wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CCSA-4

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.

What is the Transport layer of the TCP/IP model responsible for?

a)

It deals with all aspects of the physical components of network connectivity and connects with different network types.

b)

It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.

c)

It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.

d)

It transports packets as datagrams along different routes to reach their destination.

2.

Which of the completed statements is NOT true? The WebUI can be used to manage Operating System user accounts and:

a)

add users to your Gaia system.

b)

assign privileges to users.

c)

assign user rights to their home directory in the Security Management Server.

d)

edit the home directory of the user.

3.

An administrator wishes to enable Identity Awareness on the Check Point firewalls. However, they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?

a)

AD Query

b)

Browser-Based Authentication

c)

Identity Agents

d)

Terminal Servers Agent

4.

Which Check Point supported authentication scheme typically requires a user to possess a token?

a)

RADIUS

b)

Check Point password

c)

TACACS

d)

SecureID

5.

Which Check Point software blade provides visibility of users, groups and machines while also providing access control through identity-based policies?

a)

Firewall

b)

Identity Awareness

c)

Application Control

d)

URL Filtering

6.

Fill in the blank: Backup and restores can be accomplished through _________.

a)

SmartUpdate, SmartBackup. or SmartConsole

b)

WebUI, CLI, or SmartUpdate

c)

CLI, SmartUpdate, or SmartBackup

d)

SmartConsole, WebUI, or CLI

7.

Which SmartConsole tab shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?

a)

Logs Monitor

b)

Security Policies

c)

Manage Settings

d)

Gateway Servers

8.

You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?

a)

Open SmartEvent to see why they are being blocked.

b)

Open SmartMonitor and connect remotely to the wireless controller

c)

From SmartConsole, go to the Log & Monitor tab and filter for the IP address of the tablet.

d)
  • Open SmartUpdate and review the logs tab.

Show Suggested Answer


9.

While enabling the Identity Awareness blade the Identity Awareness wizard does not automatically detect the windows domain. Why does it not detect the windows domain?

a)

SmartConsole machine is not part of the domain

b)

Security Gateway is not part of the Domain

c)

dentity Awareness is not enabled on Global properties

d)

Security Management Server is not part of the domain

10.

In SmartConsole, objects are used to represent physical and virtual network components and also some logical components. These objects are divided into several categories. Which of the following is NOT an objects category?

a)

Custom Application / Site

b)

IP Address

c)

Network Object

d)

Limit

11.

What is the purpose of the Stealth Rule?

a)

To make the gateway visible to the Internet.

b)

To prevent users from directly connecting to a Security Gateway.

c)

To reduce the amount of logs for performance issues.

d)

To reduce the number of rules in the database.

12.

Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.

a)

Network location, the identity of a user and the active directory membership.

b)

Network location, the identity of a user and the identity of a machine.

c)

Network location, the telephone number of a user and the UID of a machine.

d)

Geographical location, the identity of a user and the identity of a machine.

13.

From the Gaia web interface, which of the following operations CANNOT be performed on a Security Management Server?

a)

Add a static route

b)

Verify a Security Policy

c)

Open a terminal shell

d)

View Security Management GUI Clients

14.

The SIC Status “Unknown” means:

a)

There is no connection between the gateway and Security Management Server.

b)

The Security Management Server can contact the gateway, but cannot establish SIC.

c)

The secure communication is established.

d)

There is connection between the gateway and Security Management Server but it is not trusted.

15.

Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is __________.

a)

Sent to the Security Administrator.

b)

Stored on the Certificate Revocation List.

c)

Sent to the Internal Certificate Authority.

d)

Stored on the Security Management Server.

16.

Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?

a)

Anti-Virus

b)

Threat Emulation

c)

Application Control

d)

Advanced Networking Blade

17.

Which of the following situations would not require a new license to be generated and installed?

a)

The IP address of the Security Management or Security Gateway has changed.

b)

The license is upgraded

c)

The Security Gateway is upgraded

d)

The existing license expires

18.

What does the “unknown” SIC status shown on SmartConsole mean?

a)

The management can contact the Security Gateway but cannot establish Secure Internal Communication.

b)

SIC activation key requires a reset.

c)

Administrator input the wrong SIC key.

d)

There is no connection between the Security Gateway and Security Management Server.

19.

Fill in the blank: A(n) __________ rule is created by an administrator and configured to allow or block traffic based on specified criteria.

a)

Inline

b)

Explicit

c)

Implicit accept

d)

Implicit drop

20.

Which of the following is NOT a type of Endpoint Identity Agent?

a)

Terminal

b)

Light

c)

Full

d)

Custom

21.

What are two basic rules Check Point recommends for building an effective security policy?

a)

Accept Rule and Drop Rule

b)

Cleanup Rule and Stealth Rule

c)

Explicit Rule and Implied Rule

d)

NAT Rule and Reject Rule

22.

Which command is used to add users to or from existing roles?

a)

Add rba user roles

b)

Add rba user

c)

Add user roles

d)

Add user

23.

What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?

a)

Verification tool

b)

Verification licensing

c)

Automatic licensing

d)

Automatic licensing and Verification tool

24.

At what point is the Internal Certificate Authority (ICA) created?

a)

During the primary Security Management Server installation process

b)

Upon creation of a certificate

c)

When an administrator decides to create one

d)

When an administrator initially logs into SmartConsole

25.

What is NOT an advantage of Packet Filtering?

a)

Low Security and No Screening above Network Layer

b)

Application Independence

c)

High Performance

d)

Scalability

26.

Which information is included in the “Extended Log” tracking option, but is not included in the “Log” tracking option?

a)

file attributes

b)

application information

c)

destination port

d)

data type information

27.

Which default Gaia user has full read/write access?

a)

superuser

b)

monitor

c)

altuser

d)

admin

28.

Which icon in the WebUI indicates that read/write access is enabled?

a)

Eyeglasses

b)

Pencil

c)

Padlock

d)

Book

29.

Which SmartConsole tab is used to monitor network and security performance?

a)

Logs Monitor

b)

Manage Settings

c)

Security Policies

d)

Gateway Servers

30.

Check Point Update Service Engine (CPUSE), also known as Deployment Agent [DA], is an advanced and intuitive mechanism for software deployment on Gaia OS. What software packages are supported for deployment?

a)

It supports deployments of single HotFixes (HF), and of Major Versions. Blink Packages and HotFix Accumulators (Jumbo) are not supported.

b)

It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), and of Major Versions.

c)

It supports deployments of Major Versions and Blink packages only.

d)

It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), but not of Major Versions.

31.

Application Control/URL filtering database library is known as:

a)

AppWiki

b)

Application-Forensic Database

c)

Application Library

d)

Application database

32.

Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?

a)

Gaia iOS

b)

Red Hat Enterprise Linux version 4

c)

Centos Unix

d)

Gaia embedded

33.

A security zone is a group of one or more network interfaces from different centrally managed gateways. What is considered part of the zone?

a)

Security Zones are not supported by Check Point firewalls.

b)

The firewall rule can be configured to include one or more subnets in a zone.

c)

The zone is based on the network topology and determined according to where the interface leads to.

d)

The local directly connected subnet defined by the subnet IP and subnet mask.

34.

You have enabled “Extended Log” as a tracking option to a security rule. However, you are still not seeing any data type information. What is the MOST likely reason?

a)

Log Trimming is enabled.

b)

Content Awareness is not enabled.

c)

Logging has disk space issues.

d)

Identity Awareness is not enabled.

35.

Where is the "Hit Count" feature enabled or disabled in SmartConsole?

a)

In Global Properties.

b)

On each Security Gateway.

c)

On the Policy layer.

d)

On the Policy Package.