wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CCSA

Total questions: 121

Worksheet time: 1hrs 1mins

Name
Class
Date
1.

When enabling tracking on a rule, what is the default option?

a)

Accounting Log

b)

Extended Log

c)

Log

d)

Detailed Log

2.

Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?

a)

The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.

b)

Licensed Check Point products for the Gaia operating system and the Gaia operating system itself.

c)

The CPUSE engine and the Gaia operating system.

d)

The Gaia operating system only.

3.

Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?

a)

Both License (.lic) and Contract (.xml) files

b)

cp.macro

c)

Contract file (.xml)

d)

license File (.lie)

4.

Fill in the blank: When LDAP is integrated with Check Point Security Management, it is then referred to as _______.

a)

User Center

b)

User Administration

c)

User Directory

d)

UserCheck

5.

Can you use the same layer in multiple policies or rulebases?

a)

Yes - a layer can be shared with multiple policies and rules.

b)

No - each layer must be unique.

c)

No - layers cannot be shared or reused, but an identical one can be created.

d)

Yes - but it must be copied and pasted with a different name.

6.

Which default Gaia user has full read/write access?

a)

superuser

b)

monitor

c)

altuser

d)

admin

7.

Which icon in the WebUI indicates that read/write access is enabled?

a)

Eyeglasses

b)

Pencil

c)

Padlock

d)

Book

8.

Which SmartConsole tab is used to monitor network and security performance?

a)

Logs Monitor

b)

Manage Settings

c)

Security Policies

d)

Gateway Servers

9.

Check Point Update Service Engine (CPUSE), also known as Deployment Agent [DA], is an advanced and intuitive mechanism for software deployment on Gaia OS. What software packages are supported for deployment?

a)

It supports deployments of single HotFixes (HF), and of Major Versions. Blink Packages and HotFix Accumulators (Jumbo) are not supported.

b)

It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), and of Major Versions.

c)

It supports deployments of Major Versions and Blink packages only.

d)

It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), but not of Major Versions.

10.

When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?

a)

The URL and server certificate are sent to the Check Point Online Web Service

b)

The full URL, including page data, is sent to the Check Point Online Web Service

c)

The host part of the URL is sent to the Check Point Online Web Service

d)

The URL and IP address are sent to the Check Point Online Web Service

11.

Application Control/URL filtering database library is known as:

a)

AppWiki

b)

Application-Forensic Database

c)

Application Library

d)

Application database

12.

Which deployment adds a Security Gateway to an existing environment without changing IP routing?

a)

Remote

b)

Standalone

c)

Distributed

d)

Bridge Mode

13.

Name the pre-defined Roles included in Gaia OS.

a)

AdminRole, and MonitorRole

b)

ReadWriteRole, and ReadyOnly Role

c)

AdminRole, cloningAdminRole, and Monitor Role

d)

AdminRole

14.

Gaia has two default user accounts that cannot be deleted. What are those user accounts?

a)

Admin and Default

b)

Expert and Clish

c)

Control and Monitor

d)

Admin and Monitor

15.

Name the authentication method that requires token authenticator.

a)

SecurID

b)

Radius

c)

DynamicID

d)

TACACS

16.

Which single Security Blade can be turned on to block both malicious files from being downloaded as well as block websites known to host malware?

a)

Anti-Bot

b)

None - both Anti-Virus and Anti-Bot are required for this

c)

Anti-Virus

d)

None - both URL Filtering and Anti-Virus are required for this.

17.

Log query results can be exported to what file format?

a)

Word Document (docx)

b)

Comma Separated Value (csv)

c)

Portable Document Format (pdf)

d)

Text (txt)

18.

There are four policy types available for each policy package. What are those policy types?

a)

Access Control, Threat Prevention, Mobile Access and HTTPS Inspection

b)

Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection

c)

There are only three policy types: Access Control, Threat Prevention and NAT.

d)

Access Control, Threat Prevention, NAT and HTTPS Inspection

19.

Which tool allows for the automatic updating of the Gaia OS and Check Point products installed on the Gaia OS?

a)

CPASE - Check Point Automatic Service Engine

b)

CPAUE - Check Point Automatic Update Engine

c)

CPDAS - Check Point Deployment Agent Service

d)

CPUSE - Check Point Upgrade Service Engine

20.

The purpose of the Communication Initialization process is to establish a trust between the Security Management Server and the Check Point gateways. Which statement best describes this Secure Internal Communication (SIC)?

a)

After successful initialization, the gateway can communicate with any Check Point node that possesses a SIC certificate signed by the same ICA.

b)

Secure Internal Communications authenticates the security gateway to the SMS before http communications are allowed.

c)

A SIC certificate is automatically generated on the gateway because the gateway hosts a subordinate CA to the SMS ICA.

d)

New firewalls can easily establish the trust by using the expert password defined on the SMS and the SMS IP address.

21.

Fill in the blank: SmartConsole, SmartEvent GUI client, and ___________ allow viewing of billions of consolidated logs and shows them as prioritized security events.

a)

SmartView Web Application

b)

SmartTracker

c)

SmartMonitor

d)

SmartReporter

22.

What kind of NAT enables Source Port Address Translation by default?

a)

Automatic Static NAT

b)

Manual Hide NAT

c)

Automatic Hide NAT

d)

Manual Static NAT

23.

Application Control/URL filtering database library is known as:

a)

Application database

b)

AppWiki

c)

Application-Forensic Database

d)

Application Library

24.

What are the types of Software Containers?

a)

Smart Console, Security Management, and Security Gateway

b)

Security Management, Security Gateway, and Endpoint Security

c)

Security Management, Log & Monitoring, and Security Policy

d)

Security Management, Standalone, and Security Gateway

25.

Stateful Inspection compiles and registers connections where?

a)

Connection Cache

b)

State Cache

c)

State Table

d)

Network Table

26.

Security Zones do no work with what type of defined rule?

a)

Application Control rule

b)

Manual NAT rule

c)

IPS bypass rule

d)

Firewall rule

27.

Most Check Point deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?

a)

Enterprise Network Security Appliances

b)

Rugged Appliances

c)

Scalable Platforms

d)

Small Business and Branch Office Appliances

28.

Which of the following is NOT a valid deployment option?

a)

All-in-one (stand-alone)

b)

CloudGuard

c)

Bridge Mode

d)

Distributed

29.

Which of the following is NOT a method used by Identity Awareness for acquiring identity?

a)

Remote Access

b)

Cloud IdP (Identity Provider)

c)

Active Directory Query

d)

RADIUS

30.

What Check Point tool is used to automatically update Check Point products for the Gaia OS?

a)

Check Point Update Engine

b)

Check Point Upgrade Service Engine (CPUSE)

c)

Check Point Upgrade Installation Service

d)

Check Point INSPECT Engine

31.

What are the advantages of a "shared policy"?

a)

Allows the administrator to share a policy between all the users identified by the Security Gateway.

b)

Allows the administrator to share a policy so that it is available to use in another Policy Package.

c)

Allows the administrator to share a policy between all the administrators managing the Security Management Server.

d)

Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway.

32.

URL Filtering cannot be used to:

a)

Control Bandwidth issues

b)

Control Data Security

c)

Improve organizational security

d)

Decrease legal liability

33.

Which SmartConsole application shows correlated logs and aggregated data to provide an overview of potential threats and attack patterns?

a)

SmartEvent

b)

SmartView Tracker

c)

SmartLog

d)

SmartView Monitor

34.

Which of the following is used to extract state related information from packets and store that information in state tables?

a)

STATE Engine

b)

TRACK Engine

c)

RECORD Engine

d)

INSPECT Engine

35.

Which part of SmartConsole allows administrators to add, edit delete, and clone objects?

a)

Object Browser

b)

Object Editor

c)

Object Navigator

d)

Object Explorer

36.

For Automatic Hide NAT rules created by the administrator what is a TRUE statement?

a)

Source Port Address Translation (PAT) is enabled by default.

b)

Automatic NAT rules are supported for Network objects only.

c)

Automatic NAT rules are supported for Host objects only.

d)

Source Port Address Translation (PAT) is disabled by default.

37.

Which of the following is true about Stateful Inspection?

a)

Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.

b)

Stateful Inspection looks at both the headers of packets, as well as deeply examining their content.

c)

Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.

d)

Stateful Inspection requires that a server reply to a request, in order to track a connection's state

38.

What is the user ID of a user that have all the privileges of a root user?

a)

User ID 1

b)

User ID 2

c)

User ID 0

d)

User ID 99

39.

What are the two elements of address translation rules?

a)

Original packet and translated packet

b)

Manipulated packet and original packet

c)

Translated packet and untranslated packet

d)

Untranslated packet and manipulated packet

40.

Fill in the blanks: A _______ license requires an administrator to designate a gateway for attachment whereas a _______ license is automatically attached to a Security Gateway.

a)

Formal; corporate

b)

Local; central

c)

Local; formal

d)

Central; local

41.

RADIUS protocol uses _________ to communicate with the gateway.

a)

UDP

b)

CCP

c)

TCP

d)

HTTP

42.

Which software blade enables Access Control policies to accept, drop, or limit web site access based on user, group, and/or machine?

a)

Application Control

b)

Threat Emulation

c)

Data Awareness

d)

Identity Awareness

43.

Which one of the following is TRUE?

a)

One policy can be either inline or ordered, but not both.

b)

Inline layer can be defined as a rule action.

c)

Ordered policy is a sub-policy within another policy.

d)

Pre-R80 Gateways do not support ordered layers.

44.

You have discovered suspicious activity in your network. What is the BEST immediate action to take?

a)

Contact your ISP to request them to block the traffic.

b)

Wait until traffic has been identified before making any changes.

c)

Create a new policy rule to block the traffic.

d)

Create a Suspicious Activity Monitoring (SAM) rule to block that traffic.

45.

Which of the following is NOT an identity source used for Identity Awareness?

a)

Remote Access

b)

UserCheck

c)

RADIUS

d)

AD Query

46.

Which statement describes what Identity Sharing is in Identity Awareness?

a)

Users can share identities with other users

b)

Management servers can acquire and share identities with Security Gateways

c)

Administrators can share identities with other administrators

d)

Security Gateways can acquire and share identities with other Security Gateways

47.

What is the order of NAT priorities?

a)

IP pool NAT, static NAT, hide NAT

b)

Static NAT, hide NAT, IP pool NAT

c)

Static NAT, IP pool NAT, hide NAT

d)

Static NAT, automatic NAT, hide NAT

48.

Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?

a)

Threat Emulation

b)

Anti-Malware

c)

Anti-Virus

d)

Threat Extraction

49.

What are the three essential components of the Check Point Security Management Architecture?

a)

WebUI, SmartConsole, Security Gateway

b)

SmartConsole, Security Management Server, Security Gateway

c)

SmartConsole, SmartUpdate, Security Gateway

d)

Security Management Server, Security Gateway, Command Line Interface

50.

A layer can support different combinations of blades. What are the supported blades:

a)

Firewall, URLF, Content Awareness and Mobile Access

b)

Firewall (Network Access Control), Application & URL Filtering, Content Awareness and Mobile Access

c)

Firewall, NAT, Content Awareness and Mobile Access

d)

Firewall (Network Access Control), Application & URL Filtering and Content Awareness

51.

Which option in tracking allows you to see the amount of data passed in the connection?

a)

Data

b)

Accounting

c)

Logs

d)

Advanced

52.

If there are two administrators logged in at the same time to the SmartConsole, and there are objects locked for editing, what must be done to make them available to other administrators? (Choose the BEST answer.)

a)

Save and install the Policy.

b)

Delete older versions of database.

c)

Revert the session.

d)

Publish or discard the session.

53.

Which of the following is NOT an alert option?

a)

User defined alert

b)

Mail

c)

SNMP

d)

High alert

54.

Which Identity Source(s) should be selected in Identity Awareness for when there is a requirement for a higher level of security for sensitive servers?

a)

RADIUS and Account Logon

b)

AD Query

c)

Endpoint Identity Agent and Browser-Based Authentication

d)

Terminal Servers Endpoint Identity Agent

55.

Which Check Point software blade provides protection from zero-day and undiscovered threats?

a)

Threat Emulation

b)

Firewall

c)

Application Control

d)

Threat Extraction

56.

Which options are given on features, when editing a Role on Gaia Platform?

a)

Read/Write, None

b)

Read/Write, Read Only, None

c)

Read/Write, Read Only

d)

Read Only, None

57.

AdminA and AdminB are both logged in on SmartConsole. What does it mean if AdminB sees a lock icon on a rule? (Choose the BEST answer.)

a)

Rule is locked by AdminA and will be made available if the session is published.

b)

Rule is locked by AdminA because the rule is currently being edited.

c)

Rule is locked by AdminA and if the session is saved, the rule will be made available.

d)

Rule is locked by AdminA because the save button has not been pressed.

58.

Fill in the blanks: A Security Policy is created in _____, stored in the _____, and Distributed to the various _______.

a)

Rule base, Security Management Server, Security Gateways

b)

The Check Point database, SmartConsole, Security Gateways

c)

SmartConsole, Security Gateway, Security Management Servers

d)

SmartConsole, Security Management Server, Security Gateways

59.

What is NOT an advantage of Stateful Inspection?

a)

Good Security

b)

Transparency

c)

No Screening above Network Layer

d)

High Performance

60.

Fill in the blank: Once a license is activated, a ______ should be installed.

a)

Security Gateway Contract file

b)

Service Contract file

c)

License Management file

d)

License Contract file

61.

Where is the “Hit Count” feature enabled or disabled in SmartConsole?

a)

On the Policy layer.

b)

On each Security Gateway

c)

In Global Properties

d)

On the Policy Package

62.

Fill in the blank: The ______ is used to obtain identification and security information about network users.

a)

User index

b)

UserCheck

c)

User Directory

d)

User server

63.

When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored?

a)

SmartConsole installed device

b)

Check Point user center

c)

Security Management Server

d)

Security Gateway

64.

True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway.

a)

False, Central Licenses are handled via Security Management Server

b)

True, CLI is the preferred method for Licensing

c)

False, Central Licenses are installed via Gaia on Security Gateways

d)

True, Central Licenses can be installed with CPLIC command on a Security Gateway

65.

Fill in the blanks: A Check Point software license consists of a _______ and _______.

a)

Software blade; software container

b)

Software package; signature

c)

Signature; software blade

d)

Software container; software package

66.

SmartConsole provides a consolidated solution for everything that is necessary for the security of an organization, such as the following:

a)

Security Policy Management and Log Analysis.

b)

Security Policy Management, Log Analysis, System Health Monitoring, Multi-Domain Security Management.

c)

Security Policy Management, Log Analysis and System Health Monitoring.

d)

Security Policy Management, Threat Prevention rules, System Health Monitoring and Multi-Domain Security Management.

67.

Which of the following is NOT a tracking log option in R80.x?

a)

Full Log

b)

Detailed Log

c)

Log

d)

Extended Log

68.

Where can alerts be viewed?

a)

Alerts can be seen in SmartView Monitor

b)

Alerts can be seen in the Threat Prevention policy

c)

Alerts can be seen in SmartUpdate

d)

Alert can be seen from the CLI of the gateway

69.

Which of the following is NOT a valid application navigation tab in SmartConsole?

a)

Manage and Command Line

b)

Logs and Monitor

c)

Gateway and Servers

d)

Security Policies

70.

Fill in the blank: An identity server uses a _________ to trust a Terminal Server Identity Agent.

a)

One-time password

b)

Shared secret

c)

Certificate

d)

Token

71.

John is the administrator of a Security Management server managing a Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators before installing a policy, what should John do?

a)

File > Save

b)

Install database.

c)

Logout of the session.

d)

Publish the session.

72.

What technologies are used to deny or permit network traffic?

a)

Stateful Inspection, Firewall Blade, and URL/Application Blade

b)

Packet Filtering, Stateful Inspection, and Application Layer Firewall

c)

Firewall Blade, URL/Application Blade, and IPS

d)

Stateful Inspection, URL/Application Blade, and Threat Prevention

73.

When connected to the Check Point Management Server using the SmartConsole the first administrator to connect has a lock on:

a)

only the objects being modified in his session of the Management Database and other administrators can connect to make changes using different sessions.

b)

the entire Management Database and other administrators can connect to make changes only if the first administrator switches to Read-only.

c)

the entire Management Database and all sessions and other administrators can connect only as Read-only.

d)

only the objects being modified in the Management Database and other administrators can connect to make changes using a special session as long as they all connect from the same LAN network.

74.

Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?

a)

Windows Management Instrumentation (WMI)

b)

Hypertext Transfer Protocol Secure (HTTPS)

c)

Lightweight Directory Access Protocol (LDAP)

d)

Remote Desktop Protocol (RDP)

75.

Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, where Bob and Joe are both logged in:

a)

Since they both are logged in on different interfaces, they will both be able to make changes.

b)

When Joe logs in, Bob will be logged out automatically.

c)

The database will be locked by Bob and Joe will not be able to make any changes.

d)

Bob will receive a prompt that Joe has logged in.

76.

If there is an Accept Implied Policy set to “First", what is the reason Jorge cannot see any logs?

a)

Log Implied Rule was not set correctly on the track column on the rules base.

b)

Track log column is set to Log instead of Full Log.

c)

Track log column is set to none.

d)

Log Implied Rule was not selected on Global Properties.

77.

Which Threat Prevention Software Blade provides comprehensive protection against malicious and unwanted network traffic, focusing on application and server vulnerabilities?

a)

IPS

b)

Anti-Virus

c)

Anti-Spam

d)

Anti-bot

78.

What is the purpose of a Stealth Rule?

a)

A rule that allows administrators to access SmartConsole from any device.

b)

To drop any traffic destined for the firewall that is not otherwise explicitly allowed.

c)

A rule at the end of your policy to drop any traffic that is not explicitly allowed.

d)

A rule used to hide a server's IP address from the outside world.

79.

Which one of the following is the preferred licensing model? (Choose the best answer.)

a)

Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.

b)

Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway.

c)

Central licensing because it ties the package license to the MAC-address of the Security Management Server’s Mgmt-interface and has no dependency on the gateway.

d)

Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency.

80.

Fill in the blanks: Default port numbers for an LDAP server is____ for standard connections and____ SSL connections.

a)

636; 8080

b)

290; 3389

c)

389; 636

d)

443, 389

81.

Identity Awareness allows the Security Administrator to configure network access based on which of the following?

a)

Identity of the machine, username, and certificate

b)

Network location, identity of a user, and identity of a machine

c)

Name of the application, identity of the user, and identity of the machine

d)

Browser-Based Authentication, identity of a user, and network location

82.

Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?

a)

Full Access

b)

Read Only All

c)

Super User

d)

Editor

83.

From the Gaia web interface, which of the following operations CANNOT be performed on a Security Management Server?

a)

Add a static route

b)

Verify a Security Policy

c)

Open a terminal shell

d)

View Security Management GUI Clients

84.

The SIC Status “Unknown” means:

a)

There is no connection between the gateway and Security Management Server.

b)

The Security Management Server can contact the gateway, but cannot establish SIC.

c)

The secure communication is established.

d)

There is connection between the gateway and Security Management Server but it is not trusted.

85.

Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is __________.

a)

Sent to the Security Administrator.

b)

Stored on the Certificate Revocation List.

c)

Sent to the Internal Certificate Authority.

d)

Stored on the Security Management Server.

86.

Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?

a)

Anti-Virus

b)

Threat Emulation

c)

Application Control

d)

Advanced Networking Blade

87.

Which of the following situations would not require a new license to be generated and installed?

a)

The IP address of the Security Management or Security Gateway has changed.

b)

The license is upgraded

c)

The Security Gateway is upgraded

d)

The existing license expires

88.

What does the “unknown” SIC status shown on SmartConsole mean?

a)

The management can contact the Security Gateway but cannot establish Secure Internal Communication.

b)

SIC activation key requires a reset.

c)

Administrator input the wrong SIC key.

d)

There is no connection between the Security Gateway and Security Management Server.

89.

Fill in the blank: A(n) __________ rule is created by an administrator and configured to allow or block traffic based on specified criteria.

a)

Inline

b)
  • Explicit

c)

Implicit accept

d)

Implicit drop

90.

Which information is included in the “Extended Log” tracking option, but is not included in the “Log” tracking option?

a)

file attributes

b)

application information

c)

destination port

d)

data type information

91.

What is NOT an advantage of Packet Filtering?

a)

Low Security and No Screening above Network Layer

b)

Application Independence

c)

High Performance

d)

Scalability

92.

At what point is the Internal Certificate Authority (ICA) created?

a)

During the primary Security Management Server installation process

b)

Upon creation of a certificate

c)

When an administrator decides to create one

d)

When an administrator initially logs into SmartConsole

93.

What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?

a)

Verification tool

b)

Verification licensing

c)

Automatic licensing

d)

Automatic licensing and Verification tool

94.

Which command is used to add users to or from existing roles?

a)

Add rba user roles

b)

Add rba user

c)

Add user roles

d)

Add user

95.

What are two basic rules Check Point recommends for building an effective security policy?

a)

Accept Rule and Drop Rule

b)

Cleanup Rule and Stealth Rule

c)

Explicit Rule and Implied Rule

d)

NAT Rule and Reject Rule

96.

Which of the following is NOT a type of Endpoint Identity Agent?

a)

Terminal

b)

Light

c)

Full

d)

Custom

97.

Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.

a)

Network location, the identity of a user and the active directory membership.

b)

Network location, the identity of a user and the identity of a machine.

c)

Network location, the telephone number of a user and the UID of a machine.

d)

Geographical location, the identity of a user and the identity of a machine.

98.

What is the purpose of the Stealth Rule?

a)

To make the gateway visible to the Internet.

b)

To prevent users from directly connecting to a Security Gateway.

c)

To reduce the amount of logs for performance issues.

d)

To reduce the number of rules in the database.

99.

In SmartConsole, objects are used to represent physical and virtual network components and also some logical components. These objects are divided into several categories. Which of the following is NOT an objects category?

a)

Custom Application / Site

b)

IP Address

c)

Network Object

d)

Limit

100.

While enabling the Identity Awareness blade the Identity Awareness wizard does not automatically detect the windows domain. Why does it not detect the windows domain?

a)

SmartConsole machine is not part of the domain

b)

Security Gateway is not part of the Domain

c)

Identity Awareness is not enabled on Global properties

d)

Security Management Server is not part of the domain

101.

You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?

a)

Open SmartEvent to see why they are being blocked.

b)

Open SmartMonitor and connect remotely to the wireless controller

c)

From SmartConsole, go to the Log & Monitor tab and filter for the IP address of the tablet.

d)

Open SmartUpdate and review the logs tab.

102.

Which SmartConsole tab shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?

a)

Logs Monitor

b)

Security Policies

c)

Manage Settings

d)

Gateway Servers

103.

Fill in the blank: Backup and restores can be accomplished through _________.

a)

SmartUpdate, SmartBackup. or SmartConsole

b)

WebUI, CLI, or SmartUpdate

c)

CLI, SmartUpdate, or SmartBackup

d)

SmartConsole, WebUI, or CLI

104.

Which Check Point software blade provides visibility of users, groups and machines while also providing access control through identity-based policies?

a)

Firewall

b)

Identity Awareness

c)

Application Control

d)

URL Filtering

105.

Which Check Point supported authentication scheme typically requires a user to possess a token?

a)

RADIUS

b)

Check Point password

c)

TACACS

d)

SecurID

106.

An administrator wishes to enable Identity Awareness on the Check Point firewalls. However, they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?

a)

AD Query

b)

Browser-Based Authentication

c)

Identity Agents

d)

Terminal Servers Agent

107.

Which of the completed statements is NOT true? The WebUI can be used to manage Operating System user accounts and:

a)

add users to your Gaia system.

b)

assign privileges to users.

c)

assign user rights to their home directory in the Security Management Server.

d)

edit the home directory of the user.

108.

What is the Transport layer of the TCP/IP model responsible for?

a)

It deals with all aspects of the physical components of network connectivity and connects with different network types.

b)

It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.

c)

It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.

d)

It transports packets as datagrams along different routes to reach their destination.

109.

Which Threat Tool within SmartConsole provides a list of trusted files for the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?

a)

AppWiki

b)

ThreatWiki

c)

IPS Protections

d)

Whitelist Files

110.

When a gateway requires user information for authentication, what order does it query servers for user information?

a)

First - Internal user database, then LDAP servers in order of priority, finally the generic external user profile.

b)

First the Internal user database, then generic external user profile, finally LDAP servers in order of priority.

c)

First the highest priority LDAP server, then the internal user database, then lower priority LDAP servers, finally the generic external profile.

d)

The external generic profile, then the internal user database, finally the LDAP servers in order of priority.

111.

Fill in the blank: RADIUS Accounting gets ____ data from requests generated by the accounting client.

a)

Location

b)

Payload

c)

Destination

d)

Identity

112.

In the Check Point three-tiered architecture, which of the following is NOT a function of the Security Management Server?

a)

Display policies and logs on the administrator’s workstation.

b)

Processing and sending alerts such as SNMP traps and email notifications.

c)

Verify and compile Security Policies.

d)

Store firewall logs to hard drive storage.

113.

Which of the following is an authentication method used for Identity Awareness?

a)

RSA

b)

PKI

c)

Captive Portal

d)

SSL

114.

Which software blade does NOT accompany the Threat Prevention policy?

a)

IPS

b)

Application Control and URL Filtering

c)

Threat Emulation

d)

Anti-virus

115.

Fill in the blank: In order to install a license, it must first be added to the ______.

a)

License and Contract repository

b)

Package repository

c)

Download Center Web site

d)

User Center

116.

Which Check Point Application Control feature enables application scanning and detection?

a)

CPApp

b)

AppWiki

c)

Application Library

d)

Application Dictionary

117.

Choose what BEST describes a Session.

a)

Sessions ends when policy is pushed to the Security Gateway.

b)

Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out.

c)

Sessions locks the policy package for editing.

d)

Starts when an Administrator publishes all the changes made on SmartConsole.

118.

In the Check Point Security Management Architecture, which component(s) can store logs?

a)

Security Management Server

b)

SmartConsole and Security Management Server

c)

SmartConsole

d)

Security Management Server and Security Gateway

119.

What object type would you use to grant network access to an LDAP user group?

a)

User Group

b)

SmartDirectory Group

c)

Access Role

d)

Group Template

120.

Which type of attack can a firewall NOT prevent?

a)

Buffer Overflow

b)

SYN Flood

c)

SQL Injection

d)

Network Bandwidth Saturation

121.

Which command shows the installed licenses in Expert mode?

a)

print cplic

b)

show licenses

c)

fwlic print

d)

cplic print