wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CCSE-5

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Aaron is a Cyber Security Engineer working for Global Law Firm with large scale deployment of Check Point Enterprise Appliances running GAiA R80.X. The Network Security Developer Team is having an issue testing the API with a newly deployed R80.X Security Management Server. Aaron wants to confirm API services are working properly. What should he do first?

a)

Aaron should check API Server status with “api status" from Expert mode. If services are stopped, he should start them with “api start".

b)

Aaron should check API Server status with “cpapi status" from Expert mode. If services are stopped, he should start them with "cpapi start”.

c)

Aaron should check API Server status with “fwm api status” from Expert mode. If services are stopped, he should start them with “fwm api start".

d)

Aaron should check API Server status with "cpm api status” from Expert mode. If services are stopped, he should start them with “cpi api start".

2.

For Management High Availability, which of the following is NOT a valid synchronization status?

a)

Collision

b)

Lagging

c)

Never been synchronized

d)

Down

3.

If the Active Security Management Server falls or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss.

Providing the Active Security Management Server is responsive, which of these steps should NOT be performed:

a)

Rename the hostname of the Standby member to match exactly the hostname of the Active member.

b)

Change the Active Security Management Server to Standby.

c)

Manually synchronize the Active and Standby Security Management Servers.

d)

Change the Standby Security Management Server to Active.

4.

What should the admin do in case the Primary Management Server is temporary down?

a)

Run the ‘promote_util’ to activate the Secondary Management server.

b)

The Secondary will take over automatically. Change the IP in SmartConsole to logon to the private IP of the Secondary Management Server.

c)

Use the VIP in SmartConsole you always reach the active Management Server.

d)

Logon with SmartConsole to the Secondary Management Server and choose ‘Make Active’ under Actions in the HA Management Menu.

5.

Check Point Management (cpm) is the main management process in that it provides the architecture for a consolidated management console. It empowers the migration from legacy Client-side logic to Server-side logic. The cpm process

a)

Performs database tasks such as creating, deleting, and modifying objects and compiling policy.

b)

Allows SmartConsole to communicate over TCP Port 19001

c)

Performs database tasks such as creating, deleting, and modifying objects and indexing logs

d)

Allows SmartConsole to communicate over TCP Port 18190

6.

Which Check Point daemon invokes and monitors critical processes and attempts to restart them if they fail?

a)

cpm

b)

cpwd

c)

fwm

d)

cpd

7.

John is using Management HA. Which Security Management Server should he use for making changes?

a)

Primary Log Server

b)

connect virtual IP of Smartcenter HA

c)

active SmartConsole

d)

secondary Smartcenter

8.

Name the authentication method that requires token authenticator.

a)

SecureID

b)

DynamicID

c)

Radius

d)

TACACS

9.

Fill in the blank. With the User Directory Software Blade, you can create user definitions on a(n)_______ Server.

a)

SecurID

b)

NT domain

c)

LDAP

d)

SMTP

10.

Which command is used to display status information for various components?

a)

show sysenv all

b)

show all systems

c)

show system messages

d)

sysmess all

11.

Secure Configuration Verification (SCV) makes sure that remote access client computers are configured in accordance with the enterprise Security Policy. Bob was asked by Alice to implement a specific SCV configuration but therefore Bob needs to edit and configure a specific Check Point file. Which location file and directory is true?

a)

$CPDIR/conf/client.svc

b)

$FWDIR/conf/local.scv

c)

$CPDIR/conf/local.scv

d)

$FWDIR/conf/client.scv

12.

There are multiple types of licenses for the various VPN components and types. License type related to management and functioning of Remote Access VPNs are – which of the following license requirement statement is NOT true:

a)

IPSecVPNLicense » This license is installed on the VPN Gateway and is a basic requirement for a Remote Access VPN solution

b)

EndpointPolicyManagementLicense » The Endpoint Security Suite includes blades other than the Remote Access VPN, hence this license is required to manage the suite

c)

EndpointContainerLicense » The Endpoint Software Blade Licenses does not require an Endpoint Container License as the base

d)

MobileAccessLicense » This license is required on the Security Gateway for the following Remote Access solutions

13.

Which of the following type of authentication on Mobile Access can NOT be used as the first authentication method?

a)

Username and Password

b)

Dynamic ID

c)

RADIUS

d)

Certificate

14.

You need to change the number of firewall instances used by CoreXL. How can you achieve this goal?

a)

cpconfig; reboot not required

b)

edit fwaffinity.conf; reboot not required

c)

cpconfig; reboot required

d)

edit fwaffinity.conf; reboot required

15.

Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?

a)

Run cprestart from clish

b)

After upgrading the hardware, increase the number of kernel instances using cpconfig

c)

Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores

d)

Hyperthreading must be enabled in the bios to use CoreXL.

16.

Bob is asked by Alice to disable the SecureXL mechanism temporary for further diagnostic by their Check Point partner. Which of the following Check Point Command is true:

a)

fwaccel templates

b)

fwaccel suspend

c)

fwaccel standby

d)

fwaccel off

17.

Which of the following Central Deployment is NOT a limitation in R81.20 SmartConsole?

a)

Security Gateways/Clusters is ClusterXL HA new mode

b)

Dedicated Log Server

c)

Security Gateway Clusters in Load Sharing mode

d)

Dedicated SmartEvent Server

18.

Matt wants to upgrade his old Security Management Server to R81.x using the Advanced Upgrade with Database Migration. What is one of the requirements for a successful upgrade?

a)

Size of the /var/log folder of the source machine must be at least 25% of the size of the /var/log directory on the target machine

b)

Size of the $FWDIR/log folder of the target machine must be a least 25% of the size of the $FWDIR/log directory on the source machine

c)

Size of the /var/log folder of the target machine must be 25GB or more

d)

Size of the /var/log folder of the target machine must be at least 25% of the size of the /var/log directory on the source machine

19.

The Firewall Administrator is required to create 100 new host objects with different IP addresses. What API command can he use in the script to achieve the requirement?

a)

add hostname ip-address

b)

set hostname ip-address

c)

set host name ip-address

d)

mgmt_cli-m add host name ip-address

20.

What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?

a)

VPN Routing Mode

b)

Stateless Mode

c)

Stateful Mode

d)

Wire Mode

21.

Bob has finished to setup provisioning a secondary security management server. Now he wants to check if the provisioning has been correct. Which of the following Check Point command can be used to check if the security management server has been installed as a primary or a secondary security management server?

a)

cpprod_util MgmtIsPrimary

b)

cpprod_util FwIsSecondary

c)

cpprod_util FwIsPrimary

d)

cpprod_util MgmtIsSecondary

22.

How can you see historical data with cpview?

a)

cpview -e

b)

cpview -d

c)

cpview -f

d)

cpview -t

23.

According to the policy installation flow the transfer state (CPTA) is responsible for the code generated by the FWM. On the Security Gateway side, a process receives them and first stores them into a temporary directory. Which process is true for receiving these files:

a)

CPD

b)

RAD

c)

FWD

d)

FWM

24.

What ports are used for SmartConsole to connect to the Security Management Server?

a)

CPMI (18190)

b)

CA_Pull (18210), CPMI (18190) https (443)

c)

CPM (19009), CPMI (18190) https (443)

d)

CPM (19009), CPMI (18190) CPD (18191)

25.

Which of the following Check Point processes within the Security Management Server is responsible for the receiving of log records from Security Gateway?

a)

cpd

b)

fwm

c)

logd

d)

fwd

26.

Check Point Management (cpm) is the main management process in that it provides the architecture for a consolidated management console. CPM allows the GUI client and management server to communicate via web services using _______.

a)

TCP Port 18190

b)

TCP Port 18191

c)

TCP Port 18209

d)

TCP port 19009

27.

What command is used to manually failover a Multi-Version Cluster during the upgrade?

a)

set cluster member state down in Clish

b)

clusterXL_admin down in Expert Mode

c)

set cluster down in Expert Mode

d)

clusterXL_admin down in Clish

28.

How can you make sure that the old logs will be available after updating the Management to version R81.20 using the Advanced Upgrade Method?

a)

Use the WebUI -> Maintenance > System Backup and store the backup on a remote FTP server

b)

The logs will be included running $FWDIR/scripts/migrate_server export -v R81.10

c)

Use the WebUI to save a snapshot before updating the Management -> Maintenance > Snapshot Management

d)

Use the migrate_server tool with the option ‘-l’ for the logs and ‘-x’ for the index

29.

What is the command to check the status of Check Point processes?

a)

cphaprob list

b)

top

c)

cpwd_admin list

d)

cptop

30.

In CoreXL, the Firewall kernel is replicated multiple times. Each replicated copy or instance can perform the following:

a)

The Firewall kernel only touches the packet if the connection is accelerated

b)

The Firewall kernel is replicated only with new connections and deletes itself once the connection times out

c)

The Firewall can run the same policy on all cores

d)

The Firewall can run different policies per core

31.

Which is the lowest gateway version supported by R81.20 management server?

a)

R77.30

b)

R80.20

c)

R77

d)

R65

32.

What is the purpose of Captive Portal?

a)

> It authenticates users, allowing them access to the Gaia OS

b)

It authenticates users, allowing them access to the Internet and corporate resources

c)

It provides remote access to SmartConsole

d)

It manages user permission in SmartConsole

33.

Which of the following is NOT a component of Check Point Capsule?

a)

Capsule Workspace

b)

Capsule Enterprise

c)

Capsule Docs

d)

Capsule Cloud

34.

You have a Gateway that is running with 2 cores. You plan to add a second gateway to build a cluster and used a device with 4 cores. How many cores can be used in a Cluster for Firewall-kernel on the new device?

a)

2

b)

1

c)

4

d)

3

35.

Which of the SecureXL templates are enabled by default on Security Gateway?

a)

NAT

b)

Drop

c)

None

d)

Accept

36.

What is true about the IPS-Blade?

a)

In the IPS Layer, the only three possible actions are Basic, Optimized and Strict

b)

IPS is managed by the Threat Prevention Policy

c)

IPS Exceptions cannot be attached to “all rules”

d)

The GeoPolicy Exceptions and the Threat Prevention Exceptions are the same

37.

After upgrading the primary security management server from R80.40 to R81.10 Bob wants to use the central deployment in SmartConsole R81.10 for the first time. How many installations (e.g. Jumbo Hotfix, Hotfixes or Upgrade Packages) can run of such at the same time:

a)

Up to 5 gateways

b)

Only 1 gateway

c)

Up to 10 gateways

d)

Up to 3 gateways

38.

The Check Point Central Deployment Tool (CDT) communicates with the Security Gateway(s) over Check Point SIC via ________.

a)

TCP Port 18190

b)

TCP Port 18191

c)

TCP Port 19009

d)

TCP Port 18209

39.

What is the recommended number of physical network interfaces in a Mobile Access cluster deployment?

a)

3 Interfaces - an interface leading to the organization, a second interface leading to the internet, a third interface for synchronization

b)

2 Interfaces - a data interface leading to the organization and the Internet, a second interface for synchronization

c)

4 Interfaces - an interface leading to the organization, a second interface leading to the internet, a third interface for synchronization, a fourth interface leading to the Security Management Server

d)

1 interface - an interface leading to the organization and the Internet, and configure for synchronization

40.

What is not a purpose of the deployment of Check Point API?

a)

Integrate Check Point products with 3rd party solution

b)

Create products that use and enhance the Check Point solution

c)

Create a customized GUI Client for manipulating the objects database

d)

Execute an automated script to perform common tasks