Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DUMSA_3

Total questions: 56

Worksheet time: 28mins

Name
Class
Date
1.

What are the advantages of a “shared policy” in R80?

a)

Allows the administrator to share a policy between all the users identified by the Security Gateway

b)

Allows the administrator to share a policy between all the administrators managing the Security Management Server

c)

Allows the administrator to share a policy so that it is available to use in another Policy Package

d)

Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway

2.

To view statistics on detected threats, which Threat Tool would an administrator use?

a)

Protections

b)

IPS Protections

c)

Profiles

d)

ThreatWiki

3.

What is the purpose of a Clean-up Rule?

a)

Clean-up Rules do not serve any purpose

b)

Provide a metric for determining unnecessary rules

c)

To drop any traffic that is not explicitly allowed

d)

Used to better optimize a policy

4.

What are the two types of NAT supported by the Security Gateway?

a)

Destination and Hide

b)

Hide and Static

c)

Static and Source

d)

Source and Destination

5.

Vanessa is attempting to log into the Gaia Web Portal. She is able to login successfully. Then she tries the same username and password for SmartConsole but gets the message shown in the screenshot. She has checked that the IP address of the Server is correct and the username and password she used to login into Gaia is also correct. What is the most likely reason?

a)

Check Point R80 SmartConsole authentication is more secure than in previous versions and Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.

b)

Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.

c)

SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.

d)

Authentication failed because Vanessa’s username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.

6.

What is the most complete definition of the difference between the Install Policy button on the SmartConsole’s tab, and the Install Policy within a specific policy?

a)

The Global one also saves and published the session before installation.

b)

The Global one can install multiple selected policies at the same time.

c)

The local one does not install the Anti-Malware policy along with the Network policy.

d)

The second one pre-selects the installation for only the current policy and for the applicable gateways.

7.

Which of the following is used to initially create trust between a Gateway and Security Management Server?

a)

Internal Certificate Authority

b)

Token

c)

One-time Password

d)

Certificate

8.

John is the administrator of a R80 Security Management server managing r R77.30 Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators, and to save the database before installing a policy, what must John do?

a)

Logout of the session

b)

File > Save

c)

Install database

d)

Publish the session

9.

Fill in the blanks: There are _______ types of software containers _________.

a)

Three; security management, Security Gateway, and endpoint security

b)

Three; Security gateway, endpoint security, and gateway management

c)

Two; security management and endpoint security

d)

Two; endpoint security and Security Gateway

10.

Fill in the bank: In Office mode, a Security Gateway assigns a remote client to an IP address once _____________.

a)

the user connects and authenticates

b)

office mode is initiated

c)

the user requests a connection

d)

the user connects

11.

Which Identity Source(s) should be selected in Identity Awareness for when there is a requirement for a higher level of security for sensitive servers?

a)

AD Query

b)

Terminal Servers Endpoint Identity Agent

c)

Endpoint Identity Agent and Browser-Based Authentication

d)

RADIUS and Account Logon

12.

Which statement describes what Identity Sharing is in Identity Awareness?

a)

Management servers can acquire and share identities with Security Gateways

b)

Users can share identities with other users

c)

Security Gateways can acquire and share identities with other Security Gateways

d)

Administrators can share identifies with other administrators

13.

What is the most recommended installation method for Check Point appliances?

a)

SmartUpdate installation

b)

DVD media created with Check Point ISOMorphic

c)

USB media created with Check Point ISOMorphic

d)

Cloud based installation

14.

Which of the following is NOT a role of the SmartCenter:

a)

Status monitoring

b)

Policy configuration

c)

Certificate authority

d)

Address translation

15.

Which of the following is NOT a valid application navigation tab in the R80 SmartConsole?

a)

Manage and Command Line

b)

Logs and Monitor

c)

Security Policies

d)

Gateway and Servers

16.

Phase 1 of the two-phase negotiation process conducted by IKE operates in ______ mode.

a)

Main

b)

Authentication

c)

Quick

d)

High Alert

17.

What is the BEST method to deploy Identity Awareness for roaming users?

a)

Use Office Mode

b)

Use identity agents

c)

Share user identities between gateways

d)

Use captive portal

18.

What is the purpose of the Clean-up Rule?

a)

To drop and log all connections that do not match any prior rule

b)

To allow all unmatched connections for availability

c)

To bypass inspection for trusted networks

d)

To prioritize traffic based on QoS

19.

Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?

a)

Application Control

b)

Threat Emulation

c)

Anti-Virus

d)

Advanced Networking Blade

20.

Fill in the blank: Back up and restores can be accomplished through ________.

a)

SmartConsole, WebUI, or CLI

b)

WebUI, CLI, or SmartUpdate

c)

CLI, SmartUpdate, or SmartBackup

d)

SmartUpdate, SmartBackup, or SmartConsole

21.

What does it mean if Deyra sees the gateway status shown in the image table, where the Status column displays a red “X” for gateways named A-GW and SMS, with IP addresses 10.1.1.1 and 10.1.1.101 and Version R80? Choose the BEST answer.

a)

SmartCenter Server cannot reach this Security Gateway

b)

There is a blade reporting a problem

c)

VPN software blade is reporting a malfunction

d)

Security Gateway’s MGNT NIC card is disconnected

22.

CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You suspect that the problem might be the Threat Prevention settings. The following Threat Prevention Profile has been created. How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.

a)

Set High Confidence to Low and Low Confidence to Inactive.

b)

Set the Performance Impact to Medium or lower.

c)

The problem is not with the Threat Prevention Profile. Consider adding more memory to the appliance.

d)

Set the Performance Impact to Very Low Confidence to Prevent.

23.

Which icon in the WebUI indicates that read/write access is enabled?

a)

Pencil

b)

Padlock

c)

Book

d)

Eyeglasses

24.

What is NOT an advantage of Stateful Inspection?

a)

High Performance

b)

Good Security

c)

No Screening above Network layer

d)

Transparency

25.

Which of the following Windows Security Events will NOT map a username to an IP address in Identity Awareness?

a)

Kerberos Ticket Renewed

b)

Kerberos Ticket Requested

c)

Account Logon

d)

Kerberos Ticket Timed Out

26.

Fill in the blank: Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or _________.

a)

On all satellite gateway to satellite gateway tunnels

b)

On specific tunnels for specific gateways

c)

On specific tunnels in the community

d)

On specific satellite gateway to central gateway tunnels

27.

In Unified SmartConsole Gateways and Servers tab you can perform the following functions EXCEPT ________.

a)

Upgrade the software version

b)

Open WebUI

c)

Open SSH

d)

Open service request with Check Point Technical Support

28.

Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? (Choose the best answer.)

a)

IPS

b)

Anti-Virus

c)

Anti-Malware

d)

Content Awareness

29.

When configuring Spoof Tracking, which tracking actions can an administrator select to be done when spoofed packets are detected?

a)

Log, send snmp trap, email

b)

Drop packet, alert, none

c)

Log, alert, none

d)

Log, allow packets, email

30.

Access roles allow the firewall administrator to configure network access according to:

a)

remote access clients.

b)

a combination of computer or computer groups and networks.

c)

users and user groups.

d)

All of the above.

31.

What are the three deployment considerations for a secure network?

a)

Distributed, Bridge Mode, and Remote

b)

Bridge Mode, Remote, and Standalone

c)

Remote, Standalone, and Distributed

d)

Standalone, Distributed, and Bridge Mode

32.

Which option, when applied to a rule, allows traffic to VPN gateways in specific VPN communities?

a)

All Connections (Clear or Encrypted)

b)

Accept all encrypted traffic

c)

Specific VPN Communities

d)

All Site-to-Site VPN Communities

33.

When a Security Gateways sends its logs to an IP address other than its own, which deployment option is installed?

a)

Distributed

b)

Standalone

c)

Bridge

34.

One of major features in R80.x SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB, and AdminC are editing the same Security Policy?

a)

AdminC sees a lock icon which indicates that the rule is locked for editing by another administrator.

b)

AdminA and AdminB are editing the same rule at the same time.

c)

AdminB sees a pencil icon next the rule that AdminB is currently editing.

d)

AdminA, AdminB and AdminC are editing three different rules at the same time.

35.

When should you generate new licenses?

a)

Before installing contract files.

b)

After an RMA procedure when the MAC address or serial number of the appliance changes.

c)

When the existing license expires, license is upgraded or the IP-address where the license is tied changes.

d)

Only when the license is upgraded.

36.

Fill in the blank: When a policy package is installed, ________ are also distributed to the target installation Security Gateways.

a)

User and objects databases

b)

Network databases

c)

SmartConsole databases

d)

User databases

37.

Which of the following is NOT a method used by Identity Awareness for acquiring identity?

a)

Remote Access

b)

Cloud IdP (Identity Provider)

c)

Active Directory Query

d)

RADIUS

38.

Which Check Point software blade provides Application Security and identity control?

a)

Identity Awareness

b)

Data Loss Prevention

c)

URL Filtering

d)

Application Control

39.

How are the backups stored in Check Point appliances?

a)

Saved as *.tar under /var/log/CPbackup/backups

b)

Saved as *.tgz under /var/CPbackup

c)

Saved as *.tar under /var/CPbackup

d)

Saved as *.tgz under /var/log/CPbackup/backups

40.

You are going to perform a major upgrade. Which back up solution should you use to ensure your database can be restored on that device?

a)

backup

b)

logswitch

c)

Database Revision

d)

snapshot

41.

Which tool is used to enable ClusterXL?

a)

SmartUpdate

b)

cpconfig

c)

SmartConsole

d)

sysconfig

42.

What type of NAT is a one-to-one relationship where each host is translated to a unique address?

a)

Source

b)

Static

c)

Hide

d)

Destination

43.

Which one of the following is a way that the objects can be manipulated using the new API integration in R80 Management?

a)

Microsoft Publisher

b)

JSON

c)

Microsoft Word

d)

RC4 Encryption

44.

True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway

a)

True, CLI is the prefer method for Licensing

b)

False, Central License are handled via Security Management Server

c)

False, Central License are installed via Gaia on Security Gateways

d)

True, Central License can be installed with CPLIC command on a Security Gateway

45.

Which of the following is NOT an identity source used for Identity Awareness?

a)

Remote Access

b)

UserCheck

c)

AD Query

d)

RADIUS

46.

Fill in the blanks: Default port numbers for an LDAP server is ____ for standard connections and _____ SSL connections.

a)

675, 389

b)

389, 636

c)

636, 290

d)

290, 675

47.

Which of the following is NOT supported by Bridge Mode Check Point Security Gateway?

a)

Antivirus

b)

Data Loss Prevention

c)

NAT

d)

Application Control

48.

Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?

a)

All Site-to-Site VPN Communities

b)

Accept all encrypted traffic

c)

All Connections (Clear or Encrypted)

d)

Specific VPN Communities

49.

In which scenario is it a valid option to transfer a license from one hardware device to another?

a)

From a 4400 Appliance to a 2200 Appliance

b)

From a 4400 Appliance to an HP Open Server

c)

From an IBM Open Server to an HP Open Server

d)

From an IBM Open Server to a 2200 Appliance

50.

Fill in the blanks: A ____ license requires an administrator to designate a gateway for attachment whereas a _____ license is automatically attached to a Security Gateway.

a)

Formal; corporate

b)

Local; formal

c)

Local; central

d)

Central; local

51.

Which of the following is NOT a valid configuration screen of an Access Role Object?

a)

Users

b)

Networks

c)

Time

d)

Machines

52.

What is the purpose of the Stealth Rule?

a)

To prevent users from directly connecting to a Security Gateway.

b)

To reduce the number of rules in the database.

c)

To reduce the amount of logs for performance issues.

d)

To hide the gateway from the Internet.

53.

What key is used to save the current CPView page in a filename format cpview_"cpview process ID". cap"number of captures"?

a)

S

b)

W

c)

C

d)

Space bar

54.

Fill in the blank: It is Best Practice to have a ______ rule at the end of each policy layer.

a)

Explicit Drop

b)

Implied Drop

c)

Explicit Cleanup

d)

Implicit Drop

55.

When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?

a)

Access Role

b)

User Group

c)

SmartDirectory Group

d)

Group Template

56.

The ______ software blade package uses CPU-level and OS-level sandboxing in order to detect and block malware.

a)

Next Generation Threat Prevention

b)

Next Generation Threat Emulation

c)

Next Generation Threat Extraction

d)

Next Generation Firewall