[Aug-2021] 156-215.80 Pre-Exam Practice Tests Exam Questions and Answers for CCSA R80 Study Guide [Q122-Q137]

Share

[Aug-2021] 156-215.80 Pre-Exam Practice Tests | Exam Questions and Answers for CCSA R80 Study Guide

Check Point Certified Security Administrator R80 Certification Sample Questions

NEW QUESTION 122
When doing a Stand-Alone Installation, you would install the Security Management Server with which other Check Point architecture component?

  • A. SmartConsole
  • B. None, Security Management Server would be installed by itself.
  • C. SecureClient
  • D. Security Gateway

Answer: D

Explanation:
Explanation/Reference:
Explanation:
There are different deployment scenarios for Check Point software products.
Standalone Deployment - The Security Management Server and the Security Gateway are installed

on the same computer or appliance.
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Installation_and_Upgrade_Guide-webAdmin/86429.htm

 

NEW QUESTION 123
Which utility allows you to configure the DHCP service on GAIA from the command line?

  • A. cpconfig
  • B. sysconfig
  • C. ifconfig
  • D. dhcp_cfg

Answer: B

Explanation:
Explanation
Sysconfig Configuration Options

References:

 

NEW QUESTION 124
A Check Point software license consists of a _______ and _______ .

  • A. Software package; signature
  • B. Signature; software blade
  • C. Software container; software package
  • D. Software blade; software container

Answer: D

Explanation:
Explanation
Check Point's licensing is designed to be scalable and modular. To this end, Check Point offers both predefined packages as well as the ability to custom build a solution tailored to the needs of the Network Administrator. This is accomplished by the use of the following license components:
* Software Blades
* Container

 

NEW QUESTION 125
In R80, Unified Policy is a combination of

  • A. Firewall policy, address Translation and application and URL filtering, QoS Policy,
    Desktop Security Policy and Threat Prevention Policy.
  • B. Access control policy, QoS Policy, Desktop Security Policy and Threat Prevention
    Policy.
  • C. Access control policy, QoS Policy, Desktop Security Policy and endpoint policy.
  • D. Access control policy, QoS Policy, DesktopSecurity Policy and VPN policy.

Answer: D

Explanation:
D is the best answer given the choices.
Unified Policy
In R80 the Access Control policy unifies the policies of these pre-R80 Software Blades:

 

NEW QUESTION 126
There are 4 ways to use the Management API for creating host object with R80 Management API. Which one is NOT correct?

  • A. Using SmartConsole GUI console
  • B. Using Web Services
  • C. Using CLISH
  • D. Using Mgmt_cli tool

Answer: C

Explanation:
Explanation
References:

 

NEW QUESTION 127
NAT can NOT be configured on which of the following objects?

  • A. Gateway
  • B. HTTP Logical Server
  • C. Host
  • D. Address Range

Answer: B

 

NEW QUESTION 128
You find a suspicious connection from a problematic host. You decide that you want to block everything from that whole network, not just the problematic host. You want to block this for an hour while you investigate further, but you do not want to add any rules to the Rule Base. How do you achieve this?

  • A. Use dbeditto script the addition of a rule directly into the Rule Bases_5_0.fwsconfiguration file.
  • B. Select Block intruder from the Tools menu in SmartView Tracker.
  • C. Create a Suspicious Activity Rule in Smart Monitor.
  • D. Add a temporary rule using SmartDashboard and select hide rule.

Answer: C

 

NEW QUESTION 129
Why would an administrator see the message below?

  • A. A new Policy Package created on the Gateway and transferred to the management will be overwritten by the Policy Package currently on the Gateway but can be restored from a periodic backup on the Gateway.
  • B. A new Policy Package created on the Gateway is going to be installed on the existing Management.
  • C. A new Policy Package created on the Management is going to be installed to the existing Gateway.
  • D. A new Policy Package created on both the Management and Gateway will be deleted and must be packed up first before proceeding.

Answer: C

 

NEW QUESTION 130
You are going to upgrade from R77 to R80. Before the upgrade, you want to back up the system so that, if there are any problems, you can easily restore to the old version with all configuration and management files intact. What is the BEST backup method in this scenario?

  • A. backup
  • B. Database Revision
  • C. snapshot
  • D. migrate export

Answer: C

Explanation:
Explanation
2. Snapshot Management
The snapshot creates a binary image of the entire root (lv_current) disk partition. This includes Check Point products, configuration, and operating system.
Starting in R77.10, exporting an image from one machine and importing that image on another machine of the same type is supported.
The log partition is not included in the snapshot. Therefore, any locally stored FireWall logs will not be saved.

 

NEW QUESTION 131
At what point is the Internal Certificate Authority (ICA) created?

  • A. When an administrator decides to create one.
  • B. When an administrator initially logs into SmartConsole.
  • C. Upon creation of a certificate
  • D. During the primary Security Management Server installation process.

Answer: D

Explanation:
Introduction to the ICA
The ICA is a Certificate Authority which is an integral part of the Check Point product suite. It is fully compliant with X.509 standards for both certificates and CRLs. See the relevant X.509 and PKI documentation, as well as RFC 2459 standards for more information. You can read more about Check Point and PKI in the R76 VPN Administration Guide.
The ICA is located on the Security Management server. It is created during the installation process, when the Security Management server is configured.

 

NEW QUESTION 132
To enforce the Security Policy correctly, a Security Gateway requires:

  • A. a routing table
  • B. a Demilitarized Zone
  • C. a Security Policy install
  • D. awareness of the network topology

Answer: D

Explanation:
The network topology represents the internal network (both the LAN and the DMZ) protected by the gateway. The gateway must be aware of the layout of the network topology to:
* Correctly enforce the Security Policy.
* Ensure the validity of IP addresses for inbound and outbound traffic.
* Configure a special domain for Virtual Private Networks.
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_SecMan_WebAdmin/html_frameset.htm?
topic=documents/R76/CP_R76_SecMan_WebAdmin/118037

 

NEW QUESTION 133
Using ClusterXL, what statement is true about the Sticky Decision Function?

  • A. Is only relevant when using SecureXL
  • B. Can only be changed for Load Sharing implementations
  • C. Is configured using cpconfig
  • D. All connections are processed and synchronized by the pivot

Answer: B

 

NEW QUESTION 134
With the User Directory Software Blade, you can create R80 user definitions on a(an) ___________ Server.

  • A. NT domain
  • B. LDAP
  • C. SecurID
  • D. SMTP

Answer: B

 

NEW QUESTION 135
Phase 1 of the two-phase negotiation process conducted by IKE operates in ______ mode.

  • A. Quick
  • B. Authentication
  • C. Main
  • D. High Alert

Answer: C

Explanation:
Explanation
Phase I modes
Between Security Gateways, there are two modes for IKE phase I.
These modes only apply to IKEv1:

 

NEW QUESTION 136
Which of the following is NOT a set of Regulatory Requirements related to Information Security?

  • A. Sarbanes Oxley (SOX)
  • B. ISO 37001
  • C. HIPAA
  • D. PCI

Answer: B

Explanation:
ISO 37001 - Anti-bribery management systems
Reference: http://www.iso.org/iso/home/standards/management-standards/iso37001.htm

 

NEW QUESTION 137
......

CheckPoint Exam Practice Test To Gain Brilliante Result: https://www.prepawayexam.com/CheckPoint/braindumps.156-215.80.ete.file.html