wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

nurislamgk_checkpoint81.20

Total questions: 142

Worksheet time: 1hrs 11mins

Name
Class
Date
1.

Fill in the blanks: Gaia can be configured using _______ the ________.

a)

Command line interface; WebUI

b)

Gaia Interface; GaiaUI

c)

WebUI; Gaia Interface

d)

GaiaUI; command line interface

2.

Which of the following is NOT a component of a Distinguished Name?

a)

Common Name

b)

Country

c)

User container

d)

Organizational Unit

3.

In order to see real-time and historical graph views of Security Gateway statistics in SmartView Monitor, what feature needs to be enabled on the Security Gateway?

a)

Logging & Monitoring

b)

None - the data is available by default

c)

Monitoring Blade

d)

SNMP

4.

When an encrypted packet is decrypted, where does this happen?

a)

Security policy

b)

Inbound chain

c)

Outbound chain

d)

Decryption is not supported

5.

Which software blade enables Access Control policies to accept, drop, or limit web site access based on user, group, and/or machine?

a)

Application Control

b)

Data Awareness

c)

Identity Awareness

d)

Threat Emulation

6.

Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility. Which statement is true?

a)

Manual NAT can offer more flexibility than Automatic NAT

b)

Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.

c)

Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading

d)

Automatic NAT can offer more flexibility than Manual NAT.

7.

Which default Gaia user has full read/write access?

a)

admin

b)

superuser

c)

monitor

d)

altuser

8.

What is the order of NAT priorities?

a)

IP pool NAT, static NAT, hide NAT

b)

Static NAT, hide NAT, IP pool NAT

c)

Static NAT, IP pool NAT, hide NAT

d)

Static NAT, automatic NAT, hide NAT

9.

Fill in the blank: The _______ is used to obtain identification and security information about network users.

a)

User index

b)

UserCheck

c)

User Directory

d)

User server

10.

Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is _______.

a)

Sent to the Security Administrator

b)

Stored on the Certificate Revocation List.

c)

Sent to the Internal Certificate Authority

d)

Stored on the Security Management Server

11.

If there are two administrators logged in at the same time to the SmartConsole, and there are objects locked for editing, what must be done to make them available to other administrators? Choose the BEST answer.

a)

Save and install the Policy

b)

Delete older versions of database.

c)

Revert the session

d)

Publish or discard the session.

12.

Which information is included in the "Extended Log" tracking option, but is not included in the "Log" tracking option?

a)

destination port

b)

file attributes

c)

data type information

d)

application information

13.

What are the advantages of a "shared policy"?

a)

Allows the administrator to share a policy between all the users identified by the Security Gateway

b)

Allows the administrator to share a policy so that it is available to use in another Policy Package

c)

Allows the administrator to share a policy between all the administrators managing the Security Management Server

d)

Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway

14.

Secure Internal Communication (SIC) is handled by what process?

a)

CPM

b)

HTTPS

c)

FWD

d)

CPD

15.

URL Filtering cannot be used to:

a)

Control Bandwidth issues

b)

Control Data Security

c)

Improve organizational security

d)

Decrease Legal liability

16.

Choose what BEST describes a Session.

a)

Sessions ends when policy is pushed to the Security Gateway.

b)

Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out.

c)

Sessions locks the policy package for editing

d)

Starts when an Administrator publishes all the changes made on SmartConsole.

17.

Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.

a)

Network location, the identity of a user and the active directory membership

b)

Network location, the identity of a user and the identity of a machine

c)

Network location, the telephone number of a user and the UID of a machine.

d)

Geographical location, the identity of a user and the identity of a machine.

18.

Fill in the blank: A(n) ______________ rule is created by an administrator and configured to allow or block traffic based on specified criteria.

a)

Inline

b)

Explicit

c)

Implicit drop

d)

Implicit accept

19.

What Check Point tool is used to automatically update Check Point products for the Gaia OS?

a)

Check Point Update Engine (CPUE)

b)

Check Point Upgrade Service Engine (CPUSE)

c)

Check Point Upgrade Installation Service

d)

Check Point INSPECT Engine

20.

When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?

a)

The URL and server certificate are sent to the Check Point Online Web Service

b)

The full URL, including page data, is sent to the Check Point Online Web Service

c)

The host part of the URL is sent to the Check Point Online Web Service

d)

The URL and IP address are sent to the Check Point Online Web Service

21.

Which Check Point software blade prevents malicious files from entering a network using virus signatures and anomaly-based protections from ThreatCloud?

a)

Firewall

b)

Application Control

c)

Anti-spam and Email Security

d)

Anti-Virus

22.

Which SmartConsole tab is used to monitor network and security performance?

a)

Security Policies

b)

Logs & Monitor

c)

Manage & Settings

d)

Gateway & Servers

23.

You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?

a)

Open SmartEvent to see why they are being blocked

b)

Open SmartMonitor and connect remotely to the wireless controller

c)

From SmartConsole, go to the Logs & Monitor tab and filter for the IP address of the tablet

d)

Open SmartDistributor and review the logs tab

24.

Which of the following is NOT a tracking log option in R80.x?

a)

Full log

b)

Detailed Log

c)

Log

d)

Extended Log

25.

Which of the following is NOT an alert option?

a)

User defined alert

b)

Mail

c)

SNMP

d)

High alert

26.

Which of the following is NOT an identity source used for Identity Awareness?

a)

Remote Access

b)

UserCheck

c)

RADIUS

d)

AD Query

27.

Where is the "Hit Count" feature enabled or disabled in SmartConsole?

a)

On the Policy layer

b)

On each Security Gateway

c)

In Global Properties

d)

On the Policy Package

28.

Most Check Pint deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?

a)

Enterprise Network Security Appliances

b)

Scalable Platforms

c)

Rugged Appliances

d)

Small Business and Branch Office Appliances

29.

What object type would you use to grant network access to an LDAP user group?

a)

User Group

b)

SmartDirectory Group

c)

Access Role

d)

Group Template

30.

When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored?

a)

SmartConsole installed device

b)

Check Point user center

c)

Security Management Server

d)

Security Gateway

31.

In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Which of the following options can you add to each Log, Detailed Log and Extended Log?

a)

Accounting

b)

Suppression

c)

Accounting/Suppression

d)

Accounting/Extended

32.

What is the difference between SSL VPN and IPSec VPN?

a)

IPSec VPN does not require installation of a resident VPN client

b)

SSL VPN requires installation of a resident VPN client

c)

SSL VPN and IPSec VPN are the same

d)

IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser

33.

What is the RFC number that act as a best practice guide for NAT?

a)

RFC 1939

b)

RFC 1950

c)

RFC 1918

d)

RFC 793

34.

From the Gaia web interface, which of the following operations CANNOT be performed on a Security Management Server?

a)

Verify a Security Policy

b)

Open a terminal shell

c)

Add a static route

d)

View Security Management GUI Clients

35.

Which Identity Source(s) should be selected in Identity Awareness for when there is a requirement for a higher level of security for sensitive servers?

a)

AD Query

b)

Terminal Servers Endpoint Identity Agent

c)

Endpoint Identity Agent and Browser-Based Authentication

d)

RADIUS and Account Logon

36.

What is the Transport layer of the TCP/IP model responsible for?

a)

. It transports packets as datagrams along different routes to reach their destination.

b)

It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.

c)

It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.

d)

It deals with all aspects of the physical components of network connectivity and connects with different network types.

37.

Is it possible to have more than one administrator connected to a Security Management Server at once?

a)

Yes, but only if all connected administrators connect with read-only permissions.

b)

Yes, but objects edited by one administrator will be locked for editing by others until the session is published.

c)

No, only one administrator at a time can connect to a Security Management Server

d)

Yes, but only one of those administrators will have write-permissions. All others will have read-only permission.

38.

What are the types of Software Containers?

a)

Smart Console, Security Management, and Security Gateway

b)

Security Management, Security Gateway, and Endpoint Security

c)

Security Management, Log & Monitoring, and Security Policy

d)

Security Management, Standalone, and Security Gateway

39.

If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed:

a)

Rename the hostname of the Standby member to match exactly the hostname of the Active member.

b)

Change the Standby Security Management Server to Active

c)

Change the Active Security Management Server to Standby.

d)

Manually synchronize the Active and Standby Security Management Servers.

40.

What is the BEST method to deploy Identity Awareness for roaming users?

a)

Use Office Mode

b)

Use identity agents

c)

Share user identities between gateways

d)

Use captive portal

41.

Which of the following actions do NOT take place in IKE Phase 1?

a)

Peers agree on encryption method

b)

Diffie-Hellman key is combined with the key material to produce the symmetrical IPsec key.

c)

Peers agree on integrity method

d)

Each side generates a session key from its private key and peer's public key.

42.

Which R77 GUI would you use to see number of packets accepted since the last policy install?

a)

SmartView Monitor

b)

SmartView Tracker

c)

SmartDashboard

d)

SmartView Status

43.

Which of the following is a valid deployment option?

a)

CloudSec deployment

b)

Disliked deployment

c)

Router only deployment

d)

Standalone deployment

44.

Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?

a)

Read Only All

b)

Full Access

c)

Editor

d)

Super User

45.

Which type of Check Point license ties the package license to the IP address of the Security Management Server?

a)

Central

b)

Corporate

c)

Local

d)

Formal

46.

Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? Choose the BEST answer.

a)

Anti-Malware

b)

Content Awareness

c)

Anti-Virus

d)

IPS

47.

Which one of the following is TRUE?

a)

One policy can be either inline or ordered, but not both.

b)

Inline layer can be defined as a rule action

c)

Ordered policy is a sub-policy within another policy

d)

Pre-R80 Gateways do not support ordered layers.

48.

Fill in the blanks: A Check Point software license consists of a _____ and _____.

a)

Software container; software package

b)

Software package; signature

c)

Signature; software blade

d)

Software blade; software container

49.

Which of the following is used to initially create trust between a Gateway and Security Management Server?

a)

One-time Password

b)

Token

c)

Certificate

d)

Internal Certificate Authority

50.

What are the two elements of address translation rules?

a)

Original packet and translated packet

b)

Manipulated packet and original packet

c)

Untranslated packet and manipulated packet

d)

Translated packet and untranslated packet

51.

Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?

a)

192.168.1.1 AND 172.26.1.1 AND drop

b)

src:192.168.1.1 AND dst:172.26.1.1 AND action:Drop

c)

192.168.1.1 OR 172.26.1.1 AND action:Drop

d)

src:192.168.1.1 OR dst:172.26.1.1 AND action:Drop

52.

Fill in the blanks: The _____ collects logs and sends them to the _____.

a)

Log server; Security Gateway

b)

Security Gateways; log server

c)

Log server; security management server

d)

Security management server; Security Gateway

53.

Which of the following is NOT an authentication scheme used for accounts created through SmartConsole?

a)

RADIUS

b)

SecurID

c)

Check Point password

d)

Security questions

54.

Which of the following statements about Site-to-Site VPN Domain-based is NOT true?

a)

Route-based- The Security Gateways will have a Virtual Tunnel Interface (VTI) for each VPN Tunnel with a peer VPN Gateway. The Routing Table can have routes to forward traffic to these VTIs. Any traffic routed through a VTI is automatically identified as VPN Traffic and is passed through the VPN Tunnel associated with the VTI.

b)

Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a service or user that can send or receive VPN traffic through a VPN Gateway

c)

Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a host or network that can send or receive VPN traffic through a VPN Gateway.

d)

Domain-based- VPN domains are pre-defined for all VPN Gateways. When the Security Gateway encounters traffic originating from one VPN Domain with the destination to a VPN Domain of another VPN Gateway, that traffic is identified as VPN traffic and is sent through the VPN Tunnel between the two Gateways.

55.

What is the main objective when using Application Control?

a)

To see what users are doing.

b)

Ensure security and privacy of information.

c)

To filter out specific content.

d)

To assist the firewall blade with handling traffic.

56.

Which icon in the WebUI indicates that read/write access is enabled?

a)

Eyeglasses

b)

Pencil

c)

Padlock

d)

Book

57.

Which SmartConsole tab is used to monitor network and security performance?

a)

Logs Monitor

b)

Manage Settings

c)

Security Policies

d)

Gateway Servers

58.

Check Point Update Service Engine (CPUSE), also known as Deployment Agent [DA], is an advanced and intuitive mechanism for software deployment on Gaia OS. What software packages are supported for deployment?

a)

It supports deployments of single HotFixes (HF), and of Major Versions. Blink Packages and HotFix Accumulators (Jumbo) are not supported.

b)

It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), and of Major Versions.

c)

It supports deployments of Major Versions and Blink packages only

d)

It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), but not of Major Versions.

59.

In SmartConsole, on which tab are Permissions and Administrators defined?

a)

MANAGE & SETTINGS

b)

SECURITY POLICIES

c)

GATEWAYS & SERVERS

d)

LOGS & MONITOR

60.

Which tool allows automatic update of Gaia OS and Check Point products installed on Gaia OS?

a)

CPDAS - Check Point Deployment Agent Service

b)

CPUSE - Check Point Upgrade Service Engine

c)

CPASE - Check Point Automatic Service Engine

d)

CPAUE - Check Point Automatic Update Engine

61.

In the Check Point three-tiered architecture, which of the following is NOT a function of the Security Management Server?

a)

Verify and compile Security Policies.

b)

Display policies and logs on the administrator's workstation.

c)

Store firewall logs to hard drive storage

d)

Manage the object database.

62.

True or False: More than one administrator can log into the Security Management Server with SmartConsole with write permission at the same time.

a)

True, every administrator works on a different database that is independent of the other administrators

b)

False, only one administrator can login with write permission

c)

True, every administrator works in a session that is independent of the other administrators

d)

False, this feature has to be enabled in the Global Properties

63.

What are the two deployment options available for a security gateway?

a)

Bridge and Switch

b)

Local and Remote

c)

Cloud and Router

d)

Standalone and Distributed

64.

One of major features in SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB and AdminC are editing the same Security Policy?

a)

AdminB sees a pencil icon next the rule that AdminB is currently editing.

b)

AdminA, AdminB and AdminC are editing three different rules at the same time

c)

AdminA and AdminB are editing the same rule at the same time.

d)

AdminC sees a lock icon which indicates that the rule is locked for editing by another administrator.

65.

Which one of the following is the preferred licensing model? Select the BEST answer

a)

Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.

b)

Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency

c)

Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway

d)

Central licensing because it ties the package license to the MAC-address of the Security Management Server's Mgmt-interface and has no dependency on the gateway.

66.

A Check Point Software license consists of two components, the Software Blade and the Software Container. There are _____ types of Software Containers: _____.

a)

Two; Security Management and Endpoint Security

b)

Three; Security Management, Security Gateway, and Endpoint Security

c)

Three; Security Gateway, Endpoint Security, and Gateway Management

d)

Two; Endpoint Security and Security Gateway

67.

Which type of Check Point license is tied to the IP address of a specific Security Gateway and cannot be transferred to a gateway that has a different IP address?

a)

Formal

b)

Central

c)

Local

d)

Corporate

68.

Tom has connected to the Management Server remotely using SmartConsole and is in the process of making some Rule Base changes, when he suddenly loses connectivity. Connectivity is restored shortly afterward. What will happen to the changes already made?

a)

Tom will have to reboot his SmartConsole computer, and access the Management cache store on that computer, which is only accessible after a reboot.

b)

Tom will have to reboot his SmartConsole computer, clear the cache, and restore changes.

c)

Tom's changes will have been stored on the Management when he reconnects and he will not lose any of his work.

d)

Tom’s changes will be lost since he lost connectivity and he will have to start again

69.

In which deployment is the security management server and Security Gateway installed on the same appliance?

a)

Switch

b)

Standalone

c)

Standalone

d)

Remote

70.

DLP and Mobile Access Policy are examples of what type of Policy?

a)

Shared Policies

b)

Unified Policies

c)

Inspection Policies

d)

Standard Policies

71.

What is the default shell of Gaia CLI?

a)

Read-only

b)

Expert

c)

Clish

d)

Bash

72.

Which of the following is NOT a valid application navigation tab in SmartConsole?

a)

WEBUI & COMMAND LINE

b)

SECURITY POLICIES

c)

GATEWAYS & SERVERS

d)

LOGS & MONITOR

73.

What are two basic rules Check Point recommends for building an effective security policy?

a)

Accept Rule and Drop Rule

b)

Explicit Rule and Implied Rule

c)

Cleanup Rule and Stealth Rule

d)

NAT Rule and Reject Rule

74.

When dealing with policy layers, what two layer types can be utilized?

a)

Inbound Layers and Outbound Layers

b)

Ordered Layers and Inline Layers

c)

Structured Layers and Overlap Layers

d)

R81.X does not support Layers

75.

What are the three main components of Check Point security management architecture?

a)

Smart Console, Standalone, Security Management Server

b)

Policy-Client, Security Management Server, Security Gateway

c)

SmartConsole, Security Policy Server, Logs & Monitoring

d)

SmartConsole, Security Management Server, Security Gateway

76.

Which Check Point software blade provides protection from zero-day and undiscovered threats?

a)

Threat Extraction

b)

Threat Emulation

c)

Firewall

d)

Application Control

77.

What are the three types of UserCheck messages?

a)

ask, block, and notify

b)

block, action, and warn

c)

action, inform, and ask

d)

inform, ask, and drop(block)

78.

By default, which port is used to connect to the GAiA Portal?

a)

4434

b)

80

c)

8080

d)

443

79.

Which command shows detailed information about VPN tunnels?

a)

cat $FWDIR/conf/vpn.conf

b)

vpn tu tlist

c)

vpn tu

d)

cpview

80.

After a new Log Server is added to the environment and the SIC trust has been established with the SMS what will the gateways do?

a)

Gateways will send new firewall logs to the new Log Server as soon as the SIC trust is set up between the SMS and the new Log Server.

b)

Logs are not automatically forwarded to a new Log Server. SmartConsole must be used to manually configure each gateway to send its logs to the server

c)

The firewalls will detect the new Log Server after the next policy install and redirect the new logs to the new Log Server.

d)

The gateways can only send logs to an SMS and cannot send logs to a Log Server. Log Servers are proprietary log archive servers

81.

Which of the following is a valid deployment option?

a)

CloudSec deployment

b)

Disliked deployment

c)

Router only deployment

d)

Standalone deployment

82.

Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?

a)

Read Only All

b)

Full Access

c)

Editor

d)

Super User

83.

Which Check Point software blade monitors Check Point devices and provides a picture of network and security performance?

a)

Logging and Status

b)

Monitoring

c)

Threat Emulation

d)

Application Contro

84.

Which type of Check Point license ties the package license to the IP address of the Security Management Server?

a)

Formal

b)

Corporate

c)

Central

d)

Local

85.

Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? Choose the BEST answer.

a)

Anti-Malware

b)

Content Awareness

c)

Anti-Virus

d)

IPS

86.

Which one of the following is TRUE?

a)

One policy can be either inline or ordered, but not both.

b)

Inline layer can be defined as a rule action.

c)

Ordered policy is a sub-policy within another policy

d)

Pre-R80 Gateways do not support ordered layers.

87.

Fill in the blanks: A Check Point software license consists of a _____ and _____.

a)

Software container; software package

b)

Software package; signature

c)

Signature; software blade

d)

Software blade; software container

88.

Which of the following is used to initially create trust between a Gateway and Security Management Server?

a)

One-time Password

b)

Token

c)

Certificate

d)

Internal Certificate Authority

89.

What are the two elements of address translation rules?

a)

Original packet and translated packet

b)

Manipulated packet and original packet

c)

Untranslated packet and manipulated packet

d)

Translated packet and untranslated packet

90.

Fill in the blank: Backup and restores can be accomplished through _____.

a)

CLI, SmartUpdate, or SmartBackup

b)

SmartUpdate, SmartBackup, or SmartConsole

c)

SmartConsole, WebUI, or CLI

d)

WebUI, CLI, or SmartUpdate

91.

What kind of NAT enables Source Port Address Translation by default?

a)

Automatic Hide NAT

b)

Automatic Static NAT

c)

Manual Static NAT

d)

Manual Hide NAT

92.

Fill in the blanks: In _____ NAT, Only the _____ is translated.

a)

Hide; source

b)

Simple; source

c)

Static; source

d)

Hide; destination

93.

Application Control/URL filtering database library is known as:

a)

AppWiki

b)

Application-Forensic Database

c)

Application Library

d)

Application database

94.

Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?

a)

Security Management Server

b)

Security Gateway

c)

SmartConsole

d)

SmartManager

95.

Which of the following technologies extracts detailed information from packets and stores that information in different tables?

a)

Application Layer Firewall

b)

Packet Filtering

c)

Next-Generation Firewall

d)

Stateful Inspection

96.

You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?

a)

Open SmartEvent to see why they are being blocked.

b)

From SmartConsole, go to the Log & Monitor tab and filter for the IP address of the tablet

c)

Open SmartMonitor and connect remotely to the wireless controller

d)

Open SmartUpdate and review the logs tab

97.

Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?

a)

Gaia OS

b)

Red Hat Enterprise Linux version 4

c)

Centos Unix

d)

Gaia embedded

98.

What command from the CLI would be used to view current licensing?

a)

cplic print

b)

show license -s

c)

fw ctl tab -t license -s

d)

license view

99.

A security zone is a group of one or more network interfaces from different centrally managed gateways. What is considered part of the zone?

a)

Security Zones are not supported by Check Point firewalls

b)

The firewall rule can be configured to include one or more subnets in a zone.

c)

The zone is based on the network topology and determined according to where the interface leads to

d)

The local directly connected subnet defined by the subnet IP and subnet mask

100.

Which of the completed statements is NOT true? The GAiA Portal (WebUI) can be used to manage Operating System user accounts and:

a)

assign privileges to users.

b)

assign user rights to the directory structure on the Security Management Server.

c)

add more users to the Gaia operating system.

d)

change the home directory of the user.

101.

Which encryption algorithm is the least secured?

a)

3DES

b)

AES-128

c)

DES

d)

AES-256

102.

Fill in the blank: SmartConsole, SmartEvent GUI client, and _____ allow viewing of billions of consolidated logs and shows them as prioritized security events.

a)

SmartMonitor

b)

SmartReporter

c)

SmartTracker

d)

SmartView Web Application

103.

What is the default tracking option of a rule?

a)

None

b)

Alert

c)

Log

d)

Tracking

104.

Fill in the blank: Once a license is activated, a _____ should be installed

a)

License Management file

b)

License Contract file

c)

Security Gateway Contract file

d)

Service Contract file

105.

When enabling tracking on a rule, what is the default option?

a)

Accounting Log

b)

Extended Log

c)

Log

d)

Detailed Log

106.

Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?

a)

The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.

b)

Licensed Check Point products for the Gala operating system and the Gaia operating system itself.

c)

The CPUSE engine and the Gaia operating system.

d)

The Gaia operating system only.

107.

Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?

a)

Both License (.lic) and Contract (.xml) files

b)

cp.macro

c)

Contract file (.xml)

d)

license File (.lie)

108.

Fill in the blank: When LDAP is integrated with Check Point Security Management, it is then referred to as _______.

a)

User Center

b)

User Administration

c)

User Directory

d)

UserCheck

109.

Can you use the same layer in multiple policies or rulebases?

a)

Yes - a layer can be shared with multiple policies and rules

b)

No - each layer must be unique

c)

No - layers cannot be shared or reused, but an identical one can be created

d)

Yes - but it must be copied and pasted with a different name.

110.

Security Gateway software blades must be attached to what?

a)

Security Gateway

b)

Security Gateway container

c)

Management server

d)

Management container

111.

Which tool allows you to monitor the top bandwidth on smart console?

a)

Logs & Monitoring

b)

Smart Event

c)

Gateways & Severs Tab

d)

SmartView Monitor

112.

When comparing Stateful Inspection and Packet Filtering, what is a benefit that Stateful Inspection offers over Packer Filtering?

a)

Stateful Inspection offers unlimited connections because of virtual memory usage.

b)

Stateful Inspection offers no benefits over Packet Filtering.

c)

Stateful Inspection does not use memory to record the protocol used by the connection.

d)

Only one rule is required for each connection.

113.

Which of the following is used to extract state related information from packets and store that information in state tables?

a)

INSPECT Engine

b)

TRACK Engine

c)

STATE Engine

d)

RECORD Engine

114.

Which of the following is true about Stateful Inspection?

a)

Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.

b)

Stateful Inspection tracks state using two tables, one for incoming traffic and one for outgoing traffic.

c)

Stateful Inspection requires that a server reply to a request, in order to track a connection's state

d)

Stateful Inspection looks at both the headers of packets, as well as deeply examining their content

115.

What technologies are used to deny or permit network traffic?

a)

Packet Filtering, Stateful Inspection, and Application Layer Firewall

b)

Stateful Inspection, Firewall Blade, and URL/Application Blade

c)

Firewall Blade, URL/Application Blade, and IPS

d)

Stateful Inspection, URL/Application Blade, and Threat Prevention

116.

Gaia has two default user accounts that cannot be deleted. What are those user accounts?

a)

Control and Monitor

b)

Expert and Clish

c)

Admin and Default

d)

Admin and Monitor

117.

Name the pre-defined Roles included in Gaia OS

a)

AdminRole

b)

AdminRole, and MonitorRole

c)

ReadWriteRole, and ReadyOnly Role

d)

AdminRole, cloningAdminRole, and Monitor Role

118.

What does the "unknown" SIC status shown on SmartConsole mean?

a)

There is no connection between the Security Gateway and Security Management Server

b)

SIC activation key requires a reset

c)

The management can contact the Security Gateway but cannot establish Secure Internal Communication

d)

Administrator input the wrong SIC key

119.

Which app is used for the central management and deployment of licenses and packages?

a)

SmartLicense

b)

SmartUpdate

c)

SmartProvisioning

d)

Deployment Agent

120.

There are four policy types available for each policy package. What are those policy types?

a)

Access Control, Threat Prevention, NAT and HTTPS Inspection

b)

Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection

c)

Access Control, Threat Prevention, Mobile Access and HTTPS Inspection

d)

There are only three policy types: Access Control, Threat Prevention and NAT

121.

Which part of SmartConsole allows administrators to add, edit, delete, and clone objects?

a)

Object Explorer

b)

Object Browser

c)

Object Editor

d)

Object Navigator

122.

In order for changes made to policy to be enforced by a Security Gateway, what action must an administrator perform?

a)

Publish changes

b)

Install database

c)

Save changes

d)

Install policy

123.

Can you use the same layer in multiple policies or rulebases?

a)

Yes - a layer can be shared with multiple policies and rules.

b)

Yes - but it must be copied and pasted with a different name.

c)

No - each layer must be unique.

d)

. No - layers cannot be shared or reused, but an identical one can be created.

124.

What default layers are included when creating a new policy layer?

a)

Firewall, Application Control and IPS

b)

Firewall, Application Control and IPSec VPN

c)

Access Control, Threat Prevention and HTTPS Inspection

d)

Application Control, URL Filtering and Threat Prevention

125.

URL Filtering employs a technology, which educates users on web usage policy in real time. What is the name of that technology?

a)

URL categorization

b)

WebCheck

c)

UserCheck

d)

Harmony Endpoint

126.

Application Control/URL filtering database library is known as:

a)

Application database

b)

AppWiki

c)

Application Library

d)

Application-Forensic Database

127.

In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?

a)

"Inspect", "Bypass"

b)

"Inspect", "Bypass", "Block"

c)

"Inspect", "Bypass", "Categorize"

d)

"Detect", "Bypass"

128.

What is the main objective when using Application Control?

a)

To assist the firewall blade with handling traffic

b)

To see what users are doing

c)

To filter out specific content

d)

Ensure security and privacy of information

129.

Name the authentication method that requires token authenticator

a)

Radius

b)

SecurelD

c)

TACACS

d)

DynamicID

130.

Identity Awareness allows easy configuration for network access and auditing based on what three items?

a)

Network location, the identity of a user and the identity of a machine

b)

Client machine IP address

c)

Gateway proxy IP address

d)

Log server IP address

131.

Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?

a)

Hypertext Transfer Protocol Secure (HTTPS)

b)

Lightweight Directory Access Protocol (LDAP)

c)

Remote Desktop Protocol (RDP)

d)

Windows Management Instrumentation (WMI)

132.

What is the main difference between Static NAT and Hide NAT?

a)

Static NAT allow incoming and outgoing connections. Hide NAT only allows outgoing connections.

b)

Static NAT only allows incoming connections to protect your network

c)

Static NAT only allows outgoing connections.

d)

Hide NAT allows incoming and outgoing connections.

133.

What kind of NAT enables Source Port Address Translation by default?

a)

Manual Hide NAT

b)

Automatic Static NAT

c)

Automatic Hide NAT

d)

Manual Static NAT

134.

Both major kinds of NAT support Hide and Static NAT. One offers more flexibility. Which statement is true?

a)

Automatic NAT can offer more flexibility than Manual NAT

b)

Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading

c)

Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation

d)

Manual NAT can offer more flexibility than Automatic NAT

135.

Which option in tracking allows you to see the amount of data passed in the connection?

a)

Logs

b)

Data

c)

Accounting

d)

Advanced

136.

Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?

a)

192.168.1.1 AND 172.26.1.1 AND drop

b)

src:192.168.1.1 AND dst:172.26.1.1 AND action:Drop

c)

src:192.168.1.1 OR dst:172.26.1.1 AND action:Drop

d)

192.168.1.1 OR 172.26.1.1 AND action:Drop

137.

When enabling tracking on a rule, what is the default option?

a)

Log

b)

Detailed Log

c)

Extended Log

d)

Accounting Log

138.

The Gateway Status view in SmartConsole shows the overall status of Security Gateways and Software Blades. What does the Status Attention mean?

a)

Cannot reach the Security Gateway

b)

The gateway and all its Software Blades are working properly.

c)

Cannot make SIC between the Security Management Server and the Security Gateway.

d)

At least one Software Blade has a minor issue, but the gateway works

139.

Name the utility that is used to block activities that appear to be suspicious

a)

Penalty Box

b)

Suspicious Activity Monitoring (SAM)

c)

Drop Rule in the rulebase

d)

Stealth rule

140.

What are the Threat Prevention software components available on the Check Point Security Gateway?

a)

IPS, Threat Emulation and Threat Extraction

b)

IPS, Anti-Bot, Anti-Virus, SandBlast and Macro Extraction

c)

IDS, Forensics, Anti-Virus, Sandboxing

d)

IPS, Anti-Bot, Anti-Virus, Threat Emulation and Threat Extraction

141.

Core Protections are installed as part of what Policy?

a)

Access Control Policy

b)

Threat Prevention Policy

c)

Mobile Access Policy

d)

Desktop Firewall Policy

142.

Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?

a)

Threat Emulation

b)

Anti-Virus

c)

Threat Extraction

d)

Anti-Malware