wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CCSA-1

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

When enabling tracking on a rule, what is the default option?

a)

Accounting Log

b)

Extended Log

c)

Log

d)

Detailed Log

2.

Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?

a)

The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.

b)

Licensed Check Point products for the Gaia operating system and the Gaia operating system itself.

c)

The CPUSE engine and the Gaia operating system.

d)

The Gaia operating system only.

3.

Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?

a)

Both License (.lic) and Contract (.xml) files

b)

cp.macro

c)

Contract file (.xml)

d)

license File (.lie)

4.

Fill in the blank: When LDAP is integrated with Check Point Security Management, it is then referred to as _______.

a)

User Center

b)

User Administration

c)

User Directory

d)

UserCheck

5.

Can you use the same layer in multiple policies or rulebases?

a)

Yes - a layer can be shared with multiple policies and rules.

b)

No - each layer must be unique.

c)

No - layers cannot be shared or reused, but an identical one can be created.

d)

Yes - but it must be copied and pasted with a different name.

6.

When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?

a)

The URL and server certificate are sent to the Check Point Online Web Service

b)

The full URL, including page data, is sent to the Check Point Online Web Service

c)

The host part of the URL is sent to the Check Point Online Web Service

d)

The URL and IP address are sent to the Check Point Online Web Service

7.

Which deployment adds a Security Gateway to an existing environment without changing IP routing?

a)

Remote

b)

Standalone

c)

Distributed

d)

Bridge Mode

8.

Name the pre-defined Roles included in Gaia OS.

a)

AdminRole, and MonitorRole

b)

ReadWriteRole, and ReadyOnly Role

c)

AdminRole, cloningAdminRole, and Monitor Role

d)

AdminRole

9.

Gaia has two default user accounts that cannot be deleted. What are those user accounts?

a)

Admin and Default

b)

Expert and Clish

c)

Control and Monitor

d)

Admin and Monitor

10.

Name the authentication method that requires token authenticator.

a)

SecurID

b)

Radius

c)

DynamicID

d)

TACACS

11.

Which single Security Blade can be turned on to block both malicious files from being downloaded as well as block websites known to host malware?

a)

Anti-Bot

b)

None - both Anti-Virus and Anti-Bot are required for this

c)

Anti-Virus

d)

None - both URL Filtering and Anti-Virus are required for this.

12.

Log query results can be exported to what file format?

a)

Word Document (docx)

b)

Comma Separated Value (csv)

c)

Portable Document Format (pdf)

d)

Text (txt)

13.

There are four policy types available for each policy package. What are those policy types?

a)

Access Control, Threat Prevention, Mobile Access and HTTPS Inspection

b)

Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection

c)

There are only three policy types: Access Control, Threat Prevention and NAT.

d)

Access Control, Threat Prevention, NAT and HTTPS Inspection

14.

Which tool allows for the automatic updating of the Gaia OS and Check Point products installed on the Gaia OS?

a)

CPASE - Check Point Automatic Service Engine

b)

CPAUE - Check Point Automatic Update Engine

c)

CPDAS - Check Point Deployment Agent Service

d)

CPUSE - Check Point Upgrade Service Engine

15.

The purpose of the Communication Initialization process is to establish a trust between the Security Management Server and the Check Point gateways. Which statement best describes this Secure Internal Communication (SIC)?

a)

After successful initialization, the gateway can communicate with any Check Point node that possesses a SIC certificate signed by the same ICA.

b)

Secure Internal Communications authenticates the security gateway to the SMS before http communications are allowed.

c)

A SIC certificate is automatically generated on the gateway because the gateway hosts a subordinate CA to the SMS ICA.

d)

New firewalls can easily establish the trust by using the expert password defined on the SMS and the SMS IP address.

16.

Fill in the blank: SmartConsole, SmartEvent GUI client, and ___________ allow viewing of billions of consolidated logs and shows them as prioritized security events.

a)

SmartView Web Application

b)

SmartTracker

c)

SmartMonitor

d)

SmartReporter

17.

What kind of NAT enables Source Port Address Translation by default?

a)

Automatic Static NAT

b)

Manual Hide NAT

c)

Automatic Hide NAT

d)

Manual Static NAT

18.

Application Control/URL filtering database library is known as:

a)

Application database

b)

AppWiki

c)

Application-Forensic Database

d)

Application Library

19.

What are the types of Software Containers?

a)

Smart Console, Security Management, and Security Gateway

b)

Security Management, Security Gateway, and Endpoint Security

c)

Security Management, Log & Monitoring, and Security Policy

d)

Security Management, Standalone, and Security Gateway

20.

Stateful Inspection compiles and registers connections where?

a)

Connection Cache

b)

State Cache

c)

State Table

d)

Network Table

21.

Security Zones do no work with what type of defined rule?

a)

Application Control rule

b)

Manual NAT rule

c)

IPS bypass rule

d)

Firewall rule

22.

Most Check Point deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?

a)

Enterprise Network Security Appliances

b)

Rugged Appliances

c)

Scalable Platforms

d)

Small Business and Branch Office Appliances

23.

Which of the following is NOT a valid deployment option?

a)

All-in-one (stand-alone)

b)

CloudGuard

c)

Bridge Mode

d)

Distributed

24.

Which of the following is NOT a method used by Identity Awareness for acquiring identity?

a)

Remote Access

b)

Cloud IdP (Identity Provider)

c)

Active Directory Query

d)

RADIUS

25.

What Check Point tool is used to automatically update Check Point products for the Gaia OS?

a)

Check Point Update Engine

b)

Check Point Upgrade Service Engine (CPUSE)

c)

Check Point Upgrade Installation Service

d)

Check Point INSPECT Engine

26.

What are the advantages of a "shared policy"?

a)

Allows the administrator to share a policy between all the users identified by the Security Gateway.

b)

Allows the administrator to share a policy so that it is available to use in another Policy Package.

c)

Allows the administrator to share a policy between all the administrators managing the Security Management Server.

d)

Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway.

27.

URL Filtering cannot be used to:

a)

Control Bandwidth issues

b)

Control Data Security

c)

Improve organizational security

d)

Decrease legal liability

28.

Which SmartConsole application shows correlated logs and aggregated data to provide an overview of potential threats and attack patterns?

a)

SmartEvent

b)

SmartView Tracker

c)

SmartLog

d)

SmartView Monitor

29.

Which of the following is used to extract state related information from packets and store that information in state tables?

a)

STATE Engine

b)

TRACK Engine

c)

RECORD Engine

d)

INSPECT Engine

30.

Which part of SmartConsole allows administrators to add, edit delete, and clone objects?

a)

Object Browser

b)

Object Editor

c)

Object Navigator

d)

Object Explorer