[Q295-Q320] CheckPoint 156-915.80 Practice Verified Answers - Pass Your Exams For Sure! [2021]

Share

CheckPoint 156-915.80 Practice Verified Answers - Pass Your Exams For Sure! [2021]

Valid Way To Pass CCSE Update's  156-915.80 Exam

NEW QUESTION 295
Jennifer McHanry is CEO of ACME. She recently bought her own personal iPad. She wants use her iPad to access the internal Finance Web server. Because the iPad is not a member of the Active Directory domain, she cannot identify seamlessly with AD Query.
However, she can enter her AD credentials in the Captive Portal and then get the same access as on her office computer. Her access to resources is based on rules in the R80 Firewall Rule Base.
To make this scenario work, the IT administrator must:
1) Enable Identity Awareness on a gateway and select Captive Portal as one of the Identity Sources.
2) In the Portal Settings window in the User Access section, make sure that Name and password login is selected.
3) Create a new rule in the Firewall Rule Base to let Jennifer McHanry access network destinations. Select accept as the Action.
Ms. McHanry tries to access the resource but is unable. What should she do?

  • A. Have the security administrator reboot the firewall
  • B. Install the Identity Awareness agent on her iPad
  • C. Have the security administrator select Any for the Machines tab in the appropriate Access Role
  • D. Have the security administrator select the Action field of the Firewall Rule "Redirect HTTP connections to an authentication (captive) portal"

Answer: D

 

NEW QUESTION 296
Which command will reset the kernel debug options to default settings?

  • A. fw ctl dbg -a 0
  • B. fw ctl dbg resetall
  • C. fw ctl debug 0
  • D. fw ctl debug set 0

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Reset the debugs to the default.
In case someone changed the setting in the past and since then the firewall was not rebooted we should set all back to the defaults.

Reference: https://itsecworks.com/2011/08/09/checkpoint-firewall-debugging-basics/

 

NEW QUESTION 297
Which is NOT an example of a Check Point API?

  • A. OPSEC SDK
  • B. Threat Prevention API
  • C. Gateway API
  • D. Management API

Answer: C

 

NEW QUESTION 298
You have existing dbedit scripts from R77. Can you use them with R80.10?

  • A. dbedit scripts are being replaced by mgmt._cli in R80.10
  • B. You can use dbedit to modify threat prevention or access policies, but not create or modify layers
  • C. dbedit is not supported in R80.10
  • D. dbedit is fully supported in R80.10

Answer: A

Explanation:
Explanation
dbedit (or GuiDbEdit) uses the cpmi protocol which is gradually being replaced by the new R80.10 automation architecture. cpmi clients are still supported in R80.10, but there are some functionalities that cannot be managed by cpmi anymore. For example, the Access and Threat policies do not have a cpmi representation.
They can be managed only by the new mgmt_cli and not by cpmi clients. There are still many tables that have an inner cpmi representation (for example, network objects, services, servers, and global properties) and can still be managed using cpmi.
References:

 

NEW QUESTION 299
In SPLAT the command to set the timeout was idle. In order to achieve this and increase the timeout for Gaia, what command do you use?

  • A. set idle <value>
  • B. set timeout <value>
  • C. set inactivity-timeout <value>
  • D. set inactivity <value>

Answer: C

Explanation:
Section: (none)
Explanation/Reference:
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk95447

 

NEW QUESTION 300
To verify the SecureXL status, you would enter command _____________ .

Answer:

Explanation:
fwaccel stat

 

NEW QUESTION 301
SecureXL improves non-encrypted firewall traffic throughput and encrypted VPN traffic throughput.

  • A. This statement is false because encrypted traffic cannot be inspected
  • B. This statement is false because SecureXL does not improve this traffic but CoreXL does
  • C. This statement is true because SecureXL does improve all traffic
  • D. This statement is true because SecureXL does improve this traffic

Answer: D

Explanation:
SecureXL improved non-encrypted firewall traffic throughput, and encrypted VPN traffic throughput, by nearly an order-of-magnitude- particularly for small packets flowing in long duration connections.

 

NEW QUESTION 302
In SPLAT the command to set the timeout was idle. In order to achieve this and increase the timeout for Gaia, what command do you use?

  • A. set idle <value>
  • B. set timeout <value>
  • C. set inactivity-timeout <value>
  • D. set inactivity <value>

Answer: C

 

NEW QUESTION 303
Which of these options is an implicit MEP option?

  • A. Load Sharing
  • B. Round robin
  • C. Primary-backup
  • D. Source address based

Answer: C

Explanation:
There are three methods to implement implicit MEP:
First to Respond, in which the first Security Gateway to reply to the peer Security Gateway is chosen. An organization would choose this option if, for example, the organization has two Security Gateways in a MEP configuration - one in London, the other in New York. It makes sense for VPN-1 peers located in England to try the London Security Gateway first and the NY Security Gateway second. Being geographically closer to VPN peers in England, the London Security Gateway is the first to respond, and becomes the entry point to the internal network. See: First to Respond.
Primary-Backup, in which one or multiple backup Security Gateways provide "high availability" for a primary Security Gateway. The remote peer is configured to work with the primary Security Gateway, but switches to the backup Security Gateway if the primary goes down. An organization might decide to use this configuration if it has two machines in a MEP environment, one of which is stronger than the other. It makes sense to configure the stronger machine as the primary. Or perhaps both machines are the same in terms of strength of performance, but one has a cheaper or faster connection to the Internet. In this case, the machine with the better Internet connection should be configured as the primary. See: Primary-Backup Security Gateways.
Load Distribution, in which the remote VPN peer randomly selects a Security Gateway with which to open a connection. For each IP source/destination address pair, a new Security Gateway is randomly selected. An organization might have a number of machines with equal performance abilities. In this case, it makes sense to enable load distribution. The machines are used in a random and equal way. See: Random Selection.

 

NEW QUESTION 304
To bind a NIC to a single processor when using CoreXL on GAiA, you would use the command: _______ ?

Answer:

Explanation:
sim affinity

 

NEW QUESTION 305
What is the purpose of a SmartEvent Correlation Unit?

  • A. The Correlation unit role is to evaluate logs from the log server component to identify patterns/threats and convert them to events.
  • B. The SmartEvent Correlation Unit's task it to assign severity levels to the identified events.
  • C. The SmartEvent Correlation Unit is designed to check the availability of the SmartReporter Server
  • D. The SmartEvent Correlation Unit is designed to check the connection reliability from SmartConsole to the SmartEvent Server

Answer: A

 

NEW QUESTION 306
Assume you are a Security Administrator for ABCTech. You have allowed authenticated access to users from Mkting_net to Finance_net. But in the user's properties, connections are only permitted within Mkting_net. What is the BEST way to resolve this conflict?

  • A. Select Intersect with user database or Ignore Database in the Action Properties window.
  • B. Permit access to Finance_net.
  • C. Select Intersect with user database in the Action Properties window.
  • D. Select Ignore Database in the Action Properties window.

Answer: A

 

NEW QUESTION 307
Fill in the blank. The user wants to replace a failed Windows-based firewall with a new server running GAiA.

Answer:

Explanation:
For the most complete restore of an GAiA configuration, he or she will use the command migrate_import

 

NEW QUESTION 308
Which NAT rules are prioritized first?

  • A. Automatic Static NAT
  • B. Automatic Hide NAT
  • C. Manual/Pre-Automatic NAT
  • D. Post-Automatic/Manual NAT rules

Answer: C

Explanation:
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Firewall_WebAdmin/6724.htm

 

NEW QUESTION 309
You find that Gateway fw2 can NOT be added to the cluster object. What are possible reasons for that?
Exhibit:

1) fw2 is a member in a VPN community.
2) ClusterXL software blade is not enabled on fw2.
3) fw2 is a DAIP Gateway.

  • A. All
  • B. 1 or 2
  • C. 2 or 3
  • D. 1 or 3

Answer: D

 

NEW QUESTION 310
You have three servers located in a DMZ, using private IP addresses. You want internal users from 10.10.10.x to access the DMZ servers by public IP addresses. Internal_net 10.10.10.x is configured for Hide NAT behind the Security Gateway's external interface.

What is the best configuration for 10.10.10.x users to access the DMZ servers, using the DMZ servers' public IP addresses?

  • A. When connecting to internal network 10.10.10.x, configure Hide NAT for the DMZ network behind the Security Gateway DMZ interface.
  • B. When connecting to the Internet, configure manual Static NAT rules to translate the DMZ servers.
  • C. When the source is the internal network 10.10.10.x, configure manual static NAT rules to translate the DMZ servers.
  • D. When trying to access DMZ servers, configure Hide NAT for 10.10.10.x behind the DMZ's interface.

Answer: C

 

NEW QUESTION 311
Fill in the blank.

In New Mode HA, the internal cluster IP VIP address is 10.4.8.3.
The internal interfaces on two members are 10.4.8.1 and 10.4.8.2 Internal host 10.4.8.108 pings 10.4.8.3, and receives replies.
Review the ARP table from the internal Windows host 10.4.8.108.
According to the output, which member is the standby machine?

Answer:

Explanation:
10.4.8.1

 

NEW QUESTION 312
Fill in the blank with a numeric value. The default port number for standard TCP connections with the LDAP server is _______?

Answer:

Explanation:
389

 

NEW QUESTION 313
Which is not a blade option when configuring SmartEvent?

  • A. Correlation Unit
  • B. Log Server
  • C. SmartEvent Server
  • D. SmartEvent Unit

Answer: D

Explanation:
Explanation/Reference:
Explanation:
On the Management tab, enable these Software Blades:
Logging & Status

SmartEvent Server

SmartEvent Correlation Unit

Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_LoggingAndMonitoring/ html_frameset.htm?topic=documents/R80/CP_R80_LoggingAndMonitoring/120829

 

NEW QUESTION 314
Review the Rule Base displayed.

For which rules will the connection templates be generated in SecureXL?

  • A. Rules 2 and 5
  • B. All rules except Rule 3
  • C. Rules 2 through 5
  • D. Rule 2 only

Answer: B

 

NEW QUESTION 315
CORRECT TEXT
Fill in the blank with a numeric value. The default port number for standard TCP connections with the LDAP server is

Answer:

Explanation:
389

 

NEW QUESTION 316
CORRECT TEXT
In a zero downtime firewall cluster environment, what command syntax do you run to avoid switching problems around the cluster for command cphaconf?

Answer:

Explanation:
set_ccp
broadcast

 

NEW QUESTION 317
Your perimeter Security Gateway's external IP is 200.200.200.3. Your network diagram shows:

Required: Allow only network 192.168.10.0 and 192.168.20.0 to go out to the Internet, using 200.200.200.5.
The local network 192.168.1.0/24 needs to use 200.200.200.3 to go out to the Internet.
Assuming you enable all the settings in the NAT page of Global Properties, how could you achieve these requirements?

  • A. Create network objects for 192.168.10.0/24 and 192.168.20.0/24. Enable Hide NAT on both network objects, using 200.200.200.5 as hiding IP address. Add an ARP entry for 200.200.200.3 for the MAC address of 200.200.200.5.
  • B. Create two network objects: 192.168.10.0/24 and 192.168.20.0/24. Add the two network objects to a group object. Create a manual NAT rule like the following: Original source - group object; Destination - any; Service - any; Translated source - 200.200.200.5; Destination - original; Service - original.
  • C. Create an Address Range object, starting from 192.168.10.1 to 192.168.20.254. Enable Hide NAT on the NAT page of the address range object. Enter Hiding IP address 200.200.200.5. Add an ARP entry for 200.200.200.5 for the MAC address of 200.200.200.3.
  • D. Create a network object 192.168.0.0/16. Enable Hide NAT on the NAT page. Enter 200.200.200.5 as the hiding IP address. Add an ARP entry for 200.200.200.5 for the MAC address of 200.200.200.3.

Answer: C

 

NEW QUESTION 318
What's true about Troubleshooting option in the IPS profile properties?

  • A. Temporarily change the active protection profile to "Default_Protection"
  • B. Temporarily will disable IPS kernel engine
  • C. Temporarily set all protections to track (log) in SmartView Tracker
  • D. Temporarily set all active protections to Detect

Answer: C

 

NEW QUESTION 319
Which method below is NOT one of the ways to communicate using the Management API's?

  • A. Typing API commands from a dialog box inside the SmartConsole GUI application
  • B. Sending API commands over an http connection using web-services
  • C. Typing API commands using the "mgmt._cli" command
  • D. Typing API commands using Gaia's secure shell (clash)19+

Answer: B

Explanation:
Reference: https://sc1.checkpoint.com/documents/R80/APIs/#introduction%20

 

NEW QUESTION 320
......

CheckPoint 156-915.80 Pre-Exam Practice Tests | Easy4Engine: https://www.easy4engine.com/156-915.80-test-engine.html