· 8 years ago · Aug 23, 2018, 12:18 PM
1Which of the following licenses are considered temporary?
2 Plug and play and Evaluation
3
4Which utility shows the security gateway general system information statistics like operation system information and resource usage, and individiual software blade statistics of VPN, Identity Awareness and DLP?
5 cpview
6
7How many packets does the IKE exchange use for Phase 1 Main Mode?
8 6
9
10You are about to integrate RSA SecureID users into the Check Point infrastructure. What kind of users are to be defined via SmartDashboard?
11 A group with generic user
12
13Which of the completed statemens is not true? The WebUI can be used to manage user accounts and:
14 Assign user rights to their home directory in the Security Management Server
15
16Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?
17 Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway
18
19Fill in the blank: The command ______ provides the most complete restoration of a R80 configuration.
20 upgrade_import
21
22Vanessa is a Firewall administrator. She wants to test a backup of her companys production Firewall cluster Dallas_GW. She has a lab environment that is identical to her production environment. She decided to restore production backup via SmartConsole in lab environment. Which details she need to fill in System Restore window before she can click OK button and test the backup?
23 Server, Protocol, Username, Password, Path, Comment, All Members
24
25Fill in the blank: The ______ collects logs and sends them to the ________ .
26 Security Gateways; log server
27
28What statement is true regarding Visitor Mode?
29 VPN authentication and encrypted traffic are tunneled through port TCP 443
30
31Fill in the blank: The R80 feature _______ permits blocking specific IP addresses for a specified time period
32 Suspicious Activity Monitoring
33
34Which remote Access Solution is clientless?
35 Mobile Access Portal
36
37If there is an Accept Implied Policy set to "First", what is the reason Jorge cannot see any logs?
38 Log Implied Rule was not selected on Global Properties
39
40Your company enforces a strict change control policy. Which of the following would be MOST effective for quickly dropping an attackers specific active connection?
41 Block Intruder feature of SmartView Tracker
42
43Which limitation of CoreXL is overcome by using(mitigated by) Multi-Queue?
44 Each NIC has several traffic queues that are handled by multiple CPU cores
45
46Joey is using the computer with IP address 192.168.20.13. He wants to access web page "www.checkpoint.com", which is hosted on Web server with IP address 203.0.113.111. How many rules on Check point Firewall are required for this connection?
47 Only one rule, because Check Point firewall is using Stateful Inspection technology
48
49What does ExternalZone represent in the presented rule?
50 Interfaces that administrator has defined to be part of External Security Zone
51
52What port is used for delivering logs from the gateway to the management server?
53 Port 257
54
55Where would an administrator enable Implied Rules logging
56 In Global Properties under Firewall
57
58AdminA and AdminB are both logged in on SmartConsole. What does it mean if AdminB sees a locked icon on a rule? Choose the BEST answer.
59 Rule is locked by AdminA, and will make it available if session is published
60
61Which of the following are available SmartConsole clients which can be installed from the R77 Windows CD? Read all answers and select the most complete and valid list.
62 SmartView Tracker, CPINFO, SmartUpdate
63
64Fill in the blank: The IPS policy for pre-R80 gateways is installed during the _________
65 Threat Prevention policy install
66
67How Capsule Connect and Capsule Workspace differ?
68 Capsule Connect provides a Layer3 VPN. Capsule Workspace provides a Desktop with usable applications
69
70Fill in the blank: RADIUS protocol uses ______ to communicate with the gateway.
71 UDP
72
73Which of the following is NOT an advantage to using multiple LDAP servers?
74 Information on a user is hidden, yet distributed across several servers
75
76You want to store the GAIA configuration in a file for later reference. What command should you use?
77 save configuration <filename>
78
79Which method below is NOT one of the ways to communicate using the Management APIs?
80 Sending API commands over an http connection using web-services
81
82Fill in the blank:Each cluster has _____ interfaces.
83 Three
84
85R80 Security Management Server can be installed on which of the following operating systems?
86 Gaia only
87
88As you review this security policy what changes could you make to accomodate Rule 4?
89 Modify the column VPN in Rule 2 to limit access to specific traffic.
90
91Choose the SmartLog property that is TRUE
92 SmartLog is a client of SmartConsole that enables enterprises to centrally track log records and security activity with Google-like searches
93
94Which Threat Prevention Software Blade provides comprehensive against malicious and unwanted network traffic, focusing on application and server vulnerabilities.
95 IPS
96
97When a packet arrives at the gateway, the gateway checks it against the rules in the top Policy Layer, sequentially from top to bottom, and enforces the first rule that matches a packet. Which of the following statemens about the order of rule enforcement is true?
98 If the Action is Accept, the gateway continues to check rules in the next Policy Layer down
99
100Fill in the blank: A ________ is used by a VPN gateway to send traffic as if it were a physical interface.
101 VPN Tunnel interface
102
103Fill in the blank: Once a license is activated, a ______ should be installed.
104 Service Contract file
105
106Which Check Point software blade provides protection from zero-day and undiscovered threats?
107 Threat Emulation
108
109Using ClusterXL, what statement is true about the Sticky Decision Function?
110 Can only be changed for Load Sharing implementations
111
112When defining QoS global properties, which option below is not valid?
113 Schedule
114
115Sally has a Hot Fix Accumulator(HFA) she wants to install on her Security Gateway which operates with GAIA, but she cannot SCP the HFA to the system. She can SSH into the Security Gateway, but the has never been able to SCP files to it. What would be the most likely reason she cannot do so?
116 She needs to edit /etc/scpusers and add the Standard Mode acocunt
117
118Which default user has full read/write access?
119 Administrator
120
121What is the potential downside or drawback to choosing the Standalone deployment option instead of the Distributed deployment option?
122 Degrades performance as the Security Policy grows in size
123
124The system administrator of a company is trying to find out why accelaration is not working for the traffic. The traffic is allowed according to the rule base and checked for viruses. But it is not accelerated. What is the most likely reason that the traffic is not accelerated?
125 The traffic is originating from the gateway itself
126
127Anti-Spoofing is typically set up on which object type?
128 Security Gateway
129
130What is the Manual Client Authentication TELNET port?
131 259
132
133Which Check Point software blade provides visibility of users, groups and machines while also providing access control thorugh identity-based policies?
134 Identity Awareness
135
136What happens if the identity of a user is known?
137 If the user credentials do not match an Access Role, the gateway moves onto the next rule
138
139Choose what BEST describes users on Gaia Platform.
140 There are two default users and one cannot be deleted
141
142Which component functions as the Internal Certificate Authority for R77?
143 Management Server
144
145Office mode means that
146 Allows a security gateway to assign a remote client an IP address. After the user authenticates for a tunnel, the VPN gateway assigns a routable IP address to the remote client
147
148If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed
149 Rename the hostname of the Standby member to match exactly the hostname of the Active member
150
151You work as a security administrator for a large company. CSO of your company has attended a security conference where he has learnt how hackers constantly modify their strategies and techniques to evade detection and reach corporate resources. He wants to make sure that his company has the right protections in place.
152Check Point has been selected for the security vendor. Which Check Point products protects BEST against malware and zero-day attacks while ensuring quick delivery of safe content to your users?
153 SandBlast
154
155Review the rules. Assume domain UDP is enabled in the implied rules. What happens when a user from the internal network tries to browse to the internet using HTTP? The user:
156 Can go to the Internet, without being prompted for authentication.
157
158The Firewall kernel is replicated multiple times, therefore:
159 The Firewall can run the same policy on all cores
160
161What Identity Agent allows packet tagging and computer authentication?
162 Full Agent
163
164NAT can NOT be configured on which of the following objects?
165 HTTP Logical Server
166
167The fw monitor utility is used to troubleshoot which of the following problems?
168 Address translation
169
170Which NAT rules are prioritized first?
171 Manual/Pre-Automatic NAT
172
173Which two of these Check Point Protocols are used by ______?
174 FWD and LEA
175
176All R77 Security Servers can perform authentication with the exception of one. Which of the Security Servers can NOT perform authentication?
177 SMTP
178
179Which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?
180 Read Only All
181
182R80.10 management server can manage gateways with which versions installed?
183 Version R75.20 and higher
184
185You want to reset SIC between smberlin and sgosaka. In SmartDashboard. you choose sgosaka, Communication, Reset. On sgosaka you start cpconfig, choose Secure Internal Communication and enter the new SIC Activation Key. The screen reads The SIC was successfully initialized and jumps back to the menu. When Trying to establish a connection,
186instead of a working connection you receive this error message:
187What is the reason for this behavior?
188 The check Point services on the Gateway were not restarted because you are still in the cpconfig utility.
189
190The Captive Portal tool:
191 Acquires identities from unidentified users
192
193While in SmartView Tracker, Brady has noticed some very odd network traffic that he thinks could be an intrusion. He decides to block the traffic for 60 minutes, but cannot remember all the steps. What is the correct order of steps needed to set up the block?
1941) Select Active Mode tab in SmartView Tracker
1952) Select Tools> Block Intruder
1963) Select Log Viewing tab in SmartView Tracker
1974) Set Blocking Timeout value to 60 minutes
1985) Highlight connection that should be blocked.
199
2001,5,2,4
201
202You are conducting a security audit. While reviewing configuration files and logs, you notice logs accepting POP3 traffic, but you do not see a rule allowing POP3 traffic in the Rule Base. Which of the following is the most likely cause?
203 The POP3 rule is hidden
204
205The organizations security manager wishes to back up just the Gaia operating system parameters. Which command can be used to back up only Gaia operating system parameters like itnerface details, Static routes and Proxy ARP entries?
206 Backup
207
208John Adams is an HR partner in the ACME organization.
2091)Enables Identity awareness on a gateway, selects AD Query as one of the Identity Sources
2102)Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web Server from any machine and from any Lcation
211John plugged in his laptop to the network on a different network segment and he is not able to connect. How does he solve this problem?
212 John should lock and unlock the computer
213
214Traffic from source 192.168.1.1 is going to www.google.com. The Application Control Blade on the gateway is inspecting the traffic. Assuming acceleration is enable which path is handling the traffic?
215 Slow Path
216
217You have just installed your Gateway and want to analyze the packet size distribution of your traffic with SmartView Monitor. "There are no machines that contain Firewall Blade and SmartView Monitor"
218What should yo do to analyze the packet size distribution of your traffic?
219 Enable Monitoring on your Security Gateway
220
221Which of the following authentication methods can be configured in the Identity Awareness setup wizard?
222 LDAP
223
224What is the SOLR database for?
225 Used for full text search and enables powerful matching capabilities
226
227Checkpoint APIs allow system engineers and developers to make changes to their organizations security policy with CLI tools and Web Services for all of the following except:
228 Create new dashboards to manage 3rd party task
229
230Fill in the blank: The R80 utility fw monitor is used to troubleshoot ______
231 Traffic issues
232
233Which of the following is TRUE about the Check Point Host object?
234 Check point host has no routing ability even if it has more than one interface installed
235
236Kofi, the administrator of the ABC Corp network wishes to change the default Gaia WebUI Portal port number currently set on the default HTTPS port. Which CLISH commands are required to be able to change this TCP port?
237 set web ssl-port <new port number>
238
239The WebUI offers three methods for downloading Hotfixes via CPUSE. One of them is Automatic method. How many times per day will CPUSE agent check for hotfixes and automatically download them? (R77)
240 Every three hours (Bei R80 every 6 hours)
241
242What is the default method for destination NAT?
243 Client Side
244
245You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?
246 fwm
247
248Which of the following commands is used to monitor cluster members?
249 cphaprob state
250
251The CPD daemon is a Firewall Kernel Process that does NOT do which of the following?
252 Pulls application monitoring status
253
254Provide very wide coverage for all products and protocols, with noticeable performance impact. How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.
255 Set the Performance Impact to Medium or lower.
256
257Which of the following is NOT an alert option?
258 High alert
259
260If GRE encapsulation is turned off on the router, SmartView Tracker shows a log entry for the UDP keep-alive packet every minute. Which of the following is the BEST explanation for this behavior?
261 The Log Server log unification process unifies all log entries from the Security Gateway on a specific connection into only one log entry in the SmartView Tracker. GRE traffic has a 10 minute session timeout, thus each keep-alive packet is considered part of the original logged connection at the beginning of the day.
262
263Mesh and Star are two types of VPN topologies. Which statement below is TRUE about these types of communities?
264 in a mesh community, all members can create a tunnel with any other member
265
266What component of R80 Management is used for indexing?
267 SOLR
268
269Jack works for a managed service provider and he has been tasked to create 17 new policies for several new customers. He does not have much time. What is the BEST way to do this with r80 security management?
270 Create a text-file with mgmt_cli script that creates all objects and policies. Open the file in SmartConsole Command Line to run it
271
272Full synchronization between cluster members is handled by Firewall Kernel. Which port is used for this?
273 TCP port 265
274
275 What port is used for communication to the User Center with SmartUpdate?
276 HTTPS 443
277
278What is the main difference between Threat Extraction and Threat Emulation?
279 Threat Extraction always delivers a file and takes less than a second to complete
280
281There are 4 ways to use the Management API for creating host object with R80 Management API. Which one is NOT correct?
282 Using CLISH
283
284Which of these statements describes the Check Point ThreatCloud?
285 A worldwide collaborative security network
286
287Which directory holds the SmartLog index files by default?
288 $SMARTLOGDIR/data
289
290Using R80 Smart Console, what does a "pencil icon" in a rule mean?
291 I have changed this rule
292
293Which of the following are types of VPN communicates?
294 Meshed, star, and combination
295
296Which of the following actions do NOT take place in IKE Phase 1?
297 Diffie-Hellman key is combined with the key material to produce the symmetrical IPsec key.
298
299Fill in the blanks: A High Availability deployment is referred to as a _____ cluster and a Load Sharing deployment is referred to as a ______ cluster.
300 Active/standby; active/active
301
302SmartEvent does NOT use which of the following procedures to identity events:
303 Matching a log against local exclusions
304
305As a Security Administrator you must refresh the Client Authentication authorized time-out every time a new user connection is authorized. How do you do this? Enable the Refreshable Timeout setting:
306 in the Limit tab of the Client Authentication Action Properties screen.
307
308You are using SmartView Tracker to troubleshoot NAT entries. Which column do you check to view the NATd source port if you are using Source NAT?
309 XlateSPort
310
311On the following picture an administrator configures Identity Awareness:
312After clicking "Next" the above configuration is supported by:
313 Based on Active Directory integration which allows the Security Gateway to correlate Active Directory users and machines to IP addresses in a method that is completely transparent to the user
314
315Which of these components does NOT require a Security Gateway R77 license?
316 SmartConsole
317
318What CLI utility allows an administrator to capture traffic along the firewall inspection chain?
319 fw monitor
320
321The most important part of a site-to-site VPN deployment is the _________
322 Encrypted VPN tunnel
323
324From SecureXL perspective, what are the tree paths of traffic flow
325 Firewall Path; Accelerated Path; Medium Path
326
327What happens if the identity of a user is known?
328 If the user credentials match an Access Role, the rule is applied and traffic is accepted or dropped based on the defined action.
329
330Which one of the following is true about Threat Extraction?
331 Works on all MS Office, Executables, and PDF files
332
333Which command can you use to verify the number of active concurrent connections?
334 fw ctl pst pstat
335
336What command would show the API server status?
337 show api status
338
339Which firewall daemon is responsible for the FW CLI commands?
340 fwd
341
342You want to define a selected administrators permission to edit a layer. However when you click the + sign in the "Select additional profile that will be able edit this layer" you do not see anything. What is the most likely cause of this problem? Select the BEST answer.
343 There are no permission profiles available and you need to create one first
344
345Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.
346 Failovers
347
348Fill in the blank: When LDAP is integrated with Check Point Security Management is is then referred to as________
349 User Directory
350
351Choose what BEST describes the Policy Layer Traffic Inspection.
352 If a packet matches an inline layer, it will continue matching the next layer
353
354To install a brand new Check Point Cluster, the MegaCrop IT department bought 1 Smart-1 and 2 Security Gateway Appliances to run a cluster. Which type of cluster is it?
355 High Availability
356
357If the first packet of an UDP session is rejected by a security policy, what does the firewall send to the client?
358 Nothing
359
360What does it mean if Bob gets this reuslt on an object search? Choose the BEST answer.
361 There is no object on the database with that name or that IP address.
362
363Fill in the blank: Licenses can be added to the License and Contract repository ________
364 From the User Center, from a file, or manually
365
366Fill in the blank: Service blades must be attached to a ______
367 Security Gateway
368
369The Gaia operating system supports which routing protocols?
370 BGP, OSPF, RIP
371
372You believe Phase 2 negotiations are failing while you are attempting to configure a site-to-site VPN with one of your firms business partners. Which SmartConsole application should you use to confirm your suspicions?
373 SmartView Tracker
374
375John is using Management HA. Which SmartCenter should be connected to for making changes?
376 Active SmartCenter
377
378Which application should you use to install a contract file?
379 SmartUpdate
380
381Can a Check Point gateway translate both source IP address and destination IP address in a given packet?
382 Yes
383
384In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Which of the following options can you add to each Log and Extended Log?
385 Accounting/Suppresiion
386
387In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?
388 SND is used to distribute packets among Firewall instances
389
390Which is a suitable command to check whether Drop Templates are activated or not?
391 fwaccel stat
392
393Where do you verify that UserDirectory is enabled?
394 Verify that Global Properties > UserDirectory > Use UserDirectory(LDAP) for Security Gateways is checked.
395
396What is the benefit of Manual NAT over Automatic NAT?
397 You have the full control about the priority of the NAT rules
398
399You are going to upgrade from R77 to R80. Before the upgrade, you want to back up the system so that if there are any problems, you can easily restore to the old version with all configuration and management files intact. What is the BEST backup method in this scenario?
400 Snapshot
401
402You have two rules, ten users and two user groups in a Security Policy. You create database version 1 for this configuration. You then delete two existing users and add a new user group. You modify one rule and add two new rules to the Rule Base. You save the Security Policy and create database version 2.
403After a while you decide to roll back to version 1 to use the Rule Base, but you want to keep your user databse. How can you do this?
404 Restore the entire database, except the user database.
405
406On the following graphic, you will find layers of policies. What is a precedence of traffic inspection for the defined policies?
407 A packet arrives at the gateway, it is checked against the rules in the networks policy layer and then if there is any rule which accepts the packet, it comes next to IPS layer and then after accepting the packet it passes to Threat Prevention layer.
408
409IT administrator:
4101) Enables Identity Awareness on a gateway, selects AD query as one of the Identity Sources installs the policy
4112) Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web Server from any machine and from any location
4123) Changes from static IP address to DHCP for the client PC
413What should John request when he cannot access the web server from his laptop?
414 The access should be changed to authenticate the user instead of the PC
415
416You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.
417 Another rule that accepts HTTP without authentication exists in the Rule Base
418
419What are the three components for Check Point Capsule?
420 Capsule Workspace, Capsule Docs, Capsule Cloud
421
422What are types of Check Point API available currently as part of R80.10 code?
423 Management API, Threat Prevention API, Identity Awareness Web Services API and OPSEC SDK API
424
425Which of the following firewall modes DOES NOT allow for Identity Awareness to be deployed?
426 Bridge
427
428Look at the following screenshot and select the BEST answer.
429 Clients external to the Security Gateway can download archive files from FTP_Ext server using FTP
430
431You noticed that CPU cores on the Security ateway are usually 100% utilized and many packets were dropped. You dont have a budget to perform a hardware upgrade at this time.
432To optimize drops you decide to use Priority Queues and fully enable Dynamic Dispatcher. How can you enable them?
433 fw ctl multik set_mode 9
434
435Tina is a new administrator who is currently reviewing the new Check point R80 Management console interface. In the Gateways view, she is reviewing the Summary screen as in the screenshot below. What is an "Open Server"?
436 Check Point software deployed on a non-Check Point appliance
437
438Customers R80 management server needs to be upgraded to R80.10. What is the best upgrade method when the management server is not connected to the internet?
439 CPUSE offline upgrade
440
441The IT Management team is interested in the new features of the Check Point R80 Management and wants to upgrade but they are concerned that the existing R77.30 Gaia Gateways cannot be managed by R80 because it is so different.
442As the administrator responsible for the Firewalls, how can you answer or confirm these concerns?
443 R80 Management contains compatibility packages for managing earlier versions of Check Point Gateways prior to R80. Consult the R80 Release Notes for more information.
444
445Which of the following is a new R80.10 Gateway feature that had not been available in R77.X and older?
446 Sub Policies are sets of rules that can be created and attached to specific rules. If the rule is matched, inspection will continue in the sub policy attached to it rather than in the next rule
447
448In what way are SSL VPN and IPSec VPN different?
449 IPSec VPN uses an additional virtual adapter, SSL VPN uses the client network adapter only
450
451Which feature is NOT provided by all Check Point Mobile Access solutions?
452 Support for IPv6
453
454Message digests use which of the following?
455 SHA-1 and MD5
456
457Which of the following technologies extracts detailed information from packets and stores that information in state tables?
458 Stateful Inspection
459
460Your users are defined in a Windows 2008 R2 Active Directory server. You must add LDAP users to a Client Authentication rule. Which kind of user group do you need in the Client Authentication rule in R77?
461 LDAP group
462
463What is true about the IPS-Blade?
464 in R80, IPS is managed by the Threat Prevention Policy
465
466What is also referred to as Dynamic NAT?
467 Hide NAT
468
469Administrator wishes to update IPS from SmartConsole by clicking on the option "update now" under the IPS tab. Which device requires internet acces for the update to work?
470 Device where SmartConsole is installed
471
472A client has created a new Gateway object that will be managed at a remote location. When the client attempts to install the Security Policy to the new Gateway object, the object does not appear in the Install On check box. What should you look for?
473 A gateway object created using the Check Point > Externally Managed VPN Gateway option from the Network Objects dialog box.
474
475The technical-support department has a requirement to access an intranet server. When configuring a User Authentication rule to achieve this, which of the following should you remember?
476 The Security Gateway first checks if there is any rule that does not require authentication for this type of connection before invoking the Authentication Security Server
477
478Which command is used to obtain the configuration lock in Gaia?
479 Lock database override
480
481Choose the correct statement regarding Implicit Rules.
482 To edit the implicit rules you go to: Launch Button > Policy > Global Properties > Firewall
483
484Fill in the blank: RADIUS Accounting gets _____ data from requests generated by the accounting client
485 Identity
486
487Which path below is available only when CoreXL is enabled?
488 Medium path
489
490According to Check Point Best Practice, when adding a non-managed Check Point Gateway to a Check Point security solution what object SHOULD be added?
491 Externally managed gateway
492
493Which is the correct order of a log flow processed by SmartEvent components:
494 Firewall > Log Server > Correlation Unit > SmartEvent Server Database > SmartEvent Client
495
496When using Gaia it might be necessary to temporarily change the MAC address of the interface eth. After restarting the network the old MAC address should be active. How do you configure this change?
497 As expert user, issue the command: # IP link set eth0 addr 00:0C:29:12:34:56
498
499What are the two high availability modes?
500 New and Legacy
501
502Jennifer McHanry is CEO of ACME. ... To make this scenario work, the IT administrator must:
5031) Enable Identity Awareness on a gateway and select Captive Protal as one of the Identity Sources.
5042) In the Portal Settings window in the User Access section, make sure that Name and password login is selected.
5053) Create a new rule in the Firewall Rule Base to let Jennifer McHandy access network destinations. Select accept as the Action
5064) Install policy
507Ms McHanry tries to access the resource but is unable. What should she do?
508 Have the security administrator select the action field of the Firewall Rule "Redirect HTTP connections to an authentication captive portal"
509
510To fully enable Dynamic Dispatcher on a Security Gateway:
511 run fw ctl multik set_mode 9 in Expert mode and then reboot
512
513Packages and licenses are loaded from all of these sources EXCEPT
514 UserUpdate
515
516Fill in the blank: To build an effective Security Policy, use a ______ and ______ rule.
517 Cleanup; Stealth
518
519What is the default shell of Gaia CLI?
520 CLI.sh
521
522MyCorp has the following NAT rules. You need to disable the NAT funciton when Alpha-internal networks try to reach the Google DNS (8.8.8.8) server. What can you do in this case?
523 Use network exception in the Alpha-internal network object
524
525Which type of Check Point license is tied to the IP address of a specific Security Gateway and cannot be transferred to a gateway that has a different IP address?
526 Local
527
528What is Consolidation Policy?
529 The specific Policy written in SmartDashboard to configure which log data is stored in the SmartReporter database.
530
531To ensure that VMAC mode is enabled, which CLI command you should run on all cluster members? Choose the best answer
532 fw ctl get int fwha vmac global param enabled; result of command should return value 1
533
534Fill in the blank: The _____ feature allows administrators to share a policy with other policy packages
535 Shared policy packages
536
537Which of the following statements accurately describes the command snapshot?
538 A snapshot creates a full OS-level backup, including network-interface data, Check Point production information and configuration settings of a Gaia Security Gateway
539
540You are unable to login to SmartDashboard. You log into the management server and run #cpwd_admin list with the following input
541 FWM is down
542
543Fill in the blanks: A security Policy is created in _______ , stored in the ______ , and Distributed to the various _______ .
544 SmartConsole, Security Management Server, Security Gateways
545
546How do you configure an alert in SmartView Monitor?
547 By choosing the Gateway and Configure Thresholds.
548
549What are the steps to configure the HTTPS Inspection Policy?(R77)
550 Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
551
552The CDT utility supports which of the following?
553 All upgrades
554
555Which of the following is NOT a back up method?
556 Save backup
557
558What happens when you run the command: fw sam -J src [source ip address]
559 Connections from the specified source are blocked without the need to change the Security Policy
560
561Which of these attributes would be critical for site-to-site VPN?
562 Strong data encryption
563
564What action can be performed from SmartUpdate R77?
565 cpinfo
566
567When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition
568 At least 20GB
569
570What are the three conflict resolution rules in the Threat Prevention Policy Layers?
571 Conflict on settings, conflict on address, and conflict on exception
572
573Which of the following is NOT an attribute of packet acceleration?
574 Application Awareness
575
576Session unique identifiers are passed to the web api using which http header option?
577 X-chkp-sid
578
579Which of the below is the MOST correct process to reset SIC from SmartDashboard?
580 Click the Communication button for the firewall object, then flick Reset. Run cpconfig on the gateway and type a new activation key.
581
582Which of the following type of authentication on Mobile Access can NOT be used as the first authentication method?
583 Dynamic ID
584
585Fill in the blanks: In the Network policy layer, the default action for the Implied last rule is _______ all traffic. However in the Application Control policy layer, the default action is ______ all traffic.
586 Drop; accept
587
588You installed Security Management Server on a computer using Gaia. Which is the correct order of pushing SIC certificates to the Gateway before shipping it?
5891) Run cpconfig on the Gateway, select Secure Internal Communication, enter the activation key, and reconfirm.
5902) Initialize Internal Certificate Authority (ICA) on the Security Management Server.
5913) Configure the Gateway object with the host name and IP addresses for the remote site.
5924) Click the Communication button in the Gateway objects General screen, enter the activation key, and click Initialize and OK
5935) Install the Security Policy
594
595 2, 1, 3, 4, 5
596
597Fill in the blank: The R80 SmartConsole, SmartEvent GUI client, and _______ consolidate billions of logs and shows them as prioritized security events.
598 SmartView Web Application
599
600When using LDAP as an authentication method for Identity Awareness, the query:
601 Is transparent, requiring no client or server side software, or client intervention
602
603What are the three essential components of the Check Point Security management architecture?
604 SmartConsole, Security Management Server, Security Gateway
605
606You want to verify if there are unsaved changes in Gaia that will be lost with a reboot. What command can be used?
607 show config-state
608
609Your manager requires you to setup a VPN to a new business partner site. The administrator from the partner site gives you his VPN settings and you notice that he setup AES 128 for IKE phase 1 and AES 256 for IKE phase 2. Why is this a problematic setup?
610 Only 128 bit keys are used for phase 1, keys which are protecting phase 2, so longer key length in phase 2 only costs performance and does not add security due to a shorter key in phase 1.
611
612Joey wants to configure NTP on R80 Security Management Server. He decided to do this via WebUI. What is the correct address to access the WebUI for Gaia platform via browser?
613 https://Device_IP>
614
615Your banks distributed R77 installation has Security Gateways up for renewal. Which SmartConsole application will tell you which Security Gateways have licenses that will expire within the next 30 days?
616 SmartUpdate
617
618Which of the following is NOT a VPN routing option available in a star community?
619 To satellites through center only
620 (To center only)
621
622How many users can have read/write access in Gaia at one time?
623 One
624
625Which of the following is NOT a valid option when configuring access for Captive Portal?
626 From the Internet
627
628What are two types of address translation rules?
629 Original packet and translated packet
630
631What is the difference between an event and a log?
632 A log entry becomes an event when it matches any rule defined in Event Policy
633
634During the Check Point Stateful Inspection Process, for packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are:
635 Dropped with logs and without sending a negative acknowledgment
636
637You have configured SNX on the Security Gateway. The client connects to the Security gateway and the user enters the authentication credentials.
638What must happen after authentication that allows the client to connect to the Security Gateways VPN domain?
639 SNX modifies the routing table to forward VPN traffic to the Security Gateway
640
641Which of the following is NOT a set of Regulatory Requirements related to Information Security?
642 ISO 37001
643
644The following graphic shows:
645 View from SmartView Tracker for logs initiated from source address 10.1.1.202
646
647Which authentication scheme requires a user to possess a token?
648 SecurID
649
650Which one of these features is NOT associated with the Check Point URL Filtering and Application Control Blade?
651 Detects and blocks malware by correlating multiple detection engines before users are affected.
652
653You are about to test some rule and object changes suggested in an R77 news group. Which backup solution should you use to ensure the easiest restoration of your Security Policy to its previous configuration after testing the changes?
654 Database Revision Control
655
656Which of the following uses the same key to decrypt as it does to encrypt?
657 Symmetric encryption
658
659What feature in R77 permits blocking specific IP addresses for a specified time period?
660 Suspicious Activity Monitoring
661
662Packet accelaration (SecureXL) identifies connections by several attributes. Which of the attributes is NOT used for identifying connection?
663 TCP Acknowledgement Number
664
665Which R77 GUI would you use to see number of packets accepted since the last policy install?
666 SmartDashboard (angeblich SmartView Monitor)
667
668Which policy type is used to enforce bandwith and traffic control rules?
669 QoS
670
671Which statement is NOT TRUE about Delta synchronization?
672 Using UDP Multicast or Broadcast on port 8161 (uses UDP 8116)
673
674Fill in the blank: A(n) ______ rule is created by an administrator and is located before the first and before last rules in the Rule Base.
675 Implied
676
677How do you configure the Security Policy to provide users access to the Captive Portal through an external (internet) interface?
678 Change the gateway settings to allow Captive Portal access via an external interface.
679
680Choose what BEST describes a Session.
681 Starts when an Administrator logs in to the Security Management Server thorugh SmartConsole and ends when it is published.
682
683R80, Unified Policy is a combination of
684 Access control policy, Qos Policy, Desktop Security Policy and VPN policy. (Firewall and VPN, Application Control and URL Filtering, Identity Awareness, Mobile Access, Security Zones)
685
686What does the "unknown" SIC status shown on SmartConsole mean?
687 There is no connection between the Security Gateway and SMS
688
689Please choose correct command syntax to add an "emailserver1" host with IP address 10.50.23.90 using Gaia management CLI?
690 mgmt add host name emailserver1 ip-address 10.50.23.90
691
692Which of the following is NOT defined by an Access Role object?
693 Source Server
694
695Where do we need to reset the SIC on a gateway object?
696 SmartDashboard > Edit Gateway Object > General Properties > Communication
697
698Look at the screenshot below What CLISH command provides this output?
699 show configuration
700
701VPN gateways must authenticate to each other prior to exchanging information. What are the two types of credentials used for authentication?
702 Certificates and pre-shared secret
703
704The security Gateway is installed on Gaia R80 the default WEB User Interface is ________.
705 TCP 443
706
707Which Check Point software blade prevents malicious files from entering a network using virus signatures and anomaly-based protections from ThreatCloud?
708 Antivirus
709
710Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, where Bob and Joe are both logged in:
711 If Joe tries to make changes, he wont , database will be locked
712
713Under which file is the proxy arp configuration stored?
714 $FWDIR/conf/local.arp on the gateway
715
716Which command can you use to enable or disable multi-queue per interface?
717 cpmq set
718
719When Identity Awareness is enabled, which identity sources are used for Application Control?
720 AD query and browser-based authentication ( AD Query, Browser Based Authentication, Endpoint Identity Agent, Terminal Servers Identity Agent, Remote Access)
721
722Where can administrator edit a list of trusted SmartConsole clients in R80?
723 In cpconfig on a Security Management Server, in the WebUI logged into a Security Management Server, in SmartConsole: Manage and Settings > Permissions and Administrators > Advanced> Trusted Client
724
725Fill in the blank: Browser-based Authentication sends users to a web page to acquire identities using _______.
726 Captive Portal and Transparent Kerberos Authentication
727
728What is the purpose of Captive Portal?
729 It authenticates users, allowing them access to the internet and corporate resources
730
731What is the difference between SSL VPN and IPSec VPN?
732 IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser
733
734On R80.10 when configuring Third-Party devices to read the logs using the LEA (Log Export API) the default Log Server uses port:
735 18184
736
737What is the purpose of Priority Delta VRRP?
738 When an interface fails, Effective Priority = Priority - Priority Delta
739
740Where does the security administrator activate Identity Awareness within SmartDashboard?
741 Gateway Object > General Properties
742
743What is the mechanism behind Threat Extraction?
744 Any active contents of a document, such as JavaScript, macros and links will be removed from the document and forwarded to the inteded recipient, which makes this solution very fast.
745
746Which of the following is NOT a component of a Distinguished Name?
747 User container
748
749Which of the following ClusterXL modes uses a non-unicast MAC address for the cluster IP address.
750 Load Sharing Multicast
751
752Fill in the blank: The tool _______ generates a R80 Security Gateway configuration report.
753 cpinfo
754
755If there are two administrators logged in at the same time to the SmartConsole, and there are objects locked for editing, what must be done to make them available to other administrators? Choose the BEST answer.
756 Publish or discard the session
757
758What are the three authentication methods for SIC?
759 Certificates, standards-based SSL for the creation of secure channels, and 3DES or AES128 for encryption
760
761You have enabled “Full Log†as a tracking option to a security rule. However, you are still not seeing any data type information. What is the MOST likely reason?
762 Logging has disk space issues. Change logging storage options on the logging server or Security Management Server properties and install database.
763
764What is the order of NAT priorities
765 Static NAT, IP pool NAT, hide NAT
766
767Which of the following is an identity acquisition method that allows a Security Gateway to identify Active Directory users and computers?
768 Active Directory Query
769
770Ken wants to obtain a configuration lock from other administrator on R80 Security Management Server. He can do this via WebUI or a via CLI. Which command should be use in CLI? Choose the correct answer.
771 The database feature has two commands lock database override and unlock database
772
773You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?
774 Create a separate Security Policy package for each remote Security Gateway.
775
776DLP and Geo Policy are examples of what type of Policy
777 Shared policies
778
779In which deployment is the security management server and Security Gateway installed on the same appliance
780 Standalone
781
782Fill in the blank: A _________ VPN deployment is used to provide remote users with secure access to internal corporate resources by authenticating the user through an internet browser.
783 Clientless remote access
784
785Which of the following statements is TRUE about R80 management plug-ins?
786 A management plug-in interacts with a Security Management Server to provide new features and support for new products
787
788Fill in the blank: Gaia can be configured using the _______ or ______ .
789 Command line interface; WebUI
790
791Review the following screenshot and select the best answer
792 If a connection is dropped in Network Layer, it will not be matched against the rules in Data Center Layer
793
794Which of the following is NOT a SecureXL traffic flow?
795 Fast Path
796
797Which of the following Automatically Generated Rules NAT rules have the lowest implementation priority?
798 Address Range Hide NAT
799 Network Hide NAT
800
801In R80 spoofing is defined as a method of:
802 Making packets appear as if they come from an authorized IP address (defined on the specific interface)
803
804Which of the following is NOT an integral part of VPN communication within a network?
805 VPN key
806
807Two administrators Dave and Jon both manage R80 Management as administrators for Alpha Corp.
808Jon logged into the R80 Management and then shortly after Dave lgogged in to the same server. They are both in the Security Policies view. From the screenshots
809 Jon is currently editing rule no.6 but has not yet Published his changes
810
811Vanessa is a firewall administrator in her company. Her company is using Check Point firewalls on central and remote locations which are managed centrally by R80 Security Management Server. One central location has an installed R77.30 Gateway on Open Server.
812 On central firewall AES128 encryption is used for SIC on Remote firewall 3DES encryption is used for SIC
813
814Fill in the blank: The ____ is used to obtain identification and security information about network users
815 User Directory
816
817Which Check Point feature enables application scanning and the detection
818 AppWiki
819
820Where can you trigger a failover of the cluster members?
8211)Log in to Security Gateway CLI and run command clusterXL_admin down
8222)In SmartView Monitor right-click the Security Gateway member and select Cluster member stop.
8233)Log into Security Gateway CLI and run command cphaprob down
824 1 and 2
825
826Which utility allows you to configure the DHCP service on GAIA from the command line
827 sysconfig
828
829Which VPN routing option uses VPN routing for every connection a satellite gateway handles?
830 To center, or through the center to other satellites, to internet and other VPN targets
831
832Which product correlates logs and detects security threats, providing a centralized display of potential attack patterns form all network devices?
833 SmartEvent
834
835What will be the effect of running the following command on the Security Management Server? (fw unloadlocal)
836 Remove the installed Security Policy
837
838An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both office are protected by Check Point Security Gateway managed by the same Security Management Server.
839Why does it not allow him to specify the pre-shared secret?
840 Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS
841
842Alpha Corp have recently returned from a training course on Check Points new advanced R80 management platform. You are presenting an in-house R80 Management to the other administrator in Alpha Corp. How will you describe the new "Publish" button in R80 Management Console
843 The Publish button makes any changes an administrator has made in their management session visible to all other administrator sessions and saves it to the Database.
844
845What can we infer about the recent changes made to the Rule Base?
846 Rule 1 and object webserver are locked by another administrator
847
848ALPHA Corp has a new administrator who logs into the Gaia Portal to make some changes. He realizes that even though he has logged in as an administrator, he is unable to make any changes because all configuration options are greyed out as shown in the screenshot image below. What is the likely cause for this?
849 The database is locked by another administrator SSH session.
850
851Administrator Kofi has just made some changes on his Management Server and then clicks on the Publish button in SmartConsole but then gets the error message shown in the screenshot below. Where can the administrator check for more information on these errors?
852 The Validations section in SmartConsole
853
854Harriet wants to protect sensitive information from intentional loss when users browse to a specific URL: https://personal.mymail.com , which blade will she enable to achieve her goal
855 DLP
856
857To optimize Rule Base efficiency the most hit rules should be where?
858 Towards the top of the Rule Base
859
860Which of the following is NOT a license activation method?
861 SmartConsole Wizard
862
863Which policy type has its own Exceptions section?
864 Threat Prevention
865
866By default, which port does the WebUI listen on?
867 443
868
869When doing a Stand-Alone installation, you would install the Security Management Server with which other Check Point architecture component?
870 Security Gateway
871
872Which options are given on features, when editing a Role on Gaia Platform?
873 Read/Write, Read only, None
874
875What is the default time length that Hit Cound Data is kept?
876 3 month
877
878Choose the Best place to find a Security Management Server backup file named backup_fw, on a Check Point Appliance
879 /var/log/Cpbackup/backups/backup_fw.tgz
880
881With which command can view the running configuration of Gaia-based system.
882 show configuration
883
884Which of the following is TRUE regarding Gaia command line?
885 All configuration changes should be made in CLISH and expert-mode should be used for OS-level tasks
886
887Which one of the following is the preferred licensing model? Select the Best answer.
888 Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency of the gateway.
889
890Tom has been tasked to install Check Point R80 in a distributed deployment. Before Tom installs the systems this way, how many machines will he need if he does NOT include a SmartConsole machine in his calculations?
891 Two machines
892
893Fill in the blank: A new license should be generated and installed in all of the following situations EXCEPT when _____.
894 The license is attached to the wrong Security Gateway
895
896When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored.
897 Security Management Server($FWDIR\conf\ bze $CPDIR - Licence Contract Repository) , (/var/log/cpupgrade/suroot - Package Repository)
898
899Fill in the blank: The tool ____ generates a R80 Security Gateway configuration report.
900 cpinfo
901
902Which of the following commands can be used to remove site-to-site IPSEC Security Associations (SA)?
903 vpn tun
904
905Which of the following is NOT an authentication scheme used for accounts created through SmartConsole?
906 Security questions
907
908While enabling the Identity Awareness blade the Identity Awareness wizard does not automatically detect the windows domain. Why does it not detect the windows domain?
909 SmartConsole machine is not part of the domain
910
911View the rule below. What does the lock-symbol in the left column mean? Select the BEST answer.
912 Another user has locked the rule for editing
913
914When attempting to start a VPN tunnel, in the logs the error "no proposal chosen" is seen numerous times. No other VPN-related log entries are present. Which phase of the VPN negotiations has failed?
915 IKE Phase 2
916
917You are the administrator for Alpha Corp. You have logged into your R80 Management server. You are making some changes in the Rule Base and notice that rule No.6 has a pencil icon next to it.
918 The rule No.6 has been marked for editing in your Management session
919
920Which type of the Check Point license ties the package license to the IP address of the Security Management Server?
921 Central
922
923What is NOT an advantage of Packet Filtering?
924 Low Security and No Screening above Network Layer
925
926In the Check Point three-tiered architecture, which of the following is NOT a funciton of the Security Management Server?
927 Display policies and logs on the administrators workstation
928
929Web Control Layer has been set up using the settings in the following dialogue, Consider the following policy and select the BEST answer
930 Anyone from internal network can access the internet, except the traffic defined in drop rules 5.2,5.5 and 5.6
931
932Why would an administrator see the message below?
933 A new Policy Package created on the Management is going to be installed to the existing Gateway
934
935Fill in the blank: The ______ software blade enables Application Security policies to allow, block or limit website access based on user, group, and machine identities
936 Application Control
937
938At what point is the internal certificate authority (ICA) created?
939 During the primary Security Management Server installation process.
940
941In which VPN community is a satellite VPN gateway not allowed to create a VPN tunnel with another satellite VPN gateway?
942 Star
943
944Which information is included in the "Full Log" tracking option, but is not included in the "Log" tracking option?
945 Data type information
946
947In the R80 SmartConsole on which tab are Permissions and Administrators defined?
948 Manage and Settings
949
950Which type of Endpoint Identity Agent includes packet tagging and computer authentication?
951 Full
952
953Fill in the blanks: The Application Layer Firewalls inspect traffic thorugh the ______ layer of the TCP/IP model and up to and including the ______ layer.
954 Lower; Application
955
956There are two R77.30 Security Gateways in the Firewall Cluster(FW_A and FW_B). FW_A fails , FW_B is now the active. When FW_A rejoins the cluster will it become active automatically?
957 No, since "maintain current active cluster member" option on the cluster object properties is enabled by default.
958
959After the initial installation the First Time Configuration Wizard should be run. Select the BEST answer.
960 First Time Configuration Wizard can be run from the command line or from the WebUI
961
962In order to modify Security Policies the administrator can use which of the following tools? Select the BEST answer.
963 SmartConsole or mgmt_cli on any computer where SmartConsole is installed.
964
965Fill in the blanks: A Check Point software license consists of a ______ and ______ .
966 Software blade; software container
967
968Which of the complete statements is NOT true? The WebUI can be used to manage user accounts and:
969 assign user rights to their home directory in the Security Management Server
970
971Fill in the blanks: A security Policy is created in ___________, stored in the ________, and Distributed to the various ______ .
972 SmartConsole, Security Management Server, Security Gateways
973
974Fill in the blank: Licenses can be added to the License and Contract repository ______ .
975 From the User center, from a file or manually
976
977
978
979show uptime - how long the system has been running
980
981show version all - full system version information
982
983show version os build OS version information
984show version os edition
985show version os kernel
986
987fw stat - Security Policy installed on a gateway
988fw getifs - Display interface information
989fw ver - Check Point software version
990
991WebUI modes - Basic & Advanced
992
993Add role definition - add rba role <Namee> domain-type System readonly-features <list>
994
995set expert-password
996save config
997
998tcpdump -ni eth1 - Packet sniff on eth1
999
1000show route - display route information
1001
1002netstat -rn - routing table
1003
1004netstat -an - running services and down ports
1005
1006fw getifs - display interface information
1007
1008SID method - Certificates ,TLS for secure channel , 3DES or AES128 for encryption
1009
1010Communicating, Unknown , Not Communicating
1011
1012Implied - Global Properties
1013Implicit - "Cleanup rule" wenn nichts matched
1014Explicit - Admin created rules
1015
1016Threat Prevention - IPS, Anti-Bot, Antivirus, Threat Emulation
1017Access Control - Firewall, Application Control and URL Filtering, NAT, Content Awareness
1018ThreatWiki - Malware Database
1019
1020Save/Show Configuration -> Gaia os configuration
1021
1022add backup local , tftp ip - /var/log/CPbackup/backups
1023
1024show backup status
1025
1026SAM - Suspicious Activity Monitoring integrated in SmartView Monitor. Can be used to block activities that are displayed in the SmartView Monitor
1027 Suspicious Activity Rule -
1028
1029CCP - Cluster Control Protocol
1030
1031Priority Queueing - Auch wenn 100% ausgelastet -> prioritiziere ssh.