NEW
Font size
WorksheetsCCSE-5
Total questions: 40
Worksheet time: 20mins
Aaron is a Cyber Security Engineer working for Global Law Firm with large scale deployment of Check Point Enterprise Appliances running GAiA R80.X. The Network Security Developer Team is having an issue testing the API with a newly deployed R80.X Security Management Server. Aaron wants to confirm API services are working properly. What should he do first?
Aaron should check API Server status with “api status" from Expert mode. If services are stopped, he should start them with “api start".
Aaron should check API Server status with “cpapi status" from Expert mode. If services are stopped, he should start them with "cpapi start”.
Aaron should check API Server status with “fwm api status” from Expert mode. If services are stopped, he should start them with “fwm api start".
Aaron should check API Server status with "cpm api status” from Expert mode. If services are stopped, he should start them with “cpi api start".
For Management High Availability, which of the following is NOT a valid synchronization status?
Collision
Lagging
Never been synchronized
Down
If the Active Security Management Server falls or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss.
Providing the Active Security Management Server is responsive, which of these steps should NOT be performed:
Rename the hostname of the Standby member to match exactly the hostname of the Active member.
Change the Active Security Management Server to Standby.
Manually synchronize the Active and Standby Security Management Servers.
Change the Standby Security Management Server to Active.
What should the admin do in case the Primary Management Server is temporary down?
Run the ‘promote_util’ to activate the Secondary Management server.
The Secondary will take over automatically. Change the IP in SmartConsole to logon to the private IP of the Secondary Management Server.
Use the VIP in SmartConsole you always reach the active Management Server.
Logon with SmartConsole to the Secondary Management Server and choose ‘Make Active’ under Actions in the HA Management Menu.
Check Point Management (cpm) is the main management process in that it provides the architecture for a consolidated management console. It empowers the migration from legacy Client-side logic to Server-side logic. The cpm process
Performs database tasks such as creating, deleting, and modifying objects and compiling policy.
Allows SmartConsole to communicate over TCP Port 19001
Performs database tasks such as creating, deleting, and modifying objects and indexing logs
Allows SmartConsole to communicate over TCP Port 18190
Which Check Point daemon invokes and monitors critical processes and attempts to restart them if they fail?
cpm
cpwd
fwm
cpd
John is using Management HA. Which Security Management Server should he use for making changes?
Primary Log Server
connect virtual IP of Smartcenter HA
active SmartConsole
secondary Smartcenter
Name the authentication method that requires token authenticator.
SecureID
DynamicID
Radius
TACACS
Fill in the blank. With the User Directory Software Blade, you can create user definitions on a(n)_______ Server.
SecurID
NT domain
LDAP
SMTP
Which command is used to display status information for various components?
show sysenv all
show all systems
show system messages
sysmess all
Secure Configuration Verification (SCV) makes sure that remote access client computers are configured in accordance with the enterprise Security Policy. Bob was asked by Alice to implement a specific SCV configuration but therefore Bob needs to edit and configure a specific Check Point file. Which location file and directory is true?
$CPDIR/conf/client.svc
$FWDIR/conf/local.scv
$CPDIR/conf/local.scv
$FWDIR/conf/client.scv
There are multiple types of licenses for the various VPN components and types. License type related to management and functioning of Remote Access VPNs are – which of the following license requirement statement is NOT true:
IPSecVPNLicense » This license is installed on the VPN Gateway and is a basic requirement for a Remote Access VPN solution
EndpointPolicyManagementLicense » The Endpoint Security Suite includes blades other than the Remote Access VPN, hence this license is required to manage the suite
EndpointContainerLicense » The Endpoint Software Blade Licenses does not require an Endpoint Container License as the base
MobileAccessLicense » This license is required on the Security Gateway for the following Remote Access solutions
Which of the following type of authentication on Mobile Access can NOT be used as the first authentication method?
Username and Password
Dynamic ID
RADIUS
Certificate
You need to change the number of firewall instances used by CoreXL. How can you achieve this goal?
cpconfig; reboot not required
edit fwaffinity.conf; reboot not required
cpconfig; reboot required
edit fwaffinity.conf; reboot required
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?
Run cprestart from clish
After upgrading the hardware, increase the number of kernel instances using cpconfig
Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores
Hyperthreading must be enabled in the bios to use CoreXL.
Bob is asked by Alice to disable the SecureXL mechanism temporary for further diagnostic by their Check Point partner. Which of the following Check Point Command is true:
fwaccel templates
fwaccel suspend
fwaccel standby
fwaccel off
Which of the following Central Deployment is NOT a limitation in R81.20 SmartConsole?
Security Gateways/Clusters is ClusterXL HA new mode
Dedicated Log Server
Security Gateway Clusters in Load Sharing mode
Dedicated SmartEvent Server
Matt wants to upgrade his old Security Management Server to R81.x using the Advanced Upgrade with Database Migration. What is one of the requirements for a successful upgrade?
Size of the /var/log folder of the source machine must be at least 25% of the size of the /var/log directory on the target machine
Size of the $FWDIR/log folder of the target machine must be a least 25% of the size of the $FWDIR/log directory on the source machine
Size of the /var/log folder of the target machine must be 25GB or more
Size of the /var/log folder of the target machine must be at least 25% of the size of the /var/log directory on the source machine
The Firewall Administrator is required to create 100 new host objects with different IP addresses. What API command can he use in the script to achieve the requirement?
add hostname ip-address
set hostname ip-address
set host name ip-address
mgmt_cli-m add host name ip-address
What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?
VPN Routing Mode
Stateless Mode
Stateful Mode
Wire Mode
Bob has finished to setup provisioning a secondary security management server. Now he wants to check if the provisioning has been correct. Which of the following Check Point command can be used to check if the security management server has been installed as a primary or a secondary security management server?
cpprod_util MgmtIsPrimary
cpprod_util FwIsSecondary
cpprod_util FwIsPrimary
cpprod_util MgmtIsSecondary
How can you see historical data with cpview?
cpview -e
cpview -d
cpview -f
cpview -t
According to the policy installation flow the transfer state (CPTA) is responsible for the code generated by the FWM. On the Security Gateway side, a process receives them and first stores them into a temporary directory. Which process is true for receiving these files:
CPD
RAD
FWD
FWM
What ports are used for SmartConsole to connect to the Security Management Server?
CPMI (18190)
CA_Pull (18210), CPMI (18190) https (443)
CPM (19009), CPMI (18190) https (443)
CPM (19009), CPMI (18190) CPD (18191)
Which of the following Check Point processes within the Security Management Server is responsible for the receiving of log records from Security Gateway?
cpd
fwm
logd
fwd
Check Point Management (cpm) is the main management process in that it provides the architecture for a consolidated management console. CPM allows the GUI client and management server to communicate via web services using _______.
TCP Port 18190
TCP Port 18191
TCP Port 18209
TCP port 19009
What command is used to manually failover a Multi-Version Cluster during the upgrade?
set cluster member state down in Clish
clusterXL_admin down in Expert Mode
set cluster down in Expert Mode
clusterXL_admin down in Clish
How can you make sure that the old logs will be available after updating the Management to version R81.20 using the Advanced Upgrade Method?
Use the WebUI -> Maintenance > System Backup and store the backup on a remote FTP server
The logs will be included running $FWDIR/scripts/migrate_server export -v R81.10
Use the WebUI to save a snapshot before updating the Management -> Maintenance > Snapshot Management
Use the migrate_server tool with the option ‘-l’ for the logs and ‘-x’ for the index
What is the command to check the status of Check Point processes?
cphaprob list
top
cpwd_admin list
cptop
In CoreXL, the Firewall kernel is replicated multiple times. Each replicated copy or instance can perform the following:
The Firewall kernel only touches the packet if the connection is accelerated
The Firewall kernel is replicated only with new connections and deletes itself once the connection times out
The Firewall can run the same policy on all cores
The Firewall can run different policies per core
Which is the lowest gateway version supported by R81.20 management server?
R77.30
R80.20
R77
R65
What is the purpose of Captive Portal?
> It authenticates users, allowing them access to the Gaia OS
It authenticates users, allowing them access to the Internet and corporate resources
It provides remote access to SmartConsole
It manages user permission in SmartConsole
Which of the following is NOT a component of Check Point Capsule?
Capsule Workspace
Capsule Enterprise
Capsule Docs
Capsule Cloud
You have a Gateway that is running with 2 cores. You plan to add a second gateway to build a cluster and used a device with 4 cores. How many cores can be used in a Cluster for Firewall-kernel on the new device?
2
1
4
3
Which of the SecureXL templates are enabled by default on Security Gateway?
NAT
Drop
None
Accept
What is true about the IPS-Blade?
In the IPS Layer, the only three possible actions are Basic, Optimized and Strict
IPS is managed by the Threat Prevention Policy
IPS Exceptions cannot be attached to “all rules”
The GeoPolicy Exceptions and the Threat Prevention Exceptions are the same
After upgrading the primary security management server from R80.40 to R81.10 Bob wants to use the central deployment in SmartConsole R81.10 for the first time. How many installations (e.g. Jumbo Hotfix, Hotfixes or Upgrade Packages) can run of such at the same time:
Up to 5 gateways
Only 1 gateway
Up to 10 gateways
Up to 3 gateways
The Check Point Central Deployment Tool (CDT) communicates with the Security Gateway(s) over Check Point SIC via ________.
TCP Port 18190
TCP Port 18191
TCP Port 19009
TCP Port 18209
What is the recommended number of physical network interfaces in a Mobile Access cluster deployment?
3 Interfaces - an interface leading to the organization, a second interface leading to the internet, a third interface for synchronization
2 Interfaces - a data interface leading to the organization and the Internet, a second interface for synchronization
4 Interfaces - an interface leading to the organization, a second interface leading to the internet, a third interface for synchronization, a fourth interface leading to the Security Management Server
1 interface - an interface leading to the organization and the Internet, and configure for synchronization
What is not a purpose of the deployment of Check Point API?
Integrate Check Point products with 3rd party solution
Create products that use and enhance the Check Point solution
Create a customized GUI Client for manipulating the objects database
Execute an automated script to perform common tasks
