156-215.81 Practice Exams and Training Solutions for Certifications
Dumps Free Test Engine Player Verified Answers
NEW QUESTION # 152
Log query results can be exported to what file format?
- A. Word Document (docx)
- B. Text (txt)
- C. Comma Separated Value (csv)
- D. Portable Document Format (pdf)
Answer: C
NEW QUESTION # 153
Which of the following is NOT supported by Bridge Mode on the Check Point Security Gateway?
- A. Application Control
- B. NAT
- C. Antivirus
- D. Data Loss Prevention
Answer: B
Explanation:
NAT rules (specifically, Firewall kernel in logs shows the traffic as accepted, but Security Gateway does not actually forward it). For more information, see sk106146. https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Installation_and_Upgrade_Guide/Topics-IUG/Deploying-Security-Gateway-or-ClusterXL-in-Bridge-Mode.htm
NEW QUESTION # 154
Administrator Dave logs into R80 Management Server to review and makes some rule changes. He notices that there is a padlock sign next to the DNS rule in the Rule Base.
What is the possible explanation for this?
- A. DNS Rule is a placeholder rule for a rule that existed in the past but was deleted.
- B. Another administrator is logged into the Management and currently editing the DNS Rule.
- C. DNS Rule is using one of the new feature of R80 where an administrator can mark a rule with the padlock icon to let other administrators know it is important.
- D. This is normal behavior in R80 when there are duplicate rules in the Rule Base.
Answer: B
Explanation:
Explanation
The padlock sign next to the DNS rule in the Rule Base indicates that another administrator is logged into the Management and currently editing the DNS Rule1. This is a feature of R80 that allows multiple administrators to work on the same policy simultaneously. The padlock sign prevents other administrators from modifying the same rule until the editing administrator publishes or discards the changes2. The other options are not valid explanations for the padlock sign. References: 156-215.80 : Check Point Certified Security Administrator (CCSA R80) : Part 19, Multi-User Policy Editing
NEW QUESTION # 155
The Firewall kernel is replicated multiple times, therefore:
- A. The Firewall can run the same policy on all cores
- B. The Firewall kernel only touches the packet if the connection is accelerated
- C. The Firewall kernel is replicated only with new connections and deletes itself once the connection times out
- D. The Firewall can run different policies per core
Answer: A
NEW QUESTION # 156
How do you manage Gaia?
- A. Through CLI only
- B. Through CLI and WebUI
- C. Through SmartDashboard only
- D. Through CLI, WebUI, and SmartDashboard
Answer: D
NEW QUESTION # 157
Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.
- A. Anti-Spoofing
- B. Failovers
- C. Asymmetric routing
- D. Symmetric routing
Answer: B
Explanation:
Explanation
The Sticky Decision Function (SDF) is required to prevent failovers in an Active-Active cluster. The SDF ensures that the same cluster member handles all connections that belong to a certain session. If the SDF is not enabled, different cluster members may handle different connections of the same session, which may cause a failover or a drop12. References: ClusterXL Administration Guide R81, Check Point CCSA - R81: Practice Test & Explanation
NEW QUESTION # 158
What command would show the API server status?
- A. cpm status
- B. show api status
- C. api status
- D. api restart
Answer: B
NEW QUESTION # 159
Fill in the blank: ________information is included in the "Full Log" tracking option, but is not included in the "Log" tracking option?
- A. file attributes
- B. destination port
- C. application
- D. data type
Answer: D
Explanation:
Tracking Options
NEW QUESTION # 160
When should you generate new licenses?
- A. Before installing contract files.
- B. After an RMA procedure when the MAC address or serial number of the appliance changes.
- C. Only when the license is upgraded.
- D. When the existing license expires, license is upgraded or the IP-address where the license is tied changes.
Answer: D
NEW QUESTION # 161
Fill in the blank: A(n) _____ rule is created by an administrator and is located before the first and before last rules in the Rule Base.
- A. Explicit
- B. Implicit drop
- C. Firewall drop
- D. Implied
- E. Implicit accept
Answer: D
NEW QUESTION # 162
Which tool CANNOT be launched from SmartUpdate R77?
- A. snapshot
- B. cpinfo
- C. GAiA WebUI
- D. IP Appliance Voyager
Answer: A
NEW QUESTION # 163
You manage a global network extending from your base in Chicago to Tokyo, Calcutta and Dallas. Management wants a report detailing the current software level of each Enterprise class Security Gateway. You plan to take the opportunity to create a proposal outline, listing the most cost-effective way to upgrade your Gateways.
Which two SmartConsole applications will you use to create this report and outline?
- A. SmartView Tracker and SmartView Monitor
- B. SmartDashboard and SmartView Tracker
- C. SmartLSM and SmartUpdate
- D. SmartView Monitor and SmartUpdate
Answer: D
NEW QUESTION # 164
John is using Management HA. Which Smartcenter should be connected to for making changes?
- A. connect virtual IP of Smartcenter HA
- B. secondary Smartcenter
- C. active Smartcenter
- D. primary Smartcenter
Answer: C
NEW QUESTION # 165
Which Check Point software blade provides visibility of users, groups and machines while also providing access control through identity-based policies?
- A. Firewall
- B. URL Filtering
- C. Identity Awareness
- D. Application Control
Answer: C
NEW QUESTION # 166
Which of the following is considered a "Subscription Blade", requiring renewal every 1-3 years?
- A. Firewall Blade
- B. Identity Awareness Blade
- C. IPS blade
- D. IPSEC VPN Blade
Answer: C
NEW QUESTION # 167
Gaia has two default user accounts that cannot be deleted. What are those user accounts?
- A. Control and Monitor
- B. Admin and Default
- C. Expert and Clish
- D. Admin and Monitor
Answer: D
Explanation:
Explanation
Gaia has two default user accounts that cannot be deleted. They are Admin and Monitor. Admin is the user account that has full administrative privileges and can access both WebUI and CLI. Monitor is the user account that has read-only privileges and can access only WebUI2. The other options are not default user accounts in Gaia.
NEW QUESTION # 168
If there are two administrators logged in at the same time to the SmartConsole, and there are objects locked for editing, what must be done to make them available to other administrators? Choose the BEST answer
- A. Save and install the Policy
- B. Publish or discard the session
- C. Revert the session.
- D. Delete older versions of database
Answer: B
NEW QUESTION # 169
After the initial installation on Check Point appliance, you notice that the Management interface and default gateway are incorrect. Which commands could you use to set the IP to 192.168.80.200/24 and default gateway to 192.168.80.1.
- A. add interface Mgmt ipv4-address 192.168.80.200 mask-length 24add static-route default nexthop gateway address 192.168.80.1 onsave config
- B. set interface Mgmt ipv4-address 192.168.80.200 mask-length 24set static-route default nexthop gateway address 192.168.80.1 onsave config
- C. add interface Mgmt ipv4-address 192.168.80.200 255.255.255.0add static-route 0.0.0.0.0.0.0.0 gw
192.168.80.1 onsave config - D. set interface Mgmt ipv4-address 192.168.80.200 255.255.255.0add static-route 0.0.0.0.0.0.0.0 gw
192.168.80.1 onsave config
Answer: B
Explanation:
Explanation
The commands you could use to set the IP to 192.168.80.200/24 and default gateway to 192.168.80.1 after the initial installation on Check Point appliance are:
set interface Mgmt ipv4-address 192.168.80.200 mask-length 24. This command sets the IPv4 address and subnet mask of the Management interface.
set static-route default nexthop gateway address 192.168.80.1 on. This command sets the default gateway for IPv4 routing.
save config. This command saves the configuration changes.
References: [Check Point R81 Gaia CLI Reference Guide], [Check Point R81 Gaia Administration Guide]
NEW QUESTION # 170
Which of the following is NOT a method used by Identity Awareness for acquiring identity?
- A. Active Directory Query
- B. RADIUS
- C. Remote Access
- D. Cloud IdP (Identity Provider)
Answer: D
Explanation:
Explanation
Identity Awareness uses several methods for acquiring identity, such as Active Directory Query, Identity Agent, Browser-Based Authentication, Terminal Servers, Captive Portal, and RADIUS12. Cloud IdP (Identity Provider) is not a method used by Identity Awareness12. Therefore, the correct answer is B. Cloud IdP (Identity Provider).
NEW QUESTION # 171
......
Q&As with Explanations Verified & Correct Answers: https://www.exams-boost.com/156-215.81-valid-materials.html
156-215.81 Dumps with Free 365 Days Update Fast Exam Updates: https://drive.google.com/open?id=1i1iuYbtWcmRF44kK5m3TmV3eyDupJPHi