wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

DUMSA-2.1

Total questions: 55

Worksheet time: 28mins

Name
Class
Date
1.

What is the Transport layer of the TCP/IP model responsible for?

a)

It transports packets as datagrams along different routes to reach their destination.

b)

It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.

c)

It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.

d)

It deals with all aspects of the physical components of network connectivity and connects with different network types.

2.

What needs to be configured if the NAT property ‘Translate destination on client side’ is not enabled in Global properties?

a)

A host route to route to the destination IP

b)

Use the file local.arp to add the ARP entries for NAT to work

c)

Nothing, the Gateway takes care of all details necessary

d)

Enabling ‘Allow bi-directional NAT’ for NAT to work correctly

3.

In the Check Point Security Management Architecture, which component(s) can store logs?

a)

SmartConsole

b)

Security Management Server and Security Gateway

c)

Security Management Server

d)

SmartConsole and Security Management Server

4.

Fill in the blank: In order to install a license, it must first be added to the _____________.

a)

User Center

b)

Package repository

c)

Download Center Web site

d)

License and Contract repository

5.

When logging in for the first time to a Security management Server through SmartConsole, a fingerprint is saved to the:

a)

Security Management Server’s /home/.fgpt file and is available for future SmartConsole authentications.

b)

Windows registry is available for future Security Management Server authentications.

c)

There is no memory used for saving a fingerprint anyway.

d)

SmartConsole cache is available for future Security Management Server authentications.

6.

Fill in the blank: By default, the SIC certificates issued by R80 Management Server are based on the ____________ algorithm.

a)

SHA-256

b)

SHA-200

c)

MD5

d)

SHA-128

7.

Which message indicates IKE Phase 2 has completed successfully?

a)

Quick Mode Complete

b)

Aggressive Mode Complete

c)

Main Mode Complete

d)

IKE Mode Complete

8.

Administrator Dave logs into R80 Management Server to review and makes some rule changes. He notices that there is a padlock sign next to the DNS rule in the Rule Base. What is the possible explanation for this?

a)

DNS Rule is using one of the new feature of R80 where an administrator can mark a rule with the padlock icon to let other administrators know it is important.

b)

Another administrator is logged into the Management and currently editing the DNS Rule.

c)

DNS Rule is a placeholder rule for a rule that existed in the past but was deleted.

d)

This is normal behavior in R80 when there are duplicate rules in the Rule Base.

9.

Fill in the blank: When tunnel test packets no longer invoke a response, SmartView Monitor displays ________ for the given VPN tunnel.

a)

Down

b)

No Response

c)

Inactive

d)

Failed

10.

Which of the following is the most secure means of authentication?

a)

Password

b)

Certificate

c)

Token

d)

Pre-shared secret

11.

What is the BEST command to view configuration details of all interfaces in Gaia CLISH?

a)

ifconfig -a

b)

show interfaces

c)

show interfaces detail

d)

show configuration interface

12.

Fill in the blank: Authentication rules are defined for ____________.

a)

User groups

b)

Users using UserCheck

c)

Individual users

d)

All users in the database

13.

Which tool provides a list of trusted files to the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?

a)

ThreatWiki

b)

Whitelist Files

c)

AppWiki

d)

IPS Protections

14.

Which of the following is an authentication method used for Identity Awareness?

a)

SSL

b)

Captive Portal

c)

PKI

d)

RSA

15.

The SIC Status “Unknown” means

a)

There is connection between the gateway and Security Management Server but it is not trusted.

b)

The secure communication is established.

c)

There is no connection between the gateway and Security Management Server.

d)

The Security Management Server can contact the gateway, but cannot establish SIC.

16.

What is a reason for manual creation of a NAT rule?

a)

In R80 all Network Address Translation is done automatically and there is no need for manually defined NAT-rules.

b)

Network Address Translation of RFC1918-compliant networks is needed to access the Internet.

c)

Network Address Translation is desired for some services, but not for others.

d)

The public IP-address is different from the gateway’s external IP

17.

Which of the following commands is used to verify license installation?

a)

Cplic verify license

b)

Cplic print

c)

Cplic show

d)

Cplic license

18.

To enforce the Security Policy correctly, a Security Gateway requires:

a)

a routing table

b)

awareness of the network topology

c)

a Demilitarized Zone

d)

a Security Policy install

19.

Which configuration element determines which traffic should be encrypted into a VPN tunnel vs. sent in the clear?

a)

The firewall topologies

b)

NAT Rules

c)

The Rule Base

d)

The VPN Domains

20.

You have discovered suspicious activity in your network. What is the BEST immediate action to take?

a)

Isolate the affected systems from the network to contain the activity.

b)

Perform a full network-wide scan before taking any containment steps.

c)

Notify users and continue to monitor without changes until more data is available.

d)

Disable Internet connectivity for the entire organization as a precaution.

21.

Tom has connected to the Management Server remotely using SmartConsole and is in the process of making some Rule Base changes, when he suddenly loses connectivity. Connectivity is restored shortly afterward. What will happen to the changes already made?

a)

Tom will have to reboot his SmartConsole computer, clear the cache, and restore changes.

b)

Tom will have to reboot his SmartConsole computer, and access the Management cache store on that computer, which is only accessible after a reboot.

c)

Tom’s changes will be lost since he lost connectivity and he will have to start again.

d)

Tom’s changes will have been stored on the Management when he reconnects and he will not lose any of his work.

22.

Which GUI tool can be used to view and apply Check Point licenses?

a)

cpconfig

b)

Management Command Line

c)

SmartConsole

d)

SmartUpdate

23.

How would you determine the software version from the CLI?

a)

fw ver

b)

fw stat

c)

fw monitor

d)

cpinfo

24.

In R80 Management, apart from using SmartConsole, objects or rules can also be modified using:

a)

3rd Party integration of CLI and API for Gateways prior to R80.

b)

A complete CLI and API interface using SSH and custom CPCode integration.

c)

3rd Party integration of CLI and API for Management prior to R80.

d)

A complete CLI and API interface for Management with 3rd Party integration.

25.

When connected to the Check Point R80 Management Server using the SmartConsole the first administrator to connect has a lock on:

a)

Only the objects being modified in the Management Database and other administrators can connect to make changes using a special session as long as they all connect from the same LAN network.

b)

The entire Management Database and other administrators can connect to make changes only if the first administrator switches to Read-only.

c)

The entire Management Database and all sessions and other administrators can connect only as Read-only.

d)

Only the objects being modified in his session of the Management Database and other administrators can connect to make changes using different sessions.

26.

Which is NOT an encryption algorithm that can be used in an IPSEC Security Association (Phase 2)?

a)

AES-GCM-256

b)

AES-CBC-256

c)

AES-GCM-128

27.

To create policy for traffic to or from a particular location, use the __________.

a)

DLP shared policy

b)

Geo policy shared policy

c)

Mobile Access software blade

d)

HTTPS inspection

28.

After trust has been established between the Check Point components, what is TRUE about name and IP-address changes?

a)

Security Gateway IP-address cannot be changed without re-establishing the trust

b)

The Security Gateway name cannot be changed in command line without re-establishing trust

c)

The Security Management Server name cannot be changed in SmartConsole without re-establishing trust

d)

The Security Management Server IP-address cannot be changed without re-establishing the trust

29.

Which two Identity Awareness commands are used to support identity sharing?

a)

Policy Decision Point (PDP) and Policy Enforcement Point (PEP)

b)

Policy Enforcement Point (PEP) and Policy Manipulation Point (PMP)

c)

Policy Manipulation Point (PMP) and Policy Activation Point (PAP)

d)

Policy Activation Point (PAP) and Policy Decision Point (PDP)

30.

True or False: In R80, more than one administrator can login to the Security Management Server with write permission at the same time.

a)

False, this feature has to be enabled in the Global Properties.

b)

True, every administrator works in a session that is independent of the other administrators.

c)

True, every administrator works on a different database that is independent of the other administrators.

d)

False, only one administrator can login with write permission.

31.

Which one of the following is TRUE?

a)

Ordered policy is a sub-policy within another policy

b)

One policy can be either inline or ordered, but not both

c)

Inline layer can be defined as a rule action

d)

Pre-R80 Gateways do not support ordered layers

32.

Which deployment adds a Security Gateway to an existing environment without changing IP routing?

a)

Distributed

b)

Bridge Mode

c)

Remote

d)

Standalone

33.

Fill in the blank: An identity server uses a ____________ for user authentication.

a)

Shared secret

b)

Certificate

c)

One-time password

d)

Token

34.

You can see the following graphic. What is presented on it?

a)

Properties of personal .p12 certificate file issued for user John.

b)

Shared secret properties of John’s password.

c)

VPN certificate properties of the John’s gateway.

d)

Expired .p12 certificate properties for user John.

35.

When configuring LDAP User Directory integration, Changes applied to a User Directory template are:

a)

Reflected immediately for all users who are using template.

b)

Not reflected for any users unless the local user template is changed.

c)

Reflected for all users who are using that template and if the local user template is changed as well.

d)

Not reflected for any users who are using that template.

36.

Choose what BEST describes the reason why querying logs now is very fast.

a)

New Smart-1 appliances double the physical memory install

b)

Indexing Engine indexes logs for faster search results

c)

SmartConsole now queries results directly from the Security Gateway

d)

The amount of logs been store is less than the usual in older versions

37.

Check Point ClusterXL Active/Active deployment is used when:

a)

Only when there is Multicast solution set up

b)

There is Load Sharing solution set up

c)

Only when there is Unicast solution set up

d)

There is High Availability solution set up

38.

Which of the following methods can be used to update the trusted log server regarding the policy and configuration changes performed on the Security Management Server?

a)

Save Policy

b)

Install Database

c)

Save session

d)

Install Policy

39.

From the Gaia web interface, which operation cannot be performed on a Security Management Server?

a)

Verify a Security Policy

b)

Open a terminal shell

c)

Add a static route

d)

View Security Management GUI Clients

40.

Which of the following are types of VPN communities?

a)

Pentagon, star, and combination

b)

Star, octagon, and combination

c)

Combined and star

d)

Meshed, star, and combination

41.

What are the three types of UserCheck messages?

a)

inform, ask, and block

b)

block, action, and warn

c)

action, inform, and ask

d)

ask, block, and notify

42.

What two ordered layers make up the Access Control Policy Layer?

a)

URL Filtering and Network

b)

Network and Threat Prevention

c)

Application Control and URL Filtering

d)

Network and Application Control

43.

Which statement is true of anti-spoofing?

a)

Anti-spoofing is not needed when IPS software blade is enabled

b)

It is more secure to create anti-spoofing groups manually

c)

It is best practice to have anti-spoofing groups in sync with the routing table

d)

With dynamic routing enabled, anti-spoofing groups are updated automatically whenever there is a routing change

44.

The position of an implied rule is manipulated in which window?

a)

NAT

b)

Firewall

c)

Global Properties

d)

Object Explorer

45.

How can the changes made by an administrator before publishing the session be seen by a superuser administrator?

a)

By impersonating the administrator with the 'Login as…' option

b)

They cannot be seen

c)

From the SmartView Tracker audit log

d)

From Manage and Settings > Sessions, right click on the session and click 'View Changes…'

46.

Which Check Point software blade monitors Check Point devices and provides a picture of network and security performance?

a)

Application Control

b)

Threat Emulation

c)

Logging and Status

d)

Monitoring

47.

Your internal networks 10.1.1.0/24, 10.2.2.0/24 and 192.168.0.0/16 are behind the Internet Security Gateway. Considering that Layer 2 and Layer 3 setup is correct, what are the steps you will need to do in SmartConsole in order to get the connection working?

a)

1. Define an accept rule in Security Policy. 2. Define Security Gateway to hide all internal networks behind the gateway's external IP. 3. Publish and install the policy.

b)

1. Define an accept rule in Security Policy. 2. Define automatic NAT for each network to NAT the networks behind a public IP. 3. Publish the policy.

c)

1. Define an accept rule in Security Policy. 2. Define automatic NAT for each network to NAT the networks behind a public IP. 3. Publish and install the policy.

d)

1. Define an accept rule in Security Policy. 2. Define Security Gateway to hide all internal networks behind the gateway's external IP. 3. Publish the policy.

48.

True or False: The destination server for Security Gateway logs depends on a Security Management Server configuration.

a)

False, log servers are configured on the Log Server General Properties

b)

True, all Security Gateways will only forward logs with a SmartCenter Server configuration

c)

True, all Security Gateways forward logs automatically to the Security Management Server

d)

False, log servers are enabled on the Security Gateway General Properties

49.

Consider the Global Properties settings shown in the referenced image. The selected option "Accept Domain Name over UDP (Queries)" means:

a)

UDP queries are accepted only through interfaces with external anti‑spoofing topology, and this is applied before the first explicit rule in the Security Policy.

b)

All UDP queries are accepted through all interfaces, and this is applied before the first explicit rule in the Security Policy.

c)

No UDP queries are accepted through any interface, and this is applied before the first explicit rule in the Security Policy.

d)

All UDP queries are accepted only when allowed by the first explicit rule written in the Security Policy.

50.

How is communication between different Check Point components secured in R80? Select the best answer.

a)

By using IPSEC

b)

By using SIC

c)

By using ICA

d)

By using 3DES

51.

Identify the ports to which the Client Authentication daemon listens by default.

a)

259, 900

b)

256, 257

c)

8080, 529

d)

80, 256

52.

What is the purpose of the CPCA process?

a)

Monitoring the status of processes

b)

Sending and receiving logs

c)

Communication between GUI clients and the SmartCenter server

d)

Generating and modifying certificates

53.

The Network Operations Center administrator needs access to Check Point Security devices mostly for troubleshooting purposes. You do not want to give expert‑mode access, but the administrator should still be able to run tcpdump. How can you achieve this requirement?

a)

Add tcpdump to CLISH using the add command; create a new access role; add tcpdump to the role; create a new user with any UID and assign the role to the user.

b)

Add tcpdump to CLISH using the add command; create a new access role; add tcpdump to the role; create a new user with UID 0 and assign the role to the user.

c)

Create a new access role; add expert‑mode access to the role; create a new user with UID 0 and assign the role to the user.

d)

Create a new access role; add expert‑mode access to the role; create a new user with any UID and assign the role to the user.

54.

After initial installation on a Check Point appliance, the Management interface IP address and default gateway are incorrect. Which commands set the IP to 192.168.80.200/24 and the default gateway to 192.168.80.1?

a)

set interface Mgmt ipv4-address 192.168.80.200 mask-length 24; set static-route default nexthop gateway address 192.168.80.1 on; save config

b)

add interface Mgmt ipv4-address 192.168.80.200 255.255.255.0; add static-route 0.0.0.0 0.0.0.0 gw 192.168.80.1 on; save config

c)

set interface Mgmt ipv4-address 192.168.80.200 255.255.255.0; add static-route 0.0.0.0 0.0.0.0 gw 192.168.80.1 on; save config

d)

add interface Mgmt ipv4-address 192.168.80.200 mask-length 24; add static-route default nexthop gateway address 192.168.80.1 on; save config

55.

What Check Point tool is used to automatically update Check Point products for the Gaia OS?

a)

Check Point INSPECT Engine

b)

Check Point Upgrade Service Engine

c)

Check Point Update Engine

d)

Check Point Upgrade Installation Service