management server and Security Gateway installed on the same appliance?
By default how often updates are checked when the CPUSE Software Updates Policy is set to Automatic?
John is using Management HA. Which Security Management Server should he use for making changes?
Fill in the blanks: In the Network policy layer, the default action for the Implied last rule is ____ all traffic. However, in the Application Control policy layer, the default action is ______ all traffic.
What is correct statement about Security Gateway and Security Management Server failover in Check Point R81.X in terms of Check Point Redundancy driven solution?
NO: 219
What cloud-based SandBlast Mobile application is used to register new devices and users?
What is the recommended number of physical network interfaces in a Mobile Access cluster deployment?
Capsule Connect and Capsule Workspace both offer secured connection for remote users who are using their mobile devices. However, there are differences between the two.
Which of the following statements correctly identify each product ' s capabilities?
To ensure that VMAC mode is enabled, which CLI command should you run on all cluster members?
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?
In CoreXL, the Firewall kernel is replicated multiple times. Each replicated copy or instance can perform the following:
A user complains that some Internet resources are not available. The Administrator is having issues seeing it packets are being dropped at the firewall (not seeing drops in logs). What is the solution to troubleshoot the issue?
If an administrator wants to add manual NAT for addresses now owned by the Check Point firewall, what else is necessary to be completed for it to function properly?
Can Check Point and Third-party Gateways establish a certificate-based Site-to-Site VPN tunnel?
Which statement is false in respect of the SmartConsole after upgrading the management ser v er to R81.20?
Is it possible to establish a VPN before the user login to the Endpoint Client?
What API command below creates a new host object with the name " My Host " and IP address of " 192 168 0 10 " ?
identity Awareness allows easy configuration for network access, and auditing based on what three items?
Access roles allow the firewall administrator to configure network access according to:
Which statements below are CORRECT regarding Threat Prevention profiles in Smart Dashboard?
What API command below creates a new host with the name “New Host” and IP address of “192.168.0.10”?
SmartEvent has several components that function together to track security threats. What is the function of the Correlation Unit as a component of this architecture?
You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?
You find one of your cluster gateways showing “Down” when you run the “cphaprob stat” command. You then run the “clusterXL_admin up” on the down member but unfortunately the member continues to show down. What command do you run to determine the cause?
You are investigating issues with to gateway cluster members are not able to establish the first initial cluster synchronization. What service is used by the FWD daemon to do a Full Synchronization?
To enable Dynamic Dispatch on Security Gateway without the Firewall Priority Queues, run the following command in Expert mode and reboot:
Which Check Point software blade provides Application Security and identity control?
You have a Geo-Protection policy blocking Australia and a number of other countries. Your network now requires a Check Point Firewall to be installed in Sydney, Australia.
What must you do to get SIC to work?
In the Check Point Firewall Kernel Module, each Kernel is associated with a key, which specifies the type of traffic applicable to the chain module. For Stateful Mode configuration, chain modules marked with __________________ will not apply.
Please choose the path to monitor the compliance status of the Check Point R81.20 based management.
Ken wants to obtain a configuration lock from other administrator on R81 Security Management Server. He can do this via WebUI or via CLI.
Which command should he use in CLI? (Choose the correct answer.)
You want to verify if your management server is ready to upgrade to R81.20. What tool could you use in this process?
Which of the following is a new R81 Gateway feature that had not been available in R77.X and older?
Which of the following type of authentication on Mobile Access can NOT be used as the first authentication method?
Check Point Management (cpm) is the main management process in that it provides the architecture for a consolidated management console. It empowers the migration from legacy Client-side logic to Server-side logic. The cpm process:
NAT rules are prioritized in which order?
1. Automatic Static NAT
2. Automatic Hide NAT
3. Manual/Pre-Automatic NAT
4. Post-Automatic/Manual NAT rules
Which Mobile Access Application allows a secure container on Mobile devices to give users access to internal website, file share and emails?
Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.
You can select the file types that are sent for emulation for all the Threat Prevention profiles. Each profile defines a(n) _____ or _____ action for the file types.
The Firewall Administrator is required to create 100 new host objects with different IP addresses. What API command can he use in the script to achieve the requirement?
Fill in the blank: The R81 utility fw monitor is used to troubleshoot ______________________.
Fill in the blank: The tool _____ generates a R81 Security Gateway configuration report.
In order to get info about assignment (FW, SND) of all CPUs in your SGW, what is the most accurate CLI command?
Automatic affinity means that if SecureXL is running, the affinity for each interface is automatically reset every
Check Pont Central Deployment Tool (CDT) communicates with the Security Gateway / Cluster Members over Check Point SIC _______ .
What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?
If you needed the Multicast MAC address of a cluster, what command would you run?
Tom has been tasked to install Check Point R81 in a distributed deployment. Before Tom installs the systems this way, how many machines will he need if he does NOT include a SmartConsole machine in his calculations?
Full synchronization between cluster members is handled by Firewall Kernel. Which port is used for this?
What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL Filtering, Anti-Virus, IPS, and Threat Emulation?
Both ClusterXL and VRRP are fully supported by Gaia R81.20 and available to all Check Point appliances. Which the following command is NOT related to redundancy and functions?
You want to store the GAIA configuration in a file for later reference. What command should you use?
Using Threat Emulation technologies, what is the best way to block .exe and .bat file types?
What is the protocol and port used for Health Check and State Synchronization in ClusterXL?
An administrator would like to troubleshoot why templating is not working for some traffic. How can he determine at which rule templating is disabled?
: 156
VPN Link Selection will perform the following when the primary VPN link goes down?
John is using Management HA. Which Smartcenter should be connected to for making changes?
After making modifications to the $CVPNDIR/conf/cvpnd.C file, how would you restart the daemon?
Using mgmt_cli, what is the correct syntax to import a host object called Server_1 from the CLI?
When setting up an externally managed log server, what is one item that will not be configured on the R81 Security Management Server?
SandBlast has several functional components that work together to ensure that attacks are prevented in real-time. Which the following is NOT part of the SandBlast component?
When simulating a problem on ClusterXL cluster with cphaprob –d STOP -s problem -t 0 register, to initiate a failover on an active cluster member, what command allows you remove the problematic state?
SandBlast offers flexibility in implementation based on their individual business needs. What is an option for deployment of Check Point SandBlast Zero-Day Protection?
When gathering information about a gateway using CPINFO, what information is included or excluded when using the “-x” parameter?








Firewall
Firewall
Firewall