[2022] Verified 156-215.80 Dumps Q&As - 1 Year Free & Quickly Updates [Q189-Q205]

Share

[2022] Verified 156-215.80 Dumps Q&As - 1 Year Free & Quickly Updates

Latest 2022 Realistic Verified 156-215.80 Dumps - 100% Free 156-215.80 Exam Dumps

NEW QUESTION 189
In order to modify Security Policies the administrator can use which of the following tools? Select the BEST answer.

  • A. mgmt_cli or WebUI on Security Gateway and SmartConsole on the Security Management Server.
  • B. SmartConsole or mgmt_cli on any computer where SmartConsole is installed.
  • C. SmartConsole and WebUI on the Security Management Server.
  • D. Command line of the Security Management Server or mgmt_cli.exe on any Windows computer.

Answer: B

 

NEW QUESTION 190
NAT can NOT be configured on which of the following objects?

  • A. HTTP Logical Server
  • B. Host
  • C. Gateway
  • D. Address Range

Answer: A

 

NEW QUESTION 191
Which R80 GUI would you use to see the number of packets accepted since the last policy install?

  • A. SmartView Status
  • B. SmartView Monitor
  • C. SmartView Tracker
  • D. SmartDashboard

Answer: B

 

NEW QUESTION 192
Which type of Endpoint Identity Agent includes packet tagging and computer authentication?

  • A. Full
  • B. Custom
  • C. Light
  • D. Complete

Answer: A

Explanation:
Explanation/Reference:
Endpoint Identity Agents - dedicated client agents installed on users' computers that acquire and report identities to the Security Gateway.

 

NEW QUESTION 193
Web Control Layer has been set up using the settings in the following dialogue:

Consider the following policy and select the BEST answer.

  • A. Anyone from internal network can access the internet, expect the traffic defined in drop rules 5.2, 5.5 and 5.6.
  • B. Traffic that does not match any rule in the subpolicy is dropped.
  • C. All employees can access only Youtube and Vimeo.
  • D. Access to Youtube and Vimeo is allowed only once a day.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Policy Layers and Sub-Policies
R80 introduces the concept of layers and sub-policies, allowing you to segment your policy according to your network segments or business units/functions. In addition, you can also assign granular privileges by layer or sub-policy to distribute workload and tasks to the most qualified administrators With layers, the rule base is organized into a set of security rules. These set of rules or layers, are

inspected in the order in which they are defined, allowing control over the rule base flow and the security functionalities that take precedence. If an "accept" action is performed across a layer, the inspection will continue to the next layer. For example, a compliance layer can be created to overlay across a cross-section of rules.
Sub-policies are sets of rules that are created for a specific network segment, branch office or business

unit, so if a rule is matched, inspection will continue through this subset of rules before it moves on to the next rule.
Sub-policies and layers can be managed by specific administrators, according to their permissions

profiles. This facilitates task delegation and workload distribution.
Reference: https://community.checkpoint.com/docs/DOC-1065

 

NEW QUESTION 194
Please choose correct command syntax to add an "emailserver1" host with IP address 10.50.23.90 using GAiA management CLI?

  • A. add host name emailserver1 ip-address 10.50.23.90
  • B. host name myHost12 ip-address 10.50.23.90
  • C. mgmt add host name ip-address 10.50.23.90
  • D. mgmt add host name emailserver1 ip-address 10.50.23.90

Answer: A

 

NEW QUESTION 195
Provide very wide coverage for all products and protocols, with noticeable performance impact.

How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.

  • A. Set High Confidence to Low and Low Confidence to Inactive.
  • B. Set the Performance Impact to Very Low Confidence to Prevent.
  • C. Set the Performance Impact to Medium or lower.
  • D. The problem is not with the Threat Prevention Profile. Consider adding more memory to theappliance.

Answer: C

 

NEW QUESTION 196
There are two R77.30 Security Gateways in the Firewall Cluster. They are named FW_A and FW_B. The
cluster is configured to work as HA (High availability) with default cluster configuration. FW_A is configured
to have higher priority than FW_B. FW_A was active and processing the traffic in the morning. FW_B was
standby. Around 1100 am, its interfaces went down and this caused a failover. FW_B became active. After an
hour, FW_A's interface issues were resolved and it became operational. When it re-joins the cluster, will it
become active automatically?

  • A. No, since "maintain current active cluster member" option on the cluster object properties is enabled by
    default
  • B. Yes, since "Switch to higher priority cluster member" option on the cluster object properties is enabled
    by default
  • C. Yes, since "Switch to higher priority cluster member" option is enabled by default on the Global
    Properties
  • D. No, since "maintain current active cluster member" option is enabled by default on the Global Properties

Answer: A

Explanation:
Explanation
What Happens When a Security Gateway Recovers?
In a Load Sharing configuration, when the failed Security Gateway in a cluster recovers, all connections are
redistributed among all active members. High Availability and Load Sharing in ClusterXL ClusterXL
Administration Guide R77 Versions | 31 In a High Availability configuration, when the failed Security
Gateway in a cluster recovers, the recovery method depends on the configured cluster setting. The options are:
* Maintain Current Active Security Gateway means that if one member passes on control to a lower priority
member, control will be returned to the higher priority member only if the lower priority member fails. This
mode is recommended if all members are equally capable of processing traffic, in order to minimize the
number of failover events.
* Switch to Higher Priority Security Gateway means that if the lower priority member has control and the
higher priority member is restored, then control will be returned to the higher priority member. This mode is
recommended if one member is better equipped for handling connections, so it will be the default Security
Gateway.

 

NEW QUESTION 197
What are the three deployment considerations for a secure network?

  • A. Distributed, Bridge Mode, and Remote
  • B. Bridge Mode, Remote, and Standalone
  • C. Remote, Standalone, and Distributed
  • D. Standalone, Distributed, and Bridge Mode

Answer: A

 

NEW QUESTION 198
Fill in the blank: Back up and restores can be accomplished through_________.

  • A. SmartConsole, WebUI, or CLI
  • B. SmartUpdate, SmartBackup, or SmartConsole
  • C. CLI, SmartUpdate, or SmartBackup
  • D. WebUI, CLI, or SmartUpdate

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Backup and Restore
These options let you:
Back up the Gaia OS configuration and the firewall database to a compressed file

Restore the Gaia OS configuration and the firewall database from a compressed file

To back up a configuration:
1. Right-click the Security Gateway.
2. Select Backup and Restore > Backup.
The Backup window opens.
3. Select the backup location.
Reference: https://community.checkpoint.com/thread/5375-checkpoint-gateway-firewall-backup-through- smart-console

 

NEW QUESTION 199
What is the Manual Client Authentication TELNET port?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 200
It is Best Practice to have a _____ rule at the end of each policy layer.

  • A. Explicit CleanUp
  • B. Implicit Drop
  • C. Implied Drop
  • D. Explicit Drop

Answer: A

Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SmartDashboard_OLH/ html_frameset.htm?topic=documents/R80/CP_R80_SmartDashboard_OLH/NFHf4E9NLQBJlVkHRpc16w2

 

NEW QUESTION 201
Ken wants to obtain a configuration lock from other administrator on R80 Security Management Server. He can do this via WebUI or a via CLI. Which command should be use in CLI? Choose the correct answer.

  • A. The database feature has one command lock database override.
  • B. remove database lock
  • C. override database lock
  • D. The database feature has two commands: lock database override and unlock database. Both will work.

Answer: D

Explanation:
Explanation
Use the database feature to obtain the configuration lock. The database feature has two commands:
The commands do the same thing: obtain the configuration lock from another administrator.

 

NEW QUESTION 202
What action can be performed from SmartUpdate R77?

  • A. fw stat -1
  • B. cpinfo
  • C. remote_uninstall_verifier
  • D. upgrade_export

Answer: B

 

NEW QUESTION 203
Administrator Dave logs into R80 Management Server to review and makes some rule changes. He notices that there is a padlock sign next to the DNS rule in the Rule Base.

What is the possible explanation for this?

  • A. DNS Rule is using one of the new feature of R80 where an administrator can mark a rule with the padlock icon to let other administrators know it is important.
  • B. This is normal behavior in R80 when there are duplicate rules in the Rule Base.
  • C. Another administrator is logged into the Management and currently editing the DNS Rule.
  • D. DNS Rule is a placeholder rule for a rule that existed in the past but was deleted.

Answer: C

 

NEW QUESTION 204
Fill in the blank: Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or__________.

  • A. On all satellite gateway to satellite gateway tunnels
  • B. On specific tunnels for specific gateways
  • C. On specific tunnels in the community
  • D. On specific satellite gateway to central gateway tunnels

Answer: C

Explanation:
Explanation
Each VPN tunnel in the community may be set to be a Permanent Tunnel. Since Permanent Tunnels are constantly monitored, if the VPN tunnel is down, then a log, alert, or user defined action, can be issued. A VPN tunnel is monitored by periodically sending "tunnel test" packets. As long as responses to the packets are received the VPN tunnel is considered "up." If no response is received within a given time period, the VPN tunnel is considered "down." Permanent Tunnels can only be established between Check Point Security Gateways. The configuration of Permanent Tunnels takes place on the community level and:

 

NEW QUESTION 205
......

156-215.80 Dumps PDF and Test Engine Exam Questions: https://www.easy4engine.com/156-215.80-test-engine.html

Get 2022 Updated Free CheckPoint 156-215.80 Exam Questions & Answer: https://drive.google.com/open?id=1zMD_5sp9K8hltZliZT0MzihJRVOmASJm