NEW
Font size
WorksheetsCCSA-3
Total questions: 31
Worksheet time: 16mins
SmartConsole provides a consolidated solution for everything that is necessary for the security of an organization, such as the following:
Security Policy Management and Log Analysis.
Security Policy Management, Log Analysis, System Health Monitoring, Multi-Domain Security Management.
Security Policy Management, Log Analysis and System Health Monitoring.
Security Policy Management, Threat Prevention rules, System Health Monitoring and Multi-Domain Security Management.
Which of the following is NOT a tracking log option in R80.x?
Full Log
Detailed Log
Log
Extended Log
Where can alerts be viewed?
Alerts can be seen in SmartView Monitor
Alerts can be seen in the Threat Prevention policy
Alerts can be seen in SmartUpdate
Alert can be seen from the CLI of the gateway
Which of the following is NOT a valid application navigation tab in SmartConsole?
Manage and Command Line
Logs and Monitor
Gateway and Servers
Security Policies
Fill in the blank: An identity server uses a _________ to trust a Terminal Server Identity Agent.
One-time password
Shared secret
Certificate
Token
John is the administrator of a Security Management server managing a Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators before installing a policy, what should John do?
File > Save
Install database.
Logout of the session.
Publish the session.
What technologies are used to deny or permit network traffic?
Stateful Inspection, Firewall Blade, and URL/Application Blade
Packet Filtering, Stateful Inspection, and Application Layer Firewall
Firewall Blade, URL/Application Blade, and IPS
Stateful Inspection, URL/Application Blade, and Threat Prevention
When connected to the Check Point Management Server using the SmartConsole the first administrator to connect has a lock on:
only the objects being modified in his session of the Management Database and other administrators can connect to make changes using different sessions.
the entire Management Database and other administrators can connect to make changes only if the first administrator switches to Read-only.
the entire Management Database and all sessions and other administrators can connect only as Read-only.
only the objects being modified in the Management Database and other administrators can connect to make changes using a special session as long as they all connect from the same LAN network.
Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?
Windows Management Instrumentation (WMI)
Hypertext Transfer Protocol Secure (HTTPS)
Lightweight Directory Access Protocol (LDAP)
Remote Desktop Protocol (RDP)
Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, where Bob and Joe are both logged in:
Since they both are logged in on different interfaces, they will both be able to make changes.
When Joe logs in, Bob will be logged out automatically.
The database will be locked by Bob and Joe will not be able to make any changes.
Bob will receive a prompt that Joe has logged in.
If there is an Accept Implied Policy set to “First", what is the reason Jorge cannot see any logs?
Log Implied Rule was not set correctly on the track column on the rules base.
Track log column is set to Log instead of Full Log.
Track log column is set to none.
Log Implied Rule was not selected on Global Properties.
Which Threat Prevention Software Blade provides comprehensive protection against malicious and unwanted network traffic, focusing on application and server vulnerabilities?
IPS
Anti-Virus
Anti-Spam
Anti-bot
What is the purpose of a Stealth Rule?
A rule that allows administrators to access SmartConsole from any device.
To drop any traffic destined for the firewall that is not otherwise explicitly allowed.
A rule at the end of your policy to drop any traffic that is not explicitly allowed.
A rule used to hide a server's IP address from the outside world.
Which one of the following is the preferred licensing model? (Choose the best answer.)
Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.
Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway.
Central licensing because it ties the package license to the MAC-address of the Security Management Server’s Mgmt-interface and has no dependency on the gateway.
Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency.
Fill in the blanks: Default port numbers for an LDAP server is____ for standard connections and____ SSL connections.
636; 8080
290; 3389
389; 636
443, 389
Identity Awareness allows the Security Administrator to configure network access based on which of the following?
Identity of the machine, username, and certificate
Network location, identity of a user, and identity of a machine
Name of the application, identity of the user, and identity of the machine
Browser-Based Authentication, identity of a user, and network location
Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?
Full Access
Read Only All
Super User
Editor
Which command shows the installed licenses in Expert mode?
print cplic
show licenses
fwlic print
cplic print
Which type of attack can a firewall NOT prevent?
Buffer Overflow
SYN Flood
SQL Injection
Network Bandwidth Saturation
What object type would you use to grant network access to an LDAP user group?
User Group
SmartDirectory Group
Access Role
Group Template
In the Check Point Security Management Architecture, which component(s) can store logs?
Security Management Server
SmartConsole and Security Management Server
SmartConsole
Security Management Server and Security Gateway
Choose what BEST describes a Session.
Sessions ends when policy is pushed to the Security Gateway.
Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out.
Sessions locks the policy package for editing.
Starts when an Administrator publishes all the changes made on SmartConsole.
Which Check Point Application Control feature enables application scanning and detection?
CPApp
AppWiki
Application Library
Application Dictionary
Fill in the blank: In order to install a license, it must first be added to the ______.
License and Contract repository
Package repository
Download Center Web site
User Center
Which software blade does NOT accompany the Threat Prevention policy?
IPS
Application Control and URL Filtering
Threat Emulation
Anti-virus
Which of the following is an authentication method used for Identity Awareness?
RSA
PKI
Captive Portal
SSL
In the Check Point three-tiered architecture, which of the following is NOT a function of the Security Management Server?
Display policies and logs on the administrator’s workstation.
Processing and sending alerts such as SNMP traps and email notifications.
Verify and compile Security Policies.
Store firewall logs to hard drive storage.
Fill in the blank: RADIUS Accounting gets ____ data from requests generated by the accounting client.
Location
Payload
Destination
Identity
When a gateway requires user information for authentication, what order does it query servers for user information?
First - Internal user database, then LDAP servers in order of priority, finally the generic external user profile.
First the Internal user database, then generic external user profile, finally LDAP servers in order of priority.
First the highest priority LDAP server, then the internal user database, then lower priority LDAP servers, finally the generic external profile.
The external generic profile, then the internal user database, finally the LDAP servers in order of priority.
Which Threat Tool within SmartConsole provides a list of trusted files for the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?
AppWiki
ThreatWiki
IPS Protections
Whitelist Files
In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?
"Inspect", "Bypass", "Block"
"Inspect", "Bypass", "Categorize"
"Inspect", "Bypass"
"Detect", "Bypass"
