Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CCSE-1

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

In order for changes made to policy to be enforced by a Security Gateway, what action must an administrator perform?

a)

Publish changes

b)

Save changes

c)

Install policy

d)

Install database

2.

Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?

a)

Both License (.lic) and Contract (.xml) files

b)

cp.macro

c)

Contract file (.xml)

d)

license File (.lic)

3.

Which two Identity Awareness daemons are used to support identity sharing?

a)

Policy Activation Point (PAP) and Policy Decision Point (PDP)

b)

Policy Manipulation Point (PMP) and Policy Activation Point (PAP)

c)

Policy Decision Point (PDP) and Policy Enforcement Point (PEP)

d)

Policy Enforcement Point (PEP) and Policy Manipulation Point (PMP)

4.

In which scenario will an administrator need to manually define Proxy ARP?

a)

When they configure an "Automatic Static NAT" which translates to an IP address that does not belong to one of the firewall’s interfaces.

b)

When they configure an "Automatic Hide NAT" which translates to an IP address that does not belong to one of the firewall’s interfaces.

c)

When they configure a "Manual Static NAT" which translates to an IP address that does not belong to one of the firewall’s interfaces.

d)

When they configure a "Manual Hide NAT" which translates to an IP address that belongs to one of the firewall’s interfaces.

5.

Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?

a)

Centos Linux

b)

Gaia embedded

c)

Gaia

d)

Red Hat Enterprise Linux version 5

6.

For Automatic Hide NAT rules created by the administrator what is a TRUE statement?

a)

Source Port Address Translation (PAT) is enabled by default.

b)

Automatic NAT rules are supported for Network objects only.

c)

Automatic NAT rules are supported for Host objects only.

d)

Source Port Address Translation (PAT) is disabled by default.

7.

What technologies are used to deny or permit network traffic?

a)

Stateful Inspection, Firewall Blade, and URL/Application Blade

b)

Packet Filtering, Stateful Inspection, and Application Layer Firewall

c)

Firewall Blade, URL/Application Blade, and IPS

d)

Stateful Inspection, URL/Application Blade, and Threat Prevention

8.

Identity Awareness allows easy configuration for network access and auditing based on what three items?

a)

Client machine IP address.

b)

Network location, the identity of a user and the identity of a machine.

c)

Log server IP address.

d)

Gateway proxy IP address.

9.

Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?

a)

Windows Management Instrumentation (WMI)

b)

Hypertext Transfer Protocol Secure (HTTPS)

c)

Remote Desktop Protocol (RDP)

d)

Lightweight Directory Access Protocol (LDAP)

10.

What are the types of Software Containers?

a)

Smart Console, Security Management, and Security Gateway

b)

Security Management, Security Gateway, and Endpoint Security

c)

Security Management, Log & Monitoring, and Security Policy

d)

Security Management, Standalone, and Security Gateway

11.

What are the Threat Prevention software components available on the Check Point Security Gateway?

a)

IPS, Threat Emulation and Threat Extraction

b)

IPS, Anti-Bot, Anti-Virus, SandBlast and Macro Extraction

c)

IPS, Anti-Bot, Anti-Virus, Threat Emulation and Threat Extraction

d)

IDS, Forensics, Anti-Virus, Sandboxing

12.

When using Automatic Hide NAT, what is enabled by default?

a)

Source Port Address Translation (PAT)

b)

Static NAT

c)

Static Route

d)

HTTPS Inspection

13.

In which deployment is the security management server and Security Gateway installed on the same appliance?

a)

Standalone

b)

Remote

c)

Distributed

d)

Bridge Mode

14.

What is the main objective when using Application Control?

a)

To filter out specific content.

b)

To assist the firewall blade with handling traffic.

c)

To see what users are doing.

d)

Ensure security and privacy of information.

15.

Gaia has two default user accounts that cannot be deleted. What are those user accounts?

a)

Admin and Default

b)

Expert and Clish

c)

Control and Monitor

d)

Admin and Monitor

16.

When changes are made to a Rule base, It is important to __________ to enforce changes.

a)

Publish database

b)

Activate policy

c)

Install policy

d)

Save changes

17.

Why is a Central License the preferred and recommended method of licensing?

a)

Central Licensing actually not supported with Gaia.

b)

Central Licensing is the only option when deploying Gala.

c)

Central Licensing ties to the IP address of a gateway and can be changed to any gateway if needed.

d)

Central Licensing ties to the IP address of the management server and is not dependent on the IP of any gateway in the event it changes.

18.

What does the "unknown" SIC status shown on SmartConsole mean?

a)

SIC activation key requires a reset

b)

Administrator input the wrong SIC key

c)

The management can contact the Security Gateway but cannot establish Secure Internal Communication

d)

There is no connection between the Security Gateway and Security Management Server

19.

What are valid authentication methods for mutual authenticating the VPN gateways?

a)

PKI Certificates and Kerberos Tickets

b)

PKI Certificates and DynamicID OTP

c)

Pre-Shared Secrets and Kerberos Ticket

d)

Pre-shared Secret and PKI Certificates

20.

What are the correct steps upgrading a HA cluster (M1 is active, M2 is passive) using Multi-Version Cluster(MVC)Upgrade?
1) Enable the MVC mechanism on both cluster members #cphaprob mvc on
2) Upgrade the passive node M2 to R81.10
3) In SmartConsole, change the version of the cluster object
4) Install the Access Control Policy and make sure that the installation will not stop if installation on one cluster member fails
5) After examine the cluster states upgrade node M1 to R81.10
6) On each Cluster Member, disable the MVC mechanism

a)

123456

b)

321654

c)

321456

d)

321546

21.

Which Operating Systems are supported for the Endpoint Security VPN?

a)

Windows and x86 Solaris

b)

Windows and macOS computers

c)

Windows and SPARC Solaris

d)

Windows and Red Hat Linux

22.

What are the three SecureXL Templates available in R81.10?

a)

PEP Templates, QoS Templates, VPN Templates

b)

Accept Templates, Drop Templates, NAT Templates

c)

Accept Templates, Drop Templates, Reject Templates

d)

Accept Templates, PDP Templates, PEP Templates

23.

Which Queue in the Priority Queue has the maximum priority?

a)

High Priority

b)

Control

c)

Routing

d)

Heavy Data Queue

24.

Which upgrade method you should use upgrading from R80.40 to R81.10 to avoid any downtime?

a)

Zero Downtime Upgrade (ZDU)

b)

Connectivity Upgrade (CU)

c)

Minimal Effort Upgrade (ME)

d)

Multi-Version Cluster Upgrade (MVC)

25.

The Check Point installation history feature in provides the following:

a)

View install changes and install specific version

b)

Policy Installation Date only

c)

Policy Installation Date, view install changes and install specific version

d)

View install changes

26.

What is the SOLR database for?

a)

Writes data to the database and full text search

b)

Enables powerful matching capabilities and writes data to the database

c)

Serves GUI responsible to transfer request to the DLEserver

d)

Used for full text search and enables powerful matching capabilities

27.

Which command lists firewall chain?

a)

fw ctl chain

b)

fw chain module

c)

fw tab -t chainmod

d)

fw list chain

28.

Sand Blast appliances can be deployed in the following modes:

a)

as a Mail Transfer Agent and as part of the we traffic flow only

b)

using a SPAN port to receive a copy of the traffic only

c)

detect only

d)

inline/prevent or detect

29.

Which SmartEvent component is responsible to collect the logs from different Log Servers?

a)

SmartEvent Server

b)

SmartEvent Database

c)

SmartEvent Collector

d)

SmartEvent Correlation Unit

30.

How can you switch the active log file?

a)

Run fw logswitch on the gateway

b)

Run fwm logswitch on the Management Server

c)

Run fwm logswitch on the gateway

d)

Run fw logswitch on the Management Server