wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DUMSA_1.1

Total questions: 61

Worksheet time: 31mins

Name
Class
Date
1.

Which is a suitable command to check whether Drop Templates are activated or not?

a)

fw ctl get int activate_drop_templates

b)

fwaccel stat

c)

fwaccel stats

d)

fw ctl templates -d

2.

Please choose correct command syntax to add an “emailserver1” host with IP address 10.50.23.90 using GAiA management CLI.

a)

hostname myHost12 ip-address 10.50.23.90

b)

mgmt add host name ip-address 10.50.23.90

c)

add host name emailserver1 ip-address 10.50.23.90

d)

mgmt add host name emailserver1 ip-address 10.50.23.90

3.

The CDT utility supports which of the following?

a)

Major version upgrades to R77.30

b)

Only Jumbo HFA’s and hotfixes

c)

Only major version upgrades to R80.10

d)

All upgrades

4.

Using ClusterXL, what statement is true about the Sticky Decision Function?

a)

Can only be changed for Load Sharing implementations

b)

All connections are processed and synchronized by the pivot

c)

Is configured using cpconfig

d)

Is only relevant when using SecureXL

5.

What command would show the API server status?

a)

cpm status

b)

api restart

c)

api status

d)

show api status

6.

How Capsule Connect and Capsule Workspace differ?

a)

Capsule Connect provides a Layer3 VPN. Capsule Workspace provides a Desktop with usable applications

b)

Capsule Workspace can provide access to any application

c)

Capsule Connect provides Business data isolation

d)

Capsule Connect does not require an installed application at client

7.

Which of the following is a new R80.10 Gateway feature that had not been available in R77.X and older?

a)

The rule base can be built of layers, each containing a set of the security rules. Layers are inspected in the order in which they are defined, allowing control over the rule base flow and which security functionalities take precedence.

b)

Limits the upload and download throughput for streaming media in the company to 1 Gbps.

c)

Time object to a rule to make the rule active only during specified times.

d)

Sub Policies are sets of rules that can be created and attached to specific rules. If the rule is matched, inspection will continue in the sub policy attached to it rather than in the next rule.

8.

What are the three components for Check Point Capsule?

a)

Capsule Docs, Capsule Cloud, Capsule Connect

b)

Capsule Workspace, Capsule Cloud, Capsule Connect

c)

Capsule Workspace, Capsule Docs, Capsule Connect

d)

Capsule Workspace, Capsule Docs, Capsule Cloud

9.

Full synchronization between cluster members is handled by Firewall Kernel. Which port is used for this?

a)

UDP port 265

b)

TCP port 265

c)

UDP port 256

d)

TCP port 256

10.

What is true about the IPS-Blade?

a)

in R80, IPS is managed by the Threat Prevention Policy

b)

in R80, in the IPS Layer, the only three possible actions are Basic, Optimized and Strict

c)

in R80, IPS Exceptions cannot be attached to “all rules”

d)

in R80, the GeoPolicy Exceptions and the Threat Prevention Exceptions are the same

11.

Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?

a)

Go to clsh-Run cpstop | Run cpstart

b)

Go to clsh-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway

12.

When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition?

a)

Any size

b)

Less than 20GB

c)

More than 10GB and less than 20 GB

d)

At least 20GB

13.

Which firewall daemon is responsible for the FW CLI commands?

a)

fwd

b)

fwm

c)

cpm

d)

cpd

14.

If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed?

a)

Rename the hostname of the Standby member to match exactly the hostname of the Active member.

b)

Change the Standby Security Management Server to Active.

c)

Change the Active Security Management Server to Standby.

d)

Manually synchronize the Active and Standby Security Management Servers.

15.

Using R80 Smart Console, what does a "pencil icon" in a rule mean?

a)

I have changed this rule

b)

Someone else has changed this rule

c)

This rule is managed by Check Point’s SOC

d)

This rule can’t be changed as it’s an implied rule

16.

Which method below is NOT one of the ways to communicate using the Management APIs?

a)

Typing API commands using the "mgmt_cli" command

b)

Typing API commands from a dialog box inside the SmartConsole GUI application

c)

Typing API commands using Gaia’s secure shell (clish)

d)

Sending API commands over an http connection using web-services

17.

Session unique identifiers are passed to the web API using which HTTP header option?

a)

X-chkp-sid

b)

Accept-Charset

c)

Proxy-Authorization

d)

Application

18.

What is the main difference between Threat Extraction and Threat Emulation?

a)

Threat Emulation never delivers a file and takes more than 3 minutes to complete

b)

Threat Extraction always delivers a file and takes less than a second to complete

c)

Threat Emulation never delivers a file that takes less than a second to complete

d)

Threat Extraction never delivers a file and takes more than 3 minutes to complete

19.

Which one of these features is NOT associated with the Check Point URL Filtering and Application Control Blade?

a)

Detects and blocks malware by correlating multiple detection engines before users are affected.

b)

Configure rules to limit the available network bandwidth for specified users or groups.

c)

Use UserCheck to help users understand that certain websites are against the company’s security policy.

d)

Make rules to allow or block applications and Internet sites for individual applications, categories, and risk levels.

20.

You want to store the GAiA configuration in a file for later reference. What command should you use?

a)

write mem

b)

show config -f

c)

save config -o

d)

save configuration

21.

Traffic from source 192.168.1.1 is going to www.google.com. The Application Control Blade on the gateway is inspecting the traffic. Assuming acceleration is enabled, which path is handling the traffic?

a)

Slow Path

b)

Medium Path

c)

Fast Path

d)

Accelerated Path

22.

From SecureXL perspective, what are the three paths of traffic flow?

a)

Initial Path; Medium Path; Accelerated Path

b)

Layer Path; Blade Path; Rule Path

c)

Firewall Path; Accept Path; Drop Path

d)

Firewall Path; Accelerated Path; Medium Path

23.

You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?

a)

fwd

b)

fwm

c)

cpd

d)

cpwd

24.

R80.10 management server can manage gateways with which versions installed?

a)

Versions R77 and higher

b)

Versions R76 and higher

c)

Versions R75.20 and higher

d)

Version R75 and higher

25.

You want to verify if there are unsaved changes in GAiA that will be lost with a reboot. What command can be used?

a)

show unsaved

b)

show save-state

c)

show configuration diff

d)

show config-state

26.

In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?

a)

SND is a feature to accelerate multiple SSL VPN connections

b)

SND is an alternative to IPSec Main Mode, using only 3 packets

c)

SND is used to distribute packets among Firewall instances

d)

SND is a feature of fw monitor to capture accelerated packets

27.

Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.

a)

Symmetric routing

b)

Failovers

c)

Asymmetric routing

d)

Anti-Spoofing

28.

What are the steps to configure the HTTPS Inspection Policy?

a)

Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard

b)

Go to Application&url filtering blade > Advanced > Https Inspection > Policy

c)

Go to Manage&Settings > Blades > HTTPS Inspection > Policy

d)

Go to Application&url filtering blade > Https Inspection > Policy

29.

What is the difference between SSL VPN and IPSec VPN?

a)

IPSec VPN does not require installation of a resident VPN client

b)

SSL VPN requires installation of a resident VPN client

c)

SSL VPN and IPSec VPN are the same

d)

IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser

30.

Which statement is NOT TRUE about Delta synchronization?

a)

Using UDP Multicast or Broadcast on port 8161

b)

Using UDP Multicast or Broadcast on port 8116

c)

Quicker than Full sync

d)

Transfers changes in the Kernel tables between cluster members

31.

Under which file is the proxy arp configuration stored?

a)

$FWDIR/state/proxy_arp.conf on the management server

b)

$FWDIR/conf/local.arp on the management server

c)

$FWDIR/state/_tmp/proxy.arp on the security gateway

d)

$FWDIR/conf/local.arp on the gateway

32.

Customer’s R80 management server needs to be upgraded to R80.10. What is the best upgrade method when the management server is not connected to the Internet?

a)

Export R80 configuration, clean install R80.10 and import the configuration

b)

CPUSE online upgrade

c)

CPUSE offline upgrade

d)

SmartUpdate upgrade

33.

SmartEvent does NOT use which of the following procedures to identity events:

a)

Matching a log against each event definition

b)

Create an event candidate

c)

Matching a log against local exclusions

d)

Matching a log against global exclusions

34.

John is using Management HA. Which Smartcenter should be connected to for making changes?

a)

secondary Smartcenter

b)

active Smartcenter

c)

connect virtual IP of Smartcenter HA

d)

primary Smartcenter

35.

Which path below is available only when CoreXL is enabled?

a)

Slow path

b)

Firewall path

c)

Medium path

d)

Accelerated path

36.

Which of the following describes how Threat Extraction functions?

a)

Detect threats and provides a detailed report of discovered threats

b)

Proactively detects threats

c)

Delivers file with original content

d)

Delivers PDF versions of original files with active content removed

37.

The SmartEvent R80 Web application for real-time event monitoring is called:

a)

SmartView Monitor

b)

SmartEventWeb

c)

There is no Web application for SmartEvent

d)

SmartView

38.

SandBlast offers flexibility in implementation based on their individual business needs. What is an option for deployment of Check Point SandBlast Zero-Day Protection?

a)

Smart Cloud Services

b)

Load Sharing Mode Services

c)

Threat Agent Solution

d)

Public Cloud Services

39.

What SmartEvent component creates events?

a)

Consolidation Policy

b)

Correlation Unit

c)

SmartEvent Policy

d)

SmartEvent GUI

40.

Which Threat Prevention Profile is not included by default in R80 Management?

a)

Basic – Provides reliable protection on a range of non-HTTP protocols for servers, with minimal impact on network performance

b)

Optimized – Provides excellent protection for common network products and protocols against recent or popular attacks

c)

Strict – Provides a wide coverage for all products and protocols, with impact on network performance

d)

Recommended – Provides all protection for all common network products and servers, with impact on network performance

41.

When using Monitored circuit VRRP, what is a priority delta?

a)

When an interface fails the priority changes to the priority delta

b)

When an interface fails the delta claims the priority

c)

When an interface fails the priority delta is subtracted from the priority

d)

When an interface fails the priority delta decides if the other interfaces takes over

42.

Which of the following is NOT an option to calculate the traffic direction?

a)

Incoming

b)

Internal

c)

External

d)

Outgoing

43.

When an encrypted packet is decrypted, where does this happen?

a)

Security policy

b)

Inbound chain

c)

Outbound chain

d)

Decryption is not supported

44.

Which of the following is NOT a component of Check Point Capsule?

a)

Capsule Docs

b)

Capsule Cloud

c)

Capsule Enterprise

d)

Capsule Workspace

45.

You have successfully backed up your Check Point configurations without the OS information. What command would you use to restore this backup?

a)

restore_backup

b)

import backup

c)

cp_merge

d)

migrate import

46.

What is the best sync method in the ClusterXL deployment?

a)

Use 1 cluster + 1st sync

b)

Use 1 dedicated sync interface

c)

Use 3 clusters + 1st sync + 2nd sync + 3rd sync

d)

Use 2 clusters + 1st sync + 2nd sync

47.

Can multiple administrators connect to a Security Management Server at the same time?

a)

No, only one can be connected

b)

Yes, all administrators can modify a network object at the same time

c)

Yes, every administrator has their own username, and works in a session that is independent of other administrators

d)

Yes, but only one has the right to write

48.

What Identity Agent allows packet tagging and computer authentication?

a)

Endpoint Security Client

b)

Full Agent

c)

Light Agent

d)

System Agent

49.

In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Which of the following options can you add to each Log, Detailed Log and Extended Log?

a)

Accounting

b)

Suppression

c)

Accounting/Suppression

d)

Accounting/Extended

50.

You noticed that CPU cores on the Security Gateway are usually 100% utilized and many packets were dropped. You don't have a budget to perform a hardware upgrade at this time. To optimize drops you decide to use Priority Queues and fully enable Dynamic Dispatcher. How can you enable them?

a)

fw ctl multik dynamic_dispatching on

b)

fw ctl multik dynamic_dispatching set_mode 9

c)

fw ctl multik set_mode 9

d)

fw ctl multik pq enable

51.

Which two of these Check Point Protocols are used by ?

a)

ELA and CPD

b)

FWD and LEA

c)

FWD and CPLOG

d)

ELA and CPLOG

52.

To ensure that VMAC mode is enabled, which CLI command you should run on all cluster members? Choose the best answer.

a)

fw ctl set int fwha vmac global param enabled

b)

fw ctl get int fwha vmac global param enabled; result of command should return value 1

c)

cphaprob -a if

d)

fw ctl get int fwha_vmac_global_param_enabled; result of command should return value 1

53.

What is the SOLR database for?

a)

Used for full text search and enables powerful matching capabilities

b)

Writes data to the database and full text search

c)

Serves GUI responsible to transfer request to the DLE server

d)

Enables powerful matching capabilities and writes data to the database

54.

Which of the following commands is used to monitor cluster members?

a)

cphaprob state

b)

cphaprob status

c)

cphaprob

d)

cluster state

55.

Fill in the blank: Service blades must be attached to a ____________.

a)

Security Gateway

b)

Management container

c)

Management server

d)

Security Gateway container

56.

Fill in the blank: An LDAP server holds one or more ____________.

a)

Server Units

b)

Administrator Units

c)

Account Units

d)

Account Servers

57.

Fill in the blank: In Security Gateways R75 and above, SIC uses ____________ for encryption.

a)

AES-128

b)

AES-256

c)

DES

d)

3DES

58.

What protocol is specifically used for clustered environments?

a)

Clustered Protocol

b)

Synchronized Cluster Protocol

c)

Control Cluster Protocol

d)

Cluster Control Protocol

59.

Which of the following is NOT a tracking option? Select three.

a)

Partial log

b)

Log

c)

Network log

d)

Full log

60.

Which command shows the installed licenses?

a)

cplic print

b)

print cplic

c)

fwllic print

d)

show licenses

61.

Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?

a)

SmartManager

b)

SmartConsole

c)

Security Gateway

d)

Security Management Server