Font size
Worksheetsnurislamgk_checkpoint81.20
Total questions: 142
Worksheet time: 1hrs 11mins
Fill in the blanks: Gaia can be configured using _______ the ________.
Command line interface; WebUI
Gaia Interface; GaiaUI
WebUI; Gaia Interface
GaiaUI; command line interface
Which of the following is NOT a component of a Distinguished Name?
Common Name
Country
User container
Organizational Unit
In order to see real-time and historical graph views of Security Gateway statistics in SmartView Monitor, what feature needs to be enabled on the Security Gateway?
Logging & Monitoring
None - the data is available by default
Monitoring Blade
SNMP
When an encrypted packet is decrypted, where does this happen?
Security policy
Inbound chain
Outbound chain
Decryption is not supported
Which software blade enables Access Control policies to accept, drop, or limit web site access based on user, group, and/or machine?
Application Control
Data Awareness
Identity Awareness
Threat Emulation
Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility. Which statement is true?
Manual NAT can offer more flexibility than Automatic NAT
Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.
Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading
Automatic NAT can offer more flexibility than Manual NAT.
Which default Gaia user has full read/write access?
admin
superuser
monitor
altuser
What is the order of NAT priorities?
IP pool NAT, static NAT, hide NAT
Static NAT, hide NAT, IP pool NAT
Static NAT, IP pool NAT, hide NAT
Static NAT, automatic NAT, hide NAT
Fill in the blank: The _______ is used to obtain identification and security information about network users.
User index
UserCheck
User Directory
User server
Fill in the blank: Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is _______.
Sent to the Security Administrator
Stored on the Certificate Revocation List.
Sent to the Internal Certificate Authority
Stored on the Security Management Server
If there are two administrators logged in at the same time to the SmartConsole, and there are objects locked for editing, what must be done to make them available to other administrators? Choose the BEST answer.
Save and install the Policy
Delete older versions of database.
Revert the session
Publish or discard the session.
Which information is included in the "Extended Log" tracking option, but is not included in the "Log" tracking option?
destination port
file attributes
data type information
application information
What are the advantages of a "shared policy"?
Allows the administrator to share a policy between all the users identified by the Security Gateway
Allows the administrator to share a policy so that it is available to use in another Policy Package
Allows the administrator to share a policy between all the administrators managing the Security Management Server
Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway
Secure Internal Communication (SIC) is handled by what process?
CPM
HTTPS
FWD
CPD
URL Filtering cannot be used to:
Control Bandwidth issues
Control Data Security
Improve organizational security
Decrease Legal liability
Choose what BEST describes a Session.
Sessions ends when policy is pushed to the Security Gateway.
Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out.
Sessions locks the policy package for editing
Starts when an Administrator publishes all the changes made on SmartConsole.
Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.
Network location, the identity of a user and the active directory membership
Network location, the identity of a user and the identity of a machine
Network location, the telephone number of a user and the UID of a machine.
Geographical location, the identity of a user and the identity of a machine.
Fill in the blank: A(n) ______________ rule is created by an administrator and configured to allow or block traffic based on specified criteria.
Inline
Explicit
Implicit drop
Implicit accept
What Check Point tool is used to automatically update Check Point products for the Gaia OS?
Check Point Update Engine (CPUE)
Check Point Upgrade Service Engine (CPUSE)
Check Point Upgrade Installation Service
Check Point INSPECT Engine
When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?
The URL and server certificate are sent to the Check Point Online Web Service
The full URL, including page data, is sent to the Check Point Online Web Service
The host part of the URL is sent to the Check Point Online Web Service
The URL and IP address are sent to the Check Point Online Web Service
Which Check Point software blade prevents malicious files from entering a network using virus signatures and anomaly-based protections from ThreatCloud?
Firewall
Application Control
Anti-spam and Email Security
Anti-Virus
Which SmartConsole tab is used to monitor network and security performance?
Security Policies
Logs & Monitor
Manage & Settings
Gateway & Servers
You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?
Open SmartEvent to see why they are being blocked
Open SmartMonitor and connect remotely to the wireless controller
From SmartConsole, go to the Logs & Monitor tab and filter for the IP address of the tablet
Open SmartDistributor and review the logs tab
Which of the following is NOT a tracking log option in R80.x?
Full log
Detailed Log
Log
Extended Log
Which of the following is NOT an alert option?
User defined alert
SNMP
High alert
Which of the following is NOT an identity source used for Identity Awareness?
Remote Access
UserCheck
RADIUS
AD Query
Where is the "Hit Count" feature enabled or disabled in SmartConsole?
On the Policy layer
On each Security Gateway
In Global Properties
On the Policy Package
Most Check Pint deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?
Enterprise Network Security Appliances
Scalable Platforms
Rugged Appliances
Small Business and Branch Office Appliances
What object type would you use to grant network access to an LDAP user group?
User Group
SmartDirectory Group
Access Role
Group Template
When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored?
SmartConsole installed device
Check Point user center
Security Management Server
Security Gateway
In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Which of the following options can you add to each Log, Detailed Log and Extended Log?
Accounting
Suppression
Accounting/Suppression
Accounting/Extended
What is the difference between SSL VPN and IPSec VPN?
IPSec VPN does not require installation of a resident VPN client
SSL VPN requires installation of a resident VPN client
SSL VPN and IPSec VPN are the same
IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser
What is the RFC number that act as a best practice guide for NAT?
RFC 1939
RFC 1950
RFC 1918
RFC 793
From the Gaia web interface, which of the following operations CANNOT be performed on a Security Management Server?
Verify a Security Policy
Open a terminal shell
Add a static route
View Security Management GUI Clients
Which Identity Source(s) should be selected in Identity Awareness for when there is a requirement for a higher level of security for sensitive servers?
AD Query
Terminal Servers Endpoint Identity Agent
Endpoint Identity Agent and Browser-Based Authentication
RADIUS and Account Logon
What is the Transport layer of the TCP/IP model responsible for?
. It transports packets as datagrams along different routes to reach their destination.
It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.
It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.
It deals with all aspects of the physical components of network connectivity and connects with different network types.
Is it possible to have more than one administrator connected to a Security Management Server at once?
Yes, but only if all connected administrators connect with read-only permissions.
Yes, but objects edited by one administrator will be locked for editing by others until the session is published.
No, only one administrator at a time can connect to a Security Management Server
Yes, but only one of those administrators will have write-permissions. All others will have read-only permission.
What are the types of Software Containers?
Smart Console, Security Management, and Security Gateway
Security Management, Security Gateway, and Endpoint Security
Security Management, Log & Monitoring, and Security Policy
Security Management, Standalone, and Security Gateway
If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed:
Rename the hostname of the Standby member to match exactly the hostname of the Active member.
Change the Standby Security Management Server to Active
Change the Active Security Management Server to Standby.
Manually synchronize the Active and Standby Security Management Servers.
What is the BEST method to deploy Identity Awareness for roaming users?
Use Office Mode
Use identity agents
Share user identities between gateways
Use captive portal
Which of the following actions do NOT take place in IKE Phase 1?
Peers agree on encryption method
Diffie-Hellman key is combined with the key material to produce the symmetrical IPsec key.
Peers agree on integrity method
Each side generates a session key from its private key and peer's public key.
Which R77 GUI would you use to see number of packets accepted since the last policy install?
SmartView Monitor
SmartView Tracker
SmartDashboard
SmartView Status
Which of the following is a valid deployment option?
CloudSec deployment
Disliked deployment
Router only deployment
Standalone deployment
Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?
Read Only All
Full Access
Editor
Super User
Which type of Check Point license ties the package license to the IP address of the Security Management Server?
Central
Corporate
Local
Formal
Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? Choose the BEST answer.
Anti-Malware
Content Awareness
Anti-Virus
IPS
Which one of the following is TRUE?
One policy can be either inline or ordered, but not both.
Inline layer can be defined as a rule action
Ordered policy is a sub-policy within another policy
Pre-R80 Gateways do not support ordered layers.
Fill in the blanks: A Check Point software license consists of a _____ and _____.
Software container; software package
Software package; signature
Signature; software blade
Software blade; software container
Which of the following is used to initially create trust between a Gateway and Security Management Server?
One-time Password
Token
Certificate
Internal Certificate Authority
What are the two elements of address translation rules?
Original packet and translated packet
Manipulated packet and original packet
Untranslated packet and manipulated packet
Translated packet and untranslated packet
Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?
192.168.1.1 AND 172.26.1.1 AND drop
src:192.168.1.1 AND dst:172.26.1.1 AND action:Drop
192.168.1.1 OR 172.26.1.1 AND action:Drop
src:192.168.1.1 OR dst:172.26.1.1 AND action:Drop
Fill in the blanks: The _____ collects logs and sends them to the _____.
Log server; Security Gateway
Security Gateways; log server
Log server; security management server
Security management server; Security Gateway
Which of the following is NOT an authentication scheme used for accounts created through SmartConsole?
RADIUS
SecurID
Check Point password
Security questions
Which of the following statements about Site-to-Site VPN Domain-based is NOT true?
Route-based- The Security Gateways will have a Virtual Tunnel Interface (VTI) for each VPN Tunnel with a peer VPN Gateway. The Routing Table can have routes to forward traffic to these VTIs. Any traffic routed through a VTI is automatically identified as VPN Traffic and is passed through the VPN Tunnel associated with the VTI.
Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a service or user that can send or receive VPN traffic through a VPN Gateway
Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a host or network that can send or receive VPN traffic through a VPN Gateway.
Domain-based- VPN domains are pre-defined for all VPN Gateways. When the Security Gateway encounters traffic originating from one VPN Domain with the destination to a VPN Domain of another VPN Gateway, that traffic is identified as VPN traffic and is sent through the VPN Tunnel between the two Gateways.
What is the main objective when using Application Control?
To see what users are doing.
Ensure security and privacy of information.
To filter out specific content.
To assist the firewall blade with handling traffic.
Which icon in the WebUI indicates that read/write access is enabled?
Eyeglasses
Pencil
Padlock
Book
Which SmartConsole tab is used to monitor network and security performance?
Logs Monitor
Manage Settings
Security Policies
Gateway Servers
Check Point Update Service Engine (CPUSE), also known as Deployment Agent [DA], is an advanced and intuitive mechanism for software deployment on Gaia OS. What software packages are supported for deployment?
It supports deployments of single HotFixes (HF), and of Major Versions. Blink Packages and HotFix Accumulators (Jumbo) are not supported.
It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), and of Major Versions.
It supports deployments of Major Versions and Blink packages only
It supports deployments of single HotFixes (HF), of HotFix Accumulators (Jumbo), but not of Major Versions.
In SmartConsole, on which tab are Permissions and Administrators defined?
MANAGE & SETTINGS
SECURITY POLICIES
GATEWAYS & SERVERS
LOGS & MONITOR
Which tool allows automatic update of Gaia OS and Check Point products installed on Gaia OS?
CPDAS - Check Point Deployment Agent Service
CPUSE - Check Point Upgrade Service Engine
CPASE - Check Point Automatic Service Engine
CPAUE - Check Point Automatic Update Engine
In the Check Point three-tiered architecture, which of the following is NOT a function of the Security Management Server?
Verify and compile Security Policies.
Display policies and logs on the administrator's workstation.
Store firewall logs to hard drive storage
Manage the object database.
True or False: More than one administrator can log into the Security Management Server with SmartConsole with write permission at the same time.
True, every administrator works on a different database that is independent of the other administrators
False, only one administrator can login with write permission
True, every administrator works in a session that is independent of the other administrators
False, this feature has to be enabled in the Global Properties
What are the two deployment options available for a security gateway?
Bridge and Switch
Local and Remote
Cloud and Router
Standalone and Distributed
One of major features in SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB and AdminC are editing the same Security Policy?
AdminB sees a pencil icon next the rule that AdminB is currently editing.
AdminA, AdminB and AdminC are editing three different rules at the same time
AdminA and AdminB are editing the same rule at the same time.
AdminC sees a lock icon which indicates that the rule is locked for editing by another administrator.
Which one of the following is the preferred licensing model? Select the BEST answer
Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.
Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency
Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway
Central licensing because it ties the package license to the MAC-address of the Security Management Server's Mgmt-interface and has no dependency on the gateway.
A Check Point Software license consists of two components, the Software Blade and the Software Container. There are _____ types of Software Containers: _____.
Two; Security Management and Endpoint Security
Three; Security Management, Security Gateway, and Endpoint Security
Three; Security Gateway, Endpoint Security, and Gateway Management
Two; Endpoint Security and Security Gateway
Which type of Check Point license is tied to the IP address of a specific Security Gateway and cannot be transferred to a gateway that has a different IP address?
Formal
Central
Local
Corporate
Tom has connected to the Management Server remotely using SmartConsole and is in the process of making some Rule Base changes, when he suddenly loses connectivity. Connectivity is restored shortly afterward. What will happen to the changes already made?
Tom will have to reboot his SmartConsole computer, and access the Management cache store on that computer, which is only accessible after a reboot.
Tom will have to reboot his SmartConsole computer, clear the cache, and restore changes.
Tom's changes will have been stored on the Management when he reconnects and he will not lose any of his work.
Tom’s changes will be lost since he lost connectivity and he will have to start again
In which deployment is the security management server and Security Gateway installed on the same appliance?
Switch
Standalone
Standalone
Remote
DLP and Mobile Access Policy are examples of what type of Policy?
Shared Policies
Unified Policies
Inspection Policies
Standard Policies
What is the default shell of Gaia CLI?
Read-only
Expert
Clish
Bash
Which of the following is NOT a valid application navigation tab in SmartConsole?
WEBUI & COMMAND LINE
SECURITY POLICIES
GATEWAYS & SERVERS
LOGS & MONITOR
What are two basic rules Check Point recommends for building an effective security policy?
Accept Rule and Drop Rule
Explicit Rule and Implied Rule
Cleanup Rule and Stealth Rule
NAT Rule and Reject Rule
When dealing with policy layers, what two layer types can be utilized?
Inbound Layers and Outbound Layers
Ordered Layers and Inline Layers
Structured Layers and Overlap Layers
R81.X does not support Layers
What are the three main components of Check Point security management architecture?
Smart Console, Standalone, Security Management Server
Policy-Client, Security Management Server, Security Gateway
SmartConsole, Security Policy Server, Logs & Monitoring
SmartConsole, Security Management Server, Security Gateway
Which Check Point software blade provides protection from zero-day and undiscovered threats?
Threat Extraction
Threat Emulation
Firewall
Application Control
What are the three types of UserCheck messages?
ask, block, and notify
block, action, and warn
action, inform, and ask
inform, ask, and drop(block)
By default, which port is used to connect to the GAiA Portal?
4434
80
8080
443
Which command shows detailed information about VPN tunnels?
cat $FWDIR/conf/vpn.conf
vpn tu tlist
vpn tu
cpview
After a new Log Server is added to the environment and the SIC trust has been established with the SMS what will the gateways do?
Gateways will send new firewall logs to the new Log Server as soon as the SIC trust is set up between the SMS and the new Log Server.
Logs are not automatically forwarded to a new Log Server. SmartConsole must be used to manually configure each gateway to send its logs to the server
The firewalls will detect the new Log Server after the next policy install and redirect the new logs to the new Log Server.
The gateways can only send logs to an SMS and cannot send logs to a Log Server. Log Servers are proprietary log archive servers
Which of the following is a valid deployment option?
CloudSec deployment
Disliked deployment
Router only deployment
Standalone deployment
Using the SmartConsole, which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?
Read Only All
Full Access
Editor
Super User
Which Check Point software blade monitors Check Point devices and provides a picture of network and security performance?
Logging and Status
Monitoring
Threat Emulation
Application Contro
Which type of Check Point license ties the package license to the IP address of the Security Management Server?
Formal
Corporate
Central
Local
Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? Choose the BEST answer.
Anti-Malware
Content Awareness
Anti-Virus
IPS
Which one of the following is TRUE?
One policy can be either inline or ordered, but not both.
Inline layer can be defined as a rule action.
Ordered policy is a sub-policy within another policy
Pre-R80 Gateways do not support ordered layers.
Fill in the blanks: A Check Point software license consists of a _____ and _____.
Software container; software package
Software package; signature
Signature; software blade
Software blade; software container
Which of the following is used to initially create trust between a Gateway and Security Management Server?
One-time Password
Token
Certificate
Internal Certificate Authority
What are the two elements of address translation rules?
Original packet and translated packet
Manipulated packet and original packet
Untranslated packet and manipulated packet
Translated packet and untranslated packet
Fill in the blank: Backup and restores can be accomplished through _____.
CLI, SmartUpdate, or SmartBackup
SmartUpdate, SmartBackup, or SmartConsole
SmartConsole, WebUI, or CLI
WebUI, CLI, or SmartUpdate
What kind of NAT enables Source Port Address Translation by default?
Automatic Hide NAT
Automatic Static NAT
Manual Static NAT
Manual Hide NAT
Fill in the blanks: In _____ NAT, Only the _____ is translated.
Hide; source
Simple; source
Static; source
Hide; destination
Application Control/URL filtering database library is known as:
AppWiki
Application-Forensic Database
Application Library
Application database
Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?
Security Management Server
Security Gateway
SmartConsole
SmartManager
Which of the following technologies extracts detailed information from packets and stores that information in different tables?
Application Layer Firewall
Packet Filtering
Next-Generation Firewall
Stateful Inspection
You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?
Open SmartEvent to see why they are being blocked.
From SmartConsole, go to the Log & Monitor tab and filter for the IP address of the tablet
Open SmartMonitor and connect remotely to the wireless controller
Open SmartUpdate and review the logs tab
Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?
Gaia OS
Red Hat Enterprise Linux version 4
Centos Unix
Gaia embedded
What command from the CLI would be used to view current licensing?
cplic print
show license -s
fw ctl tab -t license -s
license view
A security zone is a group of one or more network interfaces from different centrally managed gateways. What is considered part of the zone?
Security Zones are not supported by Check Point firewalls
The firewall rule can be configured to include one or more subnets in a zone.
The zone is based on the network topology and determined according to where the interface leads to
The local directly connected subnet defined by the subnet IP and subnet mask
Which of the completed statements is NOT true? The GAiA Portal (WebUI) can be used to manage Operating System user accounts and:
assign privileges to users.
assign user rights to the directory structure on the Security Management Server.
add more users to the Gaia operating system.
change the home directory of the user.
Which encryption algorithm is the least secured?
3DES
AES-128
DES
AES-256
Fill in the blank: SmartConsole, SmartEvent GUI client, and _____ allow viewing of billions of consolidated logs and shows them as prioritized security events.
SmartMonitor
SmartReporter
SmartTracker
SmartView Web Application
What is the default tracking option of a rule?
None
Alert
Log
Tracking
Fill in the blank: Once a license is activated, a _____ should be installed
License Management file
License Contract file
Security Gateway Contract file
Service Contract file
When enabling tracking on a rule, what is the default option?
Accounting Log
Extended Log
Log
Detailed Log
Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?
The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.
Licensed Check Point products for the Gala operating system and the Gaia operating system itself.
The CPUSE engine and the Gaia operating system.
The Gaia operating system only.
Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?
Both License (.lic) and Contract (.xml) files
cp.macro
Contract file (.xml)
license File (.lie)
Fill in the blank: When LDAP is integrated with Check Point Security Management, it is then referred to as _______.
User Center
User Administration
User Directory
UserCheck
Can you use the same layer in multiple policies or rulebases?
Yes - a layer can be shared with multiple policies and rules
No - each layer must be unique
No - layers cannot be shared or reused, but an identical one can be created
Yes - but it must be copied and pasted with a different name.
Security Gateway software blades must be attached to what?
Security Gateway
Security Gateway container
Management server
Management container
Which tool allows you to monitor the top bandwidth on smart console?
Logs & Monitoring
Smart Event
Gateways & Severs Tab
SmartView Monitor
When comparing Stateful Inspection and Packet Filtering, what is a benefit that Stateful Inspection offers over Packer Filtering?
Stateful Inspection offers unlimited connections because of virtual memory usage.
Stateful Inspection offers no benefits over Packet Filtering.
Stateful Inspection does not use memory to record the protocol used by the connection.
Only one rule is required for each connection.
Which of the following is used to extract state related information from packets and store that information in state tables?
INSPECT Engine
TRACK Engine
STATE Engine
RECORD Engine
Which of the following is true about Stateful Inspection?
Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.
Stateful Inspection tracks state using two tables, one for incoming traffic and one for outgoing traffic.
Stateful Inspection requires that a server reply to a request, in order to track a connection's state
Stateful Inspection looks at both the headers of packets, as well as deeply examining their content
What technologies are used to deny or permit network traffic?
Packet Filtering, Stateful Inspection, and Application Layer Firewall
Stateful Inspection, Firewall Blade, and URL/Application Blade
Firewall Blade, URL/Application Blade, and IPS
Stateful Inspection, URL/Application Blade, and Threat Prevention
Gaia has two default user accounts that cannot be deleted. What are those user accounts?
Control and Monitor
Expert and Clish
Admin and Default
Admin and Monitor
Name the pre-defined Roles included in Gaia OS
AdminRole
AdminRole, and MonitorRole
ReadWriteRole, and ReadyOnly Role
AdminRole, cloningAdminRole, and Monitor Role
What does the "unknown" SIC status shown on SmartConsole mean?
There is no connection between the Security Gateway and Security Management Server
SIC activation key requires a reset
The management can contact the Security Gateway but cannot establish Secure Internal Communication
Administrator input the wrong SIC key
Which app is used for the central management and deployment of licenses and packages?
SmartLicense
SmartUpdate
SmartProvisioning
Deployment Agent
There are four policy types available for each policy package. What are those policy types?
Access Control, Threat Prevention, NAT and HTTPS Inspection
Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection
Access Control, Threat Prevention, Mobile Access and HTTPS Inspection
There are only three policy types: Access Control, Threat Prevention and NAT
Which part of SmartConsole allows administrators to add, edit, delete, and clone objects?
Object Explorer
Object Browser
Object Editor
Object Navigator
In order for changes made to policy to be enforced by a Security Gateway, what action must an administrator perform?
Publish changes
Install database
Save changes
Install policy
Can you use the same layer in multiple policies or rulebases?
Yes - a layer can be shared with multiple policies and rules.
Yes - but it must be copied and pasted with a different name.
No - each layer must be unique.
. No - layers cannot be shared or reused, but an identical one can be created.
What default layers are included when creating a new policy layer?
Firewall, Application Control and IPS
Firewall, Application Control and IPSec VPN
Access Control, Threat Prevention and HTTPS Inspection
Application Control, URL Filtering and Threat Prevention
URL Filtering employs a technology, which educates users on web usage policy in real time. What is the name of that technology?
URL categorization
WebCheck
UserCheck
Harmony Endpoint
Application Control/URL filtering database library is known as:
Application database
AppWiki
Application Library
Application-Forensic Database
In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?
"Inspect", "Bypass"
"Inspect", "Bypass", "Block"
"Inspect", "Bypass", "Categorize"
"Detect", "Bypass"
What is the main objective when using Application Control?
To assist the firewall blade with handling traffic
To see what users are doing
To filter out specific content
Ensure security and privacy of information
Name the authentication method that requires token authenticator
Radius
SecurelD
TACACS
DynamicID
Identity Awareness allows easy configuration for network access and auditing based on what three items?
Network location, the identity of a user and the identity of a machine
Client machine IP address
Gateway proxy IP address
Log server IP address
Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?
Hypertext Transfer Protocol Secure (HTTPS)
Lightweight Directory Access Protocol (LDAP)
Remote Desktop Protocol (RDP)
Windows Management Instrumentation (WMI)
What is the main difference between Static NAT and Hide NAT?
Static NAT allow incoming and outgoing connections. Hide NAT only allows outgoing connections.
Static NAT only allows incoming connections to protect your network
Static NAT only allows outgoing connections.
Hide NAT allows incoming and outgoing connections.
What kind of NAT enables Source Port Address Translation by default?
Manual Hide NAT
Automatic Static NAT
Automatic Hide NAT
Manual Static NAT
Both major kinds of NAT support Hide and Static NAT. One offers more flexibility. Which statement is true?
Automatic NAT can offer more flexibility than Manual NAT
Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading
Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation
Manual NAT can offer more flexibility than Automatic NAT
Which option in tracking allows you to see the amount of data passed in the connection?
Logs
Data
Accounting
Advanced
Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?
192.168.1.1 AND 172.26.1.1 AND drop
src:192.168.1.1 AND dst:172.26.1.1 AND action:Drop
src:192.168.1.1 OR dst:172.26.1.1 AND action:Drop
192.168.1.1 OR 172.26.1.1 AND action:Drop
When enabling tracking on a rule, what is the default option?
Log
Detailed Log
Extended Log
Accounting Log
The Gateway Status view in SmartConsole shows the overall status of Security Gateways and Software Blades. What does the Status Attention mean?
Cannot reach the Security Gateway
The gateway and all its Software Blades are working properly.
Cannot make SIC between the Security Management Server and the Security Gateway.
At least one Software Blade has a minor issue, but the gateway works
Name the utility that is used to block activities that appear to be suspicious
Penalty Box
Suspicious Activity Monitoring (SAM)
Drop Rule in the rulebase
Stealth rule
What are the Threat Prevention software components available on the Check Point Security Gateway?
IPS, Threat Emulation and Threat Extraction
IPS, Anti-Bot, Anti-Virus, SandBlast and Macro Extraction
IDS, Forensics, Anti-Virus, Sandboxing
IPS, Anti-Bot, Anti-Virus, Threat Emulation and Threat Extraction
Core Protections are installed as part of what Policy?
Access Control Policy
Threat Prevention Policy
Mobile Access Policy
Desktop Firewall Policy
Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?
Threat Emulation
Anti-Virus
Threat Extraction
Anti-Malware
