NEW
Font size
WorksheetsCCSA-4
Total questions: 35
Worksheet time: 18mins
What is the Transport layer of the TCP/IP model responsible for?
It deals with all aspects of the physical components of network connectivity and connects with different network types.
It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.
It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.
It transports packets as datagrams along different routes to reach their destination.
Which of the completed statements is NOT true? The WebUI can be used to manage Operating System user accounts and:
add users to your Gaia system.
assign privileges to users.
assign user rights to their home directory in the Security Management Server.
edit the home directory of the user.
An administrator wishes to enable Identity Awareness on the Check Point firewalls. However, they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?
AD Query
Browser-Based Authentication
Identity Agents
Terminal Servers Agent
Which Check Point supported authentication scheme typically requires a user to possess a token?
RADIUS
Check Point password
TACACS
SecureID
Which Check Point software blade provides visibility of users, groups and machines while also providing access control through identity-based policies?
Firewall
Identity Awareness
Application Control
URL Filtering
Fill in the blank: Backup and restores can be accomplished through _________.
SmartUpdate, SmartBackup. or SmartConsole
WebUI, CLI, or SmartUpdate
CLI, SmartUpdate, or SmartBackup
SmartConsole, WebUI, or CLI
Which SmartConsole tab shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?
Logs Monitor
Security Policies
Manage Settings
Gateway Servers
You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?
Open SmartEvent to see why they are being blocked.
Open SmartMonitor and connect remotely to the wireless controller
From SmartConsole, go to the Log & Monitor tab and filter for the IP address of the tablet.
Open SmartUpdate and review the logs tab.
While enabling the Identity Awareness blade the Identity Awareness wizard does not automatically detect the windows domain. Why does it not detect the windows domain?
SmartConsole machine is not part of the domain
Security Gateway is not part of the Domain
dentity Awareness is not enabled on Global properties
Security Management Server is not part of the domain
In SmartConsole, objects are used to represent physical and virtual network components and also some logical components. These objects are divided into several categories. Which of the following is NOT an objects category?
Custom Application / Site
IP Address
Network Object
Limit
What is the purpose of the Stealth Rule?
To make the gateway visible to the Internet.
To prevent users from directly connecting to a Security Gateway.
To reduce the amount of logs for performance issues.
To reduce the number of rules in the database.
Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.
Network location, the identity of a user and the active directory membership.
Network location, the identity of a user and the identity of a machine.
Network location, the telephone number of a user and the UID of a machine.
Geographical location, the identity of a user and the identity of a machine.
From the Gaia web interface, which of the following operations CANNOT be performed on a Security Management Server?
Add a static route
Verify a Security Policy
Open a terminal shell
View Security Management GUI Clients
The SIC Status “Unknown” means:
There is no connection between the gateway and Security Management Server.
The Security Management Server can contact the gateway, but cannot establish SIC.
The secure communication is established.
There is connection between the gateway and Security Management Server but it is not trusted.
Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is __________.
Sent to the Security Administrator.
Stored on the Certificate Revocation List.
Sent to the Internal Certificate Authority.
Stored on the Security Management Server.
Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?
Anti-Virus
Threat Emulation
Application Control
Advanced Networking Blade
Which of the following situations would not require a new license to be generated and installed?
The IP address of the Security Management or Security Gateway has changed.
The license is upgraded
The Security Gateway is upgraded
The existing license expires
What does the “unknown” SIC status shown on SmartConsole mean?
The management can contact the Security Gateway but cannot establish Secure Internal Communication.
SIC activation key requires a reset.
Administrator input the wrong SIC key.
There is no connection between the Security Gateway and Security Management Server.
Fill in the blank: A(n) __________ rule is created by an administrator and configured to allow or block traffic based on specified criteria.
Inline
Explicit
Implicit accept
Implicit drop
Which of the following is NOT a type of Endpoint Identity Agent?
Terminal
Light
Full
Custom
What are two basic rules Check Point recommends for building an effective security policy?
Accept Rule and Drop Rule
Cleanup Rule and Stealth Rule
Explicit Rule and Implied Rule
NAT Rule and Reject Rule
Which command is used to add users to or from existing roles?
Add rba user roles
Add rba user
Add user roles
Add user
What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?
Verification tool
Verification licensing
Automatic licensing
Automatic licensing and Verification tool
At what point is the Internal Certificate Authority (ICA) created?
During the primary Security Management Server installation process
Upon creation of a certificate
When an administrator decides to create one
When an administrator initially logs into SmartConsole
What is NOT an advantage of Packet Filtering?
Low Security and No Screening above Network Layer
Application Independence
High Performance
Scalability
Which information is included in the “Extended Log” tracking option, but is not included in the “Log” tracking option?
file attributes
application information
destination port
data type information
Which default Gaia user has full read/write access?
superuser
monitor
altuser
admin
Which icon in the WebUI indicates that read/write access is enabled?
Eyeglasses
Pencil
Padlock
Book
Which SmartConsole tab is used to monitor network and security performance?
Logs Monitor
Manage Settings
Security Policies
Gateway Servers
Check Point Update Service Engine (CPUSE), also known as Deployment Agent [DA], is an advanced and intuitive mechanism for software deployment on Gaia OS. What software packages are supported for deployment?
It supports deployments of single HotFixes (HF), and of Major Versions. Blink Packages and HotFix Accumulators (Jumbo) are not supported.
It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), and of Major Versions.
It supports deployments of Major Versions and Blink packages only.
It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), but not of Major Versions.
Application Control/URL filtering database library is known as:
AppWiki
Application-Forensic Database
Application Library
Application database
Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?
Gaia iOS
Red Hat Enterprise Linux version 4
Centos Unix
Gaia embedded
A security zone is a group of one or more network interfaces from different centrally managed gateways. What is considered part of the zone?
Security Zones are not supported by Check Point firewalls.
The firewall rule can be configured to include one or more subnets in a zone.
The zone is based on the network topology and determined according to where the interface leads to.
The local directly connected subnet defined by the subnet IP and subnet mask.
You have enabled “Extended Log” as a tracking option to a security rule. However, you are still not seeing any data type information. What is the MOST likely reason?
Log Trimming is enabled.
Content Awareness is not enabled.
Logging has disk space issues.
Identity Awareness is not enabled.
Where is the "Hit Count" feature enabled or disabled in SmartConsole?
In Global Properties.
On each Security Gateway.
On the Policy layer.
On the Policy Package.
