Font size
WorksheetsCCSA
Total questions: 121
Worksheet time: 1hrs 1mins
When enabling tracking on a rule, what is the default option?
Accounting Log
Extended Log
Log
Detailed Log
Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?
The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.
Licensed Check Point products for the Gaia operating system and the Gaia operating system itself.
The CPUSE engine and the Gaia operating system.
The Gaia operating system only.
Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?
Both License (.lic) and Contract (.xml) files
cp.macro
Contract file (.xml)
license File (.lie)
Fill in the blank: When LDAP is integrated with Check Point Security Management, it is then referred to as _______.
User Center
User Administration
User Directory
UserCheck
Can you use the same layer in multiple policies or rulebases?
Yes - a layer can be shared with multiple policies and rules.
No - each layer must be unique.
No - layers cannot be shared or reused, but an identical one can be created.
Yes - but it must be copied and pasted with a different name.
Which default Gaia user has full read/write access?
superuser
monitor
altuser
admin
Which icon in the WebUI indicates that read/write access is enabled?
Eyeglasses
Pencil
Padlock
Book
Which SmartConsole tab is used to monitor network and security performance?
Logs Monitor
Manage Settings
Security Policies
Gateway Servers
Check Point Update Service Engine (CPUSE), also known as Deployment Agent [DA], is an advanced and intuitive mechanism for software deployment on Gaia OS. What software packages are supported for deployment?
It supports deployments of single HotFixes (HF), and of Major Versions. Blink Packages and HotFix Accumulators (Jumbo) are not supported.
It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), and of Major Versions.
It supports deployments of Major Versions and Blink packages only.
It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), but not of Major Versions.
When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?
The URL and server certificate are sent to the Check Point Online Web Service
The full URL, including page data, is sent to the Check Point Online Web Service
The host part of the URL is sent to the Check Point Online Web Service
The URL and IP address are sent to the Check Point Online Web Service
Application Control/URL filtering database library is known as:
AppWiki
Application-Forensic Database
Application Library
Application database
Which deployment adds a Security Gateway to an existing environment without changing IP routing?
Remote
Standalone
Distributed
Bridge Mode
Name the pre-defined Roles included in Gaia OS.
AdminRole, and MonitorRole
ReadWriteRole, and ReadyOnly Role
AdminRole, cloningAdminRole, and Monitor Role
AdminRole
Gaia has two default user accounts that cannot be deleted. What are those user accounts?
Admin and Default
Expert and Clish
Control and Monitor
Admin and Monitor
Name the authentication method that requires token authenticator.
SecurID
Radius
DynamicID
TACACS
Which single Security Blade can be turned on to block both malicious files from being downloaded as well as block websites known to host malware?
Anti-Bot
None - both Anti-Virus and Anti-Bot are required for this
Anti-Virus
None - both URL Filtering and Anti-Virus are required for this.
Log query results can be exported to what file format?
Word Document (docx)
Comma Separated Value (csv)
Portable Document Format (pdf)
Text (txt)
There are four policy types available for each policy package. What are those policy types?
Access Control, Threat Prevention, Mobile Access and HTTPS Inspection
Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection
There are only three policy types: Access Control, Threat Prevention and NAT.
Access Control, Threat Prevention, NAT and HTTPS Inspection
Which tool allows for the automatic updating of the Gaia OS and Check Point products installed on the Gaia OS?
CPASE - Check Point Automatic Service Engine
CPAUE - Check Point Automatic Update Engine
CPDAS - Check Point Deployment Agent Service
CPUSE - Check Point Upgrade Service Engine
The purpose of the Communication Initialization process is to establish a trust between the Security Management Server and the Check Point gateways. Which statement best describes this Secure Internal Communication (SIC)?
After successful initialization, the gateway can communicate with any Check Point node that possesses a SIC certificate signed by the same ICA.
Secure Internal Communications authenticates the security gateway to the SMS before http communications are allowed.
A SIC certificate is automatically generated on the gateway because the gateway hosts a subordinate CA to the SMS ICA.
New firewalls can easily establish the trust by using the expert password defined on the SMS and the SMS IP address.
Fill in the blank: SmartConsole, SmartEvent GUI client, and ___________ allow viewing of billions of consolidated logs and shows them as prioritized security events.
SmartView Web Application
SmartTracker
SmartMonitor
SmartReporter
What kind of NAT enables Source Port Address Translation by default?
Automatic Static NAT
Manual Hide NAT
Automatic Hide NAT
Manual Static NAT
Application Control/URL filtering database library is known as:
Application database
AppWiki
Application-Forensic Database
Application Library
What are the types of Software Containers?
Smart Console, Security Management, and Security Gateway
Security Management, Security Gateway, and Endpoint Security
Security Management, Log & Monitoring, and Security Policy
Security Management, Standalone, and Security Gateway
Stateful Inspection compiles and registers connections where?
Connection Cache
State Cache
State Table
Network Table
Security Zones do no work with what type of defined rule?
Application Control rule
Manual NAT rule
IPS bypass rule
Firewall rule
Most Check Point deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?
Enterprise Network Security Appliances
Rugged Appliances
Scalable Platforms
Small Business and Branch Office Appliances
Which of the following is NOT a valid deployment option?
All-in-one (stand-alone)
CloudGuard
Bridge Mode
Distributed
Which of the following is NOT a method used by Identity Awareness for acquiring identity?
Remote Access
Cloud IdP (Identity Provider)
Active Directory Query
RADIUS
What Check Point tool is used to automatically update Check Point products for the Gaia OS?
Check Point Update Engine
Check Point Upgrade Service Engine (CPUSE)
Check Point Upgrade Installation Service
Check Point INSPECT Engine
What are the advantages of a "shared policy"?
Allows the administrator to share a policy between all the users identified by the Security Gateway.
Allows the administrator to share a policy so that it is available to use in another Policy Package.
Allows the administrator to share a policy between all the administrators managing the Security Management Server.
Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway.
URL Filtering cannot be used to:
Control Bandwidth issues
Control Data Security
Improve organizational security
Decrease legal liability
Which SmartConsole application shows correlated logs and aggregated data to provide an overview of potential threats and attack patterns?
SmartEvent
SmartView Tracker
SmartLog
SmartView Monitor
Which of the following is used to extract state related information from packets and store that information in state tables?
STATE Engine
TRACK Engine
RECORD Engine
INSPECT Engine
Which part of SmartConsole allows administrators to add, edit delete, and clone objects?
Object Browser
Object Editor
Object Navigator
Object Explorer
For Automatic Hide NAT rules created by the administrator what is a TRUE statement?
Source Port Address Translation (PAT) is enabled by default.
Automatic NAT rules are supported for Network objects only.
Automatic NAT rules are supported for Host objects only.
Source Port Address Translation (PAT) is disabled by default.
Which of the following is true about Stateful Inspection?
Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.
Stateful Inspection looks at both the headers of packets, as well as deeply examining their content.
Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.
Stateful Inspection requires that a server reply to a request, in order to track a connection's state
What is the user ID of a user that have all the privileges of a root user?
User ID 1
User ID 2
User ID 0
User ID 99
What are the two elements of address translation rules?
Original packet and translated packet
Manipulated packet and original packet
Translated packet and untranslated packet
Untranslated packet and manipulated packet
Fill in the blanks: A _______ license requires an administrator to designate a gateway for attachment whereas a _______ license is automatically attached to a Security Gateway.
Formal; corporate
Local; central
Local; formal
Central; local
RADIUS protocol uses _________ to communicate with the gateway.
UDP
CCP
TCP
HTTP
Which software blade enables Access Control policies to accept, drop, or limit web site access based on user, group, and/or machine?
Application Control
Threat Emulation
Data Awareness
Identity Awareness
Which one of the following is TRUE?
One policy can be either inline or ordered, but not both.
Inline layer can be defined as a rule action.
Ordered policy is a sub-policy within another policy.
Pre-R80 Gateways do not support ordered layers.
You have discovered suspicious activity in your network. What is the BEST immediate action to take?
Contact your ISP to request them to block the traffic.
Wait until traffic has been identified before making any changes.
Create a new policy rule to block the traffic.
Create a Suspicious Activity Monitoring (SAM) rule to block that traffic.
Which of the following is NOT an identity source used for Identity Awareness?
Remote Access
UserCheck
RADIUS
AD Query
Which statement describes what Identity Sharing is in Identity Awareness?
Users can share identities with other users
Management servers can acquire and share identities with Security Gateways
Administrators can share identities with other administrators
Security Gateways can acquire and share identities with other Security Gateways
What is the order of NAT priorities?
IP pool NAT, static NAT, hide NAT
Static NAT, hide NAT, IP pool NAT
Static NAT, IP pool NAT, hide NAT
Static NAT, automatic NAT, hide NAT
Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?
Threat Emulation
Anti-Malware
Anti-Virus
Threat Extraction
What are the three essential components of the Check Point Security Management Architecture?
WebUI, SmartConsole, Security Gateway
SmartConsole, Security Management Server, Security Gateway
SmartConsole, SmartUpdate, Security Gateway
Security Management Server, Security Gateway, Command Line Interface
A layer can support different combinations of blades. What are the supported blades:
Firewall, URLF, Content Awareness and Mobile Access
Firewall (Network Access Control), Application & URL Filtering, Content Awareness and Mobile Access
Firewall, NAT, Content Awareness and Mobile Access
Firewall (Network Access Control), Application & URL Filtering and Content Awareness
Which option in tracking allows you to see the amount of data passed in the connection?
Data
Accounting
Logs
Advanced
If there are two administrators logged in at the same time to the SmartConsole, and there are objects locked for editing, what must be done to make them available to other administrators? (Choose the BEST answer.)
Save and install the Policy.
Delete older versions of database.
Revert the session.
Publish or discard the session.
Which of the following is NOT an alert option?
User defined alert
SNMP
High alert
Which Identity Source(s) should be selected in Identity Awareness for when there is a requirement for a higher level of security for sensitive servers?
RADIUS and Account Logon
AD Query
Endpoint Identity Agent and Browser-Based Authentication
Terminal Servers Endpoint Identity Agent
Which Check Point software blade provides protection from zero-day and undiscovered threats?
Threat Emulation
Firewall
Application Control
Threat Extraction
Which options are given on features, when editing a Role on Gaia Platform?
Read/Write, None
Read/Write, Read Only, None
Read/Write, Read Only
Read Only, None
AdminA and AdminB are both logged in on SmartConsole. What does it mean if AdminB sees a lock icon on a rule? (Choose the BEST answer.)
Rule is locked by AdminA and will be made available if the session is published.
Rule is locked by AdminA because the rule is currently being edited.
Rule is locked by AdminA and if the session is saved, the rule will be made available.
Rule is locked by AdminA because the save button has not been pressed.
Fill in the blanks: A Security Policy is created in _____, stored in the _____, and Distributed to the various _______.
Rule base, Security Management Server, Security Gateways
The Check Point database, SmartConsole, Security Gateways
SmartConsole, Security Gateway, Security Management Servers
SmartConsole, Security Management Server, Security Gateways
What is NOT an advantage of Stateful Inspection?
Good Security
Transparency
No Screening above Network Layer
High Performance
Fill in the blank: Once a license is activated, a ______ should be installed.
Security Gateway Contract file
Service Contract file
License Management file
License Contract file
Where is the “Hit Count” feature enabled or disabled in SmartConsole?
On the Policy layer.
On each Security Gateway
In Global Properties
On the Policy Package
Fill in the blank: The ______ is used to obtain identification and security information about network users.
User index
UserCheck
User Directory
User server
When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored?
SmartConsole installed device
Check Point user center
Security Management Server
Security Gateway
True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway.
False, Central Licenses are handled via Security Management Server
True, CLI is the preferred method for Licensing
False, Central Licenses are installed via Gaia on Security Gateways
True, Central Licenses can be installed with CPLIC command on a Security Gateway
Fill in the blanks: A Check Point software license consists of a _______ and _______.
Software blade; software container
Software package; signature
Signature; software blade
Software container; software package
SmartConsole provides a consolidated solution for everything that is necessary for the security of an organization, such as the following:
Security Policy Management and Log Analysis.
Security Policy Management, Log Analysis, System Health Monitoring, Multi-Domain Security Management.
Security Policy Management, Log Analysis and System Health Monitoring.
Security Policy Management, Threat Prevention rules, System Health Monitoring and Multi-Domain Security Management.
Which of the following is NOT a tracking log option in R80.x?
Full Log
Detailed Log
Log
Extended Log
Where can alerts be viewed?
Alerts can be seen in SmartView Monitor
Alerts can be seen in the Threat Prevention policy
Alerts can be seen in SmartUpdate
Alert can be seen from the CLI of the gateway
Which of the following is NOT a valid application navigation tab in SmartConsole?
Manage and Command Line
Logs and Monitor
Gateway and Servers
Security Policies
Fill in the blank: An identity server uses a _________ to trust a Terminal Server Identity Agent.
One-time password
Shared secret
Certificate
Token
John is the administrator of a Security Management server managing a Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators before installing a policy, what should John do?
File > Save
Install database.
Logout of the session.
Publish the session.
What technologies are used to deny or permit network traffic?
Stateful Inspection, Firewall Blade, and URL/Application Blade
Packet Filtering, Stateful Inspection, and Application Layer Firewall
Firewall Blade, URL/Application Blade, and IPS
Stateful Inspection, URL/Application Blade, and Threat Prevention
When connected to the Check Point Management Server using the SmartConsole the first administrator to connect has a lock on:
only the objects being modified in his session of the Management Database and other administrators can connect to make changes using different sessions.
the entire Management Database and other administrators can connect to make changes only if the first administrator switches to Read-only.
the entire Management Database and all sessions and other administrators can connect only as Read-only.
only the objects being modified in the Management Database and other administrators can connect to make changes using a special session as long as they all connect from the same LAN network.
Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?
Windows Management Instrumentation (WMI)
Hypertext Transfer Protocol Secure (HTTPS)
Lightweight Directory Access Protocol (LDAP)
Remote Desktop Protocol (RDP)
Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, where Bob and Joe are both logged in:
Since they both are logged in on different interfaces, they will both be able to make changes.
When Joe logs in, Bob will be logged out automatically.
The database will be locked by Bob and Joe will not be able to make any changes.
Bob will receive a prompt that Joe has logged in.
If there is an Accept Implied Policy set to “First", what is the reason Jorge cannot see any logs?
Log Implied Rule was not set correctly on the track column on the rules base.
Track log column is set to Log instead of Full Log.
Track log column is set to none.
Log Implied Rule was not selected on Global Properties.
Which Threat Prevention Software Blade provides comprehensive protection against malicious and unwanted network traffic, focusing on application and server vulnerabilities?
IPS
Anti-Virus
Anti-Spam
Anti-bot
What is the purpose of a Stealth Rule?
A rule that allows administrators to access SmartConsole from any device.
To drop any traffic destined for the firewall that is not otherwise explicitly allowed.
A rule at the end of your policy to drop any traffic that is not explicitly allowed.
A rule used to hide a server's IP address from the outside world.
Which one of the following is the preferred licensing model? (Choose the best answer.)
Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.
Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway.
Central licensing because it ties the package license to the MAC-address of the Security Management Server’s Mgmt-interface and has no dependency on the gateway.
Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency.
Fill in the blanks: Default port numbers for an LDAP server is____ for standard connections and____ SSL connections.
636; 8080
290; 3389
389; 636
443, 389
Identity Awareness allows the Security Administrator to configure network access based on which of the following?
Identity of the machine, username, and certificate
Network location, identity of a user, and identity of a machine
Name of the application, identity of the user, and identity of the machine
Browser-Based Authentication, identity of a user, and network location
Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?
Full Access
Read Only All
Super User
Editor
From the Gaia web interface, which of the following operations CANNOT be performed on a Security Management Server?
Add a static route
Verify a Security Policy
Open a terminal shell
View Security Management GUI Clients
The SIC Status “Unknown” means:
There is no connection between the gateway and Security Management Server.
The Security Management Server can contact the gateway, but cannot establish SIC.
The secure communication is established.
There is connection between the gateway and Security Management Server but it is not trusted.
Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is __________.
Sent to the Security Administrator.
Stored on the Certificate Revocation List.
Sent to the Internal Certificate Authority.
Stored on the Security Management Server.
Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?
Anti-Virus
Threat Emulation
Application Control
Advanced Networking Blade
Which of the following situations would not require a new license to be generated and installed?
The IP address of the Security Management or Security Gateway has changed.
The license is upgraded
The Security Gateway is upgraded
The existing license expires
What does the “unknown” SIC status shown on SmartConsole mean?
The management can contact the Security Gateway but cannot establish Secure Internal Communication.
SIC activation key requires a reset.
Administrator input the wrong SIC key.
There is no connection between the Security Gateway and Security Management Server.
Fill in the blank: A(n) __________ rule is created by an administrator and configured to allow or block traffic based on specified criteria.
Inline
Explicit
Implicit accept
Implicit drop
Which information is included in the “Extended Log” tracking option, but is not included in the “Log” tracking option?
file attributes
application information
destination port
data type information
What is NOT an advantage of Packet Filtering?
Low Security and No Screening above Network Layer
Application Independence
High Performance
Scalability
At what point is the Internal Certificate Authority (ICA) created?
During the primary Security Management Server installation process
Upon creation of a certificate
When an administrator decides to create one
When an administrator initially logs into SmartConsole
What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?
Verification tool
Verification licensing
Automatic licensing
Automatic licensing and Verification tool
Which command is used to add users to or from existing roles?
Add rba user roles
Add rba user
Add user roles
Add user
What are two basic rules Check Point recommends for building an effective security policy?
Accept Rule and Drop Rule
Cleanup Rule and Stealth Rule
Explicit Rule and Implied Rule
NAT Rule and Reject Rule
Which of the following is NOT a type of Endpoint Identity Agent?
Terminal
Light
Full
Custom
Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.
Network location, the identity of a user and the active directory membership.
Network location, the identity of a user and the identity of a machine.
Network location, the telephone number of a user and the UID of a machine.
Geographical location, the identity of a user and the identity of a machine.
What is the purpose of the Stealth Rule?
To make the gateway visible to the Internet.
To prevent users from directly connecting to a Security Gateway.
To reduce the amount of logs for performance issues.
To reduce the number of rules in the database.
In SmartConsole, objects are used to represent physical and virtual network components and also some logical components. These objects are divided into several categories. Which of the following is NOT an objects category?
Custom Application / Site
IP Address
Network Object
Limit
While enabling the Identity Awareness blade the Identity Awareness wizard does not automatically detect the windows domain. Why does it not detect the windows domain?
SmartConsole machine is not part of the domain
Security Gateway is not part of the Domain
Identity Awareness is not enabled on Global properties
Security Management Server is not part of the domain
You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?
Open SmartEvent to see why they are being blocked.
Open SmartMonitor and connect remotely to the wireless controller
From SmartConsole, go to the Log & Monitor tab and filter for the IP address of the tablet.
Open SmartUpdate and review the logs tab.
Which SmartConsole tab shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?
Logs Monitor
Security Policies
Manage Settings
Gateway Servers
Fill in the blank: Backup and restores can be accomplished through _________.
SmartUpdate, SmartBackup. or SmartConsole
WebUI, CLI, or SmartUpdate
CLI, SmartUpdate, or SmartBackup
SmartConsole, WebUI, or CLI
Which Check Point software blade provides visibility of users, groups and machines while also providing access control through identity-based policies?
Firewall
Identity Awareness
Application Control
URL Filtering
Which Check Point supported authentication scheme typically requires a user to possess a token?
RADIUS
Check Point password
TACACS
SecurID
An administrator wishes to enable Identity Awareness on the Check Point firewalls. However, they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?
AD Query
Browser-Based Authentication
Identity Agents
Terminal Servers Agent
Which of the completed statements is NOT true? The WebUI can be used to manage Operating System user accounts and:
add users to your Gaia system.
assign privileges to users.
assign user rights to their home directory in the Security Management Server.
edit the home directory of the user.
What is the Transport layer of the TCP/IP model responsible for?
It deals with all aspects of the physical components of network connectivity and connects with different network types.
It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.
It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.
It transports packets as datagrams along different routes to reach their destination.
Which Threat Tool within SmartConsole provides a list of trusted files for the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?
AppWiki
ThreatWiki
IPS Protections
Whitelist Files
When a gateway requires user information for authentication, what order does it query servers for user information?
First - Internal user database, then LDAP servers in order of priority, finally the generic external user profile.
First the Internal user database, then generic external user profile, finally LDAP servers in order of priority.
First the highest priority LDAP server, then the internal user database, then lower priority LDAP servers, finally the generic external profile.
The external generic profile, then the internal user database, finally the LDAP servers in order of priority.
Fill in the blank: RADIUS Accounting gets ____ data from requests generated by the accounting client.
Location
Payload
Destination
Identity
In the Check Point three-tiered architecture, which of the following is NOT a function of the Security Management Server?
Display policies and logs on the administrator’s workstation.
Processing and sending alerts such as SNMP traps and email notifications.
Verify and compile Security Policies.
Store firewall logs to hard drive storage.
Which of the following is an authentication method used for Identity Awareness?
RSA
PKI
Captive Portal
SSL
Which software blade does NOT accompany the Threat Prevention policy?
IPS
Application Control and URL Filtering
Threat Emulation
Anti-virus
Fill in the blank: In order to install a license, it must first be added to the ______.
License and Contract repository
Package repository
Download Center Web site
User Center
Which Check Point Application Control feature enables application scanning and detection?
CPApp
AppWiki
Application Library
Application Dictionary
Choose what BEST describes a Session.
Sessions ends when policy is pushed to the Security Gateway.
Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out.
Sessions locks the policy package for editing.
Starts when an Administrator publishes all the changes made on SmartConsole.
In the Check Point Security Management Architecture, which component(s) can store logs?
Security Management Server
SmartConsole and Security Management Server
SmartConsole
Security Management Server and Security Gateway
What object type would you use to grant network access to an LDAP user group?
User Group
SmartDirectory Group
Access Role
Group Template
Which type of attack can a firewall NOT prevent?
Buffer Overflow
SYN Flood
SQL Injection
Network Bandwidth Saturation
Which command shows the installed licenses in Expert mode?
print cplic
show licenses
fwlic print
cplic print
