NEW
Font size
WorksheetsCCSE-4
Total questions: 35
Worksheet time: 18mins
What order should be used when upgrading a Management High Availability Cluster?
Secondary Management, then Primary Management
Active Management, then Standby Management
Standby Management, then Active Management
Primary Management, then Secondary Management
You need to see which hotfixes are installed on your Check Point server, which command would you use?
cpinfo –h all
cpinfo –o hotfix
cpinfo –y all
cpinfo –I hotfix
What mechanism can ensure that the Security Gateway can communicate with the Management Server with ease in situations with overwhelmed network resources?
There is a feature for ensuring stable connectivity to the management server and is done via Priority Queuing.
The corresponding feature is new to R81.10 and is called “Management Data Plane Separation”
The corresponding feature is called “Dynamic Split”
The corresponding feature is called “Dynamic Dispatching”
Which process is used mainly for backward compatibility of gateways in R80.x and newer? It provides communication with GUI-client, database manipulation, policy compilation and Management HA synchronization.
cpm
fwd
cpd
fwm
What component of Management is used for indexing?
fwm
SOLR
API Server
DBSync
What is the responsibility of SOLR process on the management server?
Validating all data before it’s written into the database
It generates indexes of data written to the database
Communication between SmartConsole applications and the Security Management Server
Writing all information into the database
What is the difference between Updatable Objects and Dynamic Objects?
Updatable Objects is a Threat Cloud Service. The provided Objects are updated automatically. Dynamic Objects are created and maintained locally. In both cases there is no need to install policy for the changes to take effect.
Dynamic Objects are maintained automatically by the Threat Cloud. For Dynamic Objects there is no need to install policy for the changes to take effect. Updatable Objects are created and maintained locally.
Updatable Objects is a Threat Cloud Service. The provided Objects are updated automatically. Dynamic Objects are created and maintained locally. For Dynamic Objects there is no need to install policy for the changes to take effect.
Dynamic Objects are maintained automatically by the Threat Cloud. Updatable Objects are created and maintained locally. In both cases there is no need to install policy for the changes to take effect.
Which process handles connections from SmartConsole R80?
cpm
cpd
cpmd
fwd
Which of the following cannot be configured in an Access Role Object?
Networks
Machines
Users
Time
Which of the following is NOT a component of a Distinguished Name?
Common Name
Country
User container
Organizational Unit
Using Threat Emulation technologies, what is the best way to block .exe and .bat file types?
Enable .exe bat protection in IPS Policy
tecli advanced attributes set prohibited_file_types exe, bat
create FW rule for particular protocol
enable DLP and select .exe and .bat file type
Which command will reset the kernel debug options to default settings?
fw ctl dbg –a 0
fw ctl debug set 0
fw ctl debug 0
fw ctl dbg resetall
Alice knows about the Check Point Management HA installation from Bob and needs to know which Check Point Security Management Server is currently capable of issuing and managing certificate. Alice uses the Check Point command “cpconfig” to run the Check Point Security Management Server configuration tool on both Check Point Management HA instances “Primary & Secondary”. Which configuration option does she need to look for?
Certificate's Fingerprint
Random Pool
Certificate Authority
CA Authority
Is it possible to establish a VPN before the user login to the Endpoint Client.
Yes, you had to set neo_remember_user_password to true in the trac.defaults of the Remote Access Client or you can use the endpoint_vpn_remember_user_password attribute in the trac_client_1.ttm file located in the $FWDIR/conf directory on the Security Gateway
Yes, you had to set neo_always_connected to true in the trac.defaults of the Remote Access Client or you can use the endpoint_vpn_always_connected attribute in the trac_client_1.ttm file located in the $FWDIR/conf directory on the Security Gateway
No, the user must login first.
Yes, you have to enable Machine Authentication in the Gateway object of the Smart Console
Mobile Access Gateway can be configured as a reverse proxy for Internal Web Applications. Reverse proxy users browse to a URL that is resolved to the Security Gateway IP address. Which of the following Check Point command is true for enabling the Reverse Proxy:
ReverseProxy
ReverseCLIProxy
ReverseProxyCLI
ProxyReverseCLI
Capsule Connect and Capsule Workspace both offer secured connection for remote users who are using their mobile devices. However, there are differences between the two. Which of the following statements correctly identify each product’s capabilities?
For compliance/host checking, Workspace offers the MDM cooperative enforcement, whereas Connect offers both jailbreak/root detection and MDM cooperative enforcement.
Workspace can support any application, whereas Connect has a limited number of application types which it will support
Workspace supports iOS, Android, and WP8, whereas Connect supports iOS and Android only
For credential protection, Connect uses One-time Password login support, but has no SSO support, whereas Workspace offers both One-Time Password login support as well as SSO for specific applications.
What are the two modes for SNX (SSL Network Extender)?
Network Mode and Hub Mode
Network Mode and Application Mode
Visitor Mode and Office Mode
Office Mode and Hub Mode
Native Applications require a thin client under which circumstances?
If you want to have assigned a particular Office Mode IP address
If you are about to use a client (FTP, RDP, ...) that is installed on the endpoint.
If you want to use a VPN Client that is not officially supported by the underlying operating system
If you want to use a legacy 32-Bit Windows OS
In SmartConsole, where do you manage your Mobile Access Policy?
Through the Mobile Console
Shared Gateways Policy
From the Dedicated Mobility Tab
Smart Dashboard
When detected, an event can activate an Automatic Reaction. The SmartEvent administrator can create and configure one Automatic Reaction, or many, according to the needs of the system. Which of the following statement is false and NOT part of possible automatic reactions:
Syslog
SNMP Trap
Block Source
What are possible Automatic Reactions in SmartEvent?
Web Mail, Forward to SandBlast Appliance, SNMP Trap, External Script
Web Mail, Block Service, SNMP Trap, SmartTask, Geo Protectio
Web Mail, Block Destination, SNMP Trap, SmartTask
Mail, SNMP Trap, Block Source, Block Event Activity, External Script
Which command can you use to enable or disable multi-queue per interface?
Cpmqueue set
Set cpmq enable
Cpmq config
cpmq set
What is Dynamic Balancing?
It is a feature that uses a daemon to balance the required number of firewall instances and SNDs based on the current load
It is a ClusterXL feature that switches an HA cluster into an LS cluster if required to maximize throughput.
It is a CoreXL feature that assigns the SND to network interfaces to balance the RX Cache of the interfaces
It is a new feature that is capable of dynamically reserve the amount of Hash kernel memory to reflect the resource usage necessary for maximizing the session rate.
Which is the command to identify the NIC driver before considering about the employment of the Multi-Queue feature?
ip show int eth0
show interface eth0 mq
ifconfig –i eth0 verbose
ethtool –i eth0
What is the minimum number of CPU cores required to enable CoreXL?
2
1
4
6
What destination versions are supported for a Multi-Version Cluster Upgrade?
R77.30 and later
R80.10 and Later
R70 and Later
R76 and later
Which command can you use to verify the number of active concurrent connections?
fw conn all
show all connections
fw ctl pstat
show connections
Under which file is the proxy arp configuration stored?
$FWDIR/state/_tmp/proxy.arp on the security gateway
$FWDIR/conf/local.arp on the management server
$FWDIR/conf/local.arp on the gateway
$FWDIR/state/proxy_arp.conf on the management server
You pushed a policy to your gateway, and you cannot access the gateway remotely anymore. What command should you use to remove the policy from the gateway by logging in through console access?
“fw unloadpolicy”
“fw unloadlocal”
“fw cpstop”
“fw undo”
Which command would disable a Cluster Member permanently?
clusterXL_admin_down
cphaprob_admin down
clusterXL_admin down –p
set clusterXL down –p
While using the Gaia CLI, what is the correct command to publish changes to the management server?
json publish
mgmt publish
mgmt._cli commit
commit19009
The fwd process on the Security Gateway sends logs to the fwd process on the Management Server, where it is forwarded to ______ via ______.
cpm, cpd
cpwd, fwssd
fwm, cpd
cpd, fwm
Which TCP port does the CPM process listen on?
19009
18191
8983
18190
What command is used to manually failover a cluster during a zero-downtime upgrade?
clusterXL_admin down
set cluster member down
cpstop
set clusterXL down
Which of the following is an identity acquisition method that allows a Security Gateway to identify Active Directory users and computers?
UserCheck
User Directory Query
Account Unit Query
Active Directory Query
