Font size
WorksheetsDUMSA_1.1
Total questions: 61
Worksheet time: 31mins
Which is a suitable command to check whether Drop Templates are activated or not?
fw ctl get int activate_drop_templates
fwaccel stat
fwaccel stats
fw ctl templates -d
Please choose correct command syntax to add an “emailserver1” host with IP address 10.50.23.90 using GAiA management CLI.
hostname myHost12 ip-address 10.50.23.90
mgmt add host name ip-address 10.50.23.90
add host name emailserver1 ip-address 10.50.23.90
mgmt add host name emailserver1 ip-address 10.50.23.90
The CDT utility supports which of the following?
Major version upgrades to R77.30
Only Jumbo HFA’s and hotfixes
Only major version upgrades to R80.10
All upgrades
Using ClusterXL, what statement is true about the Sticky Decision Function?
Can only be changed for Load Sharing implementations
All connections are processed and synchronized by the pivot
Is configured using cpconfig
Is only relevant when using SecureXL
What command would show the API server status?
cpm status
api restart
api status
show api status
How Capsule Connect and Capsule Workspace differ?
Capsule Connect provides a Layer3 VPN. Capsule Workspace provides a Desktop with usable applications
Capsule Workspace can provide access to any application
Capsule Connect provides Business data isolation
Capsule Connect does not require an installed application at client
Which of the following is a new R80.10 Gateway feature that had not been available in R77.X and older?
The rule base can be built of layers, each containing a set of the security rules. Layers are inspected in the order in which they are defined, allowing control over the rule base flow and which security functionalities take precedence.
Limits the upload and download throughput for streaming media in the company to 1 Gbps.
Time object to a rule to make the rule active only during specified times.
Sub Policies are sets of rules that can be created and attached to specific rules. If the rule is matched, inspection will continue in the sub policy attached to it rather than in the next rule.
What are the three components for Check Point Capsule?
Capsule Docs, Capsule Cloud, Capsule Connect
Capsule Workspace, Capsule Cloud, Capsule Connect
Capsule Workspace, Capsule Docs, Capsule Connect
Capsule Workspace, Capsule Docs, Capsule Cloud
Full synchronization between cluster members is handled by Firewall Kernel. Which port is used for this?
UDP port 265
TCP port 265
UDP port 256
TCP port 256
What is true about the IPS-Blade?
in R80, IPS is managed by the Threat Prevention Policy
in R80, in the IPS Layer, the only three possible actions are Basic, Optimized and Strict
in R80, IPS Exceptions cannot be attached to “all rules”
in R80, the GeoPolicy Exceptions and the Threat Prevention Exceptions are the same
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?
Go to clsh-Run cpstop | Run cpstart
Go to clsh-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway
When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition?
Any size
Less than 20GB
More than 10GB and less than 20 GB
At least 20GB
Which firewall daemon is responsible for the FW CLI commands?
fwd
fwm
cpm
cpd
If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed?
Rename the hostname of the Standby member to match exactly the hostname of the Active member.
Change the Standby Security Management Server to Active.
Change the Active Security Management Server to Standby.
Manually synchronize the Active and Standby Security Management Servers.
Using R80 Smart Console, what does a "pencil icon" in a rule mean?
I have changed this rule
Someone else has changed this rule
This rule is managed by Check Point’s SOC
This rule can’t be changed as it’s an implied rule
Which method below is NOT one of the ways to communicate using the Management APIs?
Typing API commands using the "mgmt_cli" command
Typing API commands from a dialog box inside the SmartConsole GUI application
Typing API commands using Gaia’s secure shell (clish)
Sending API commands over an http connection using web-services
Session unique identifiers are passed to the web API using which HTTP header option?
X-chkp-sid
Accept-Charset
Proxy-Authorization
Application
What is the main difference between Threat Extraction and Threat Emulation?
Threat Emulation never delivers a file and takes more than 3 minutes to complete
Threat Extraction always delivers a file and takes less than a second to complete
Threat Emulation never delivers a file that takes less than a second to complete
Threat Extraction never delivers a file and takes more than 3 minutes to complete
Which one of these features is NOT associated with the Check Point URL Filtering and Application Control Blade?
Detects and blocks malware by correlating multiple detection engines before users are affected.
Configure rules to limit the available network bandwidth for specified users or groups.
Use UserCheck to help users understand that certain websites are against the company’s security policy.
Make rules to allow or block applications and Internet sites for individual applications, categories, and risk levels.
You want to store the GAiA configuration in a file for later reference. What command should you use?
write mem
show config -f
save config -o
save configuration
Traffic from source 192.168.1.1 is going to www.google.com. The Application Control Blade on the gateway is inspecting the traffic. Assuming acceleration is enabled, which path is handling the traffic?
Slow Path
Medium Path
Fast Path
Accelerated Path
From SecureXL perspective, what are the three paths of traffic flow?
Initial Path; Medium Path; Accelerated Path
Layer Path; Blade Path; Rule Path
Firewall Path; Accept Path; Drop Path
Firewall Path; Accelerated Path; Medium Path
You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?
fwd
fwm
cpd
cpwd
R80.10 management server can manage gateways with which versions installed?
Versions R77 and higher
Versions R76 and higher
Versions R75.20 and higher
Version R75 and higher
You want to verify if there are unsaved changes in GAiA that will be lost with a reboot. What command can be used?
show unsaved
show save-state
show configuration diff
show config-state
In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?
SND is a feature to accelerate multiple SSL VPN connections
SND is an alternative to IPSec Main Mode, using only 3 packets
SND is used to distribute packets among Firewall instances
SND is a feature of fw monitor to capture accelerated packets
Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.
Symmetric routing
Failovers
Asymmetric routing
Anti-Spoofing
What are the steps to configure the HTTPS Inspection Policy?
Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
Go to Application&url filtering blade > Advanced > Https Inspection > Policy
Go to Manage&Settings > Blades > HTTPS Inspection > Policy
Go to Application&url filtering blade > Https Inspection > Policy
What is the difference between SSL VPN and IPSec VPN?
IPSec VPN does not require installation of a resident VPN client
SSL VPN requires installation of a resident VPN client
SSL VPN and IPSec VPN are the same
IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser
Which statement is NOT TRUE about Delta synchronization?
Using UDP Multicast or Broadcast on port 8161
Using UDP Multicast or Broadcast on port 8116
Quicker than Full sync
Transfers changes in the Kernel tables between cluster members
Under which file is the proxy arp configuration stored?
$FWDIR/state/proxy_arp.conf on the management server
$FWDIR/conf/local.arp on the management server
$FWDIR/state/_tmp/proxy.arp on the security gateway
$FWDIR/conf/local.arp on the gateway
Customer’s R80 management server needs to be upgraded to R80.10. What is the best upgrade method when the management server is not connected to the Internet?
Export R80 configuration, clean install R80.10 and import the configuration
CPUSE online upgrade
CPUSE offline upgrade
SmartUpdate upgrade
SmartEvent does NOT use which of the following procedures to identity events:
Matching a log against each event definition
Create an event candidate
Matching a log against local exclusions
Matching a log against global exclusions
John is using Management HA. Which Smartcenter should be connected to for making changes?
secondary Smartcenter
active Smartcenter
connect virtual IP of Smartcenter HA
primary Smartcenter
Which path below is available only when CoreXL is enabled?
Slow path
Firewall path
Medium path
Accelerated path
Which of the following describes how Threat Extraction functions?
Detect threats and provides a detailed report of discovered threats
Proactively detects threats
Delivers file with original content
Delivers PDF versions of original files with active content removed
The SmartEvent R80 Web application for real-time event monitoring is called:
SmartView Monitor
SmartEventWeb
There is no Web application for SmartEvent
SmartView
SandBlast offers flexibility in implementation based on their individual business needs. What is an option for deployment of Check Point SandBlast Zero-Day Protection?
Smart Cloud Services
Load Sharing Mode Services
Threat Agent Solution
Public Cloud Services
What SmartEvent component creates events?
Consolidation Policy
Correlation Unit
SmartEvent Policy
SmartEvent GUI
Which Threat Prevention Profile is not included by default in R80 Management?
Basic – Provides reliable protection on a range of non-HTTP protocols for servers, with minimal impact on network performance
Optimized – Provides excellent protection for common network products and protocols against recent or popular attacks
Strict – Provides a wide coverage for all products and protocols, with impact on network performance
Recommended – Provides all protection for all common network products and servers, with impact on network performance
When using Monitored circuit VRRP, what is a priority delta?
When an interface fails the priority changes to the priority delta
When an interface fails the delta claims the priority
When an interface fails the priority delta is subtracted from the priority
When an interface fails the priority delta decides if the other interfaces takes over
Which of the following is NOT an option to calculate the traffic direction?
Incoming
Internal
External
Outgoing
When an encrypted packet is decrypted, where does this happen?
Security policy
Inbound chain
Outbound chain
Decryption is not supported
Which of the following is NOT a component of Check Point Capsule?
Capsule Docs
Capsule Cloud
Capsule Enterprise
Capsule Workspace
You have successfully backed up your Check Point configurations without the OS information. What command would you use to restore this backup?
restore_backup
import backup
cp_merge
migrate import
What is the best sync method in the ClusterXL deployment?
Use 1 cluster + 1st sync
Use 1 dedicated sync interface
Use 3 clusters + 1st sync + 2nd sync + 3rd sync
Use 2 clusters + 1st sync + 2nd sync
Can multiple administrators connect to a Security Management Server at the same time?
No, only one can be connected
Yes, all administrators can modify a network object at the same time
Yes, every administrator has their own username, and works in a session that is independent of other administrators
Yes, but only one has the right to write
What Identity Agent allows packet tagging and computer authentication?
Endpoint Security Client
Full Agent
Light Agent
System Agent
In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Which of the following options can you add to each Log, Detailed Log and Extended Log?
Accounting
Suppression
Accounting/Suppression
Accounting/Extended
You noticed that CPU cores on the Security Gateway are usually 100% utilized and many packets were dropped. You don't have a budget to perform a hardware upgrade at this time. To optimize drops you decide to use Priority Queues and fully enable Dynamic Dispatcher. How can you enable them?
fw ctl multik dynamic_dispatching on
fw ctl multik dynamic_dispatching set_mode 9
fw ctl multik set_mode 9
fw ctl multik pq enable
Which two of these Check Point Protocols are used by ?
ELA and CPD
FWD and LEA
FWD and CPLOG
ELA and CPLOG
To ensure that VMAC mode is enabled, which CLI command you should run on all cluster members? Choose the best answer.
fw ctl set int fwha vmac global param enabled
fw ctl get int fwha vmac global param enabled; result of command should return value 1
cphaprob -a if
fw ctl get int fwha_vmac_global_param_enabled; result of command should return value 1
What is the SOLR database for?
Used for full text search and enables powerful matching capabilities
Writes data to the database and full text search
Serves GUI responsible to transfer request to the DLE server
Enables powerful matching capabilities and writes data to the database
Which of the following commands is used to monitor cluster members?
cphaprob state
cphaprob status
cphaprob
cluster state
Fill in the blank: Service blades must be attached to a ____________.
Security Gateway
Management container
Management server
Security Gateway container
Fill in the blank: An LDAP server holds one or more ____________.
Server Units
Administrator Units
Account Units
Account Servers
Fill in the blank: In Security Gateways R75 and above, SIC uses ____________ for encryption.
AES-128
AES-256
DES
3DES
What protocol is specifically used for clustered environments?
Clustered Protocol
Synchronized Cluster Protocol
Control Cluster Protocol
Cluster Control Protocol
Which of the following is NOT a tracking option? Select three.
Partial log
Log
Network log
Full log
Which command shows the installed licenses?
cplic print
print cplic
fwllic print
show licenses
Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?
SmartManager
SmartConsole
Security Gateway
Security Management Server
