wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

DUMSA_3.1

Total questions: 57

Worksheet time: 29mins

Name
Class
Date
1.

What are the advantages of a “shared policy” in R80?

a)

Allows the administrator to share a policy between all the users identified by the Security Gateway

b)

Allows the administrator to share a policy between all the administrators managing the Security Management Server

c)

Allows the administrator to share a policy so that it is available to use in another Policy Package

d)

Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway

2.

To view statistics on detected threats, which Threat Tool would an administrator use?

a)

Protections

b)

IPS Protections

c)

Profiles

d)

ThreatWiki

3.

What is the purpose of a Clean-up Rule?

a)

Clean-up Rules do not serve any purpose.

b)

Provide a metric for determining unnecessary rules.

c)

To drop any traffic that is not explicitly allowed.

d)

Used to better optimize a policy.

4.

What are the two types of NAT supported by the Security Gateway?

a)

Destination and Hide

b)

Hide and Static

c)

Static and Source

d)

Source and Destination

5.

Vanessa is attempting to log into the Gaia Web Portal and is able to log in successfully. Then she tries the same username and password for SmartConsole and gets the message shown in the screenshot. She has checked that the IP address of the Server is correct and the username and password she used to log into Gaia are also correct. What is the most likely reason?

a)

Check Point R80 SmartConsole authentication is more secure than in previous versions and Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.

b)

Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.

c)

SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.

d)

Authentication failed because Vanessa’s username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.

6.

What is the most complete definition of the difference between the Install Policy button on the SmartConsole’s tab, and the Install Policy within a specific policy?

a)

The Global one also saves and published the session before installation.

b)

The Global one can install multiple selected policies at the same time.

c)

The local one does not install the Anti-Malware policy along with the Network policy.

d)

The second one pre-selects the installation for only the current policy and for the applicable gateways.

7.

Which of the following is used to initially create trust between a Gateway and Security Management Server?

a)

Internal Certificate Authority

b)

Token

c)

One-time Password

d)

Certificate

8.

John is the administrator of a R80 Security Management server managing a R77.30 Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators, and to save the database before installing a policy, what must John do?

a)

Logout of the session

b)

File > Save

c)

Install database

d)

Publish the session

9.

Fill in the blanks: There are ________ types of software containers ________.

a)

Three; security management, Security Gateway, and endpoint security

b)

Three; Security gateway, endpoint security, and gateway management

c)

Two; security management and endpoint security

d)

Two; endpoint security and Security Gateway

10.

In Office mode, a Security Gateway assigns a remote client to an IP address once ________.

a)

the user connects and authenticates

b)

office mode is initiated

c)

the user requests a connection

d)

the user connects

11.

Which Identity Source(s) should be selected in Identity Awareness when there is a requirement for a higher level of security for sensitive servers?

a)

AD Query

b)

Terminal Servers Endpoint Identity Agent

c)

Endpoint Identity Agent and Browser-Based Authentication

d)

RADIUS and Account Logon

12.

Which statement describes what Identity Sharing is in Identity Awareness?

a)

Management servers can acquire and share identities with Security Gateways

b)

Users can share identities with other users

c)

Security Gateways can acquire and share identities with other Security Gateways

d)

Administrators can share identities with other administrators

13.

What is the most recommended installation method for Check Point appliances?

a)

SmartUpdate installation

b)

DVD media created with Check Point ISOMorphic

c)

USB media created with Check Point ISOMorphic

d)

Cloud based installation

14.

Which of the following is NOT a role of the SmartCenter?

a)

Status monitoring

b)

Policy configuration

c)

Certificate authority

d)

Address translation

15.

Which of the following is NOT a valid application navigation tab in the R80 SmartConsole?

a)

Manage and Command Line

b)

Logs and Monitor

c)

Security Policies

d)

Gateway and Servers

16.

Phase 1 of the two-phase negotiation process conducted by IKE operates in ______ mode.

a)

Main

b)

Authentication

c)

Quick

d)

High Alert

17.

What is the BEST method to deploy Identity Awareness for roaming users?

a)

Use Office Mode

b)

Use identity agents

c)

Share user identities between gateways

d)

Use captive portal

18.

What is the purpose of the Clean-up Rule?

a)

To drop any traffic not explicitly allowed and log the event

b)

To allow all traffic as a failsafe when other rules fail

c)

To prioritize cleanup tasks during maintenance windows

d)

To reset the Security Gateway to a default policy state

19.

What is the purpose of the Clean-up Rule?

a)

To log all traffic that is not explicitly allowed or denied in the Rule Base

b)

To clean up policies found inconsistent with the compliance blade reports

c)

To remove all rules that could have a conflict with other rules in the database

d)

To eliminate duplicate log entries in the Security Gateway

20.

Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?

a)

Application Control

b)

Threat Emulation

c)

Anti-Virus

d)

Advanced Networking Blade

21.

Back up and restores can be accomplished through __________.

a)

SmartConsole, WebUI, or CLI

b)

WebUI, CLI, or SmartUpdate

c)

CLI, SmartUpdate, or SmartBackup

d)

SmartUpdate, SmartBackup, or SmartConsole

22.

What does it mean if Deyra sees the gateway status shown in the image? Choose the BEST answer.

a)

SmartCenter Server cannot reach this Security Gateway

b)

There is a blade reporting a problem

c)

VPN software blade is reporting a malfunction

d)

Security Gateway’s MGNT NIC card is disconnected

23.

CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You suspect that the problem might be the Threat Prevention settings. The following Threat Prevention Profile has been created. How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.

a)

Set High Confidence to Low and Low Confidence to Inactive.

b)

Set the Performance Impact to Medium or lower.

c)

The problem is not with the Threat Prevention Profile. Consider adding more memory to the appliance.

d)

Set the Performance Impact to Very Low Confidence to Prevent.

24.

Which icon in the WebUI indicates that read/write access is enabled?

a)

Pencil

b)

Padlock

c)

Book

d)

Eyeglasses

25.

What is NOT an advantage of Stateful Inspection?

a)

High Performance

b)

Good Security

c)

No Screening above Network layer

d)

Transparency

26.

Which of the following Windows Security Events will NOT map a username to an IP address in Identity Awareness?

a)

Kerberos Ticket Renewed

b)

Kerberos Ticket Requested

c)

Account Logon

d)

Kerberos Ticket Timed Out

27.

Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or ________.

a)

On all satellite gateway to satellite gateway tunnels

b)

On specific tunnels for specific gateways

c)

On specific tunnels in the community

d)

On specific satellite gateway to central gateway tunnels

28.

In Unified SmartConsole Gateways and Servers tab you can perform the following functions EXCEPT ________.

a)

Upgrade the software version

b)

Open WebUI

c)

Open SSH

d)

Open service request with Check Point Technical Support

29.

Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? (Choose the best answer.)

a)

IPS

b)

Anti-Virus

c)

Anti-Malware

d)

Content Awareness

30.

When configuring Spoof Tracking, which tracking actions can an administrator select to be done when spoofed packets are detected?

a)

Log, send snmp trap, email

b)

Drop packet, alert, none

c)

Log, alert, none

d)

Log, allow packets, email

31.

Access roles allow the firewall administrator to configure network access according to:

a)

remote access clients.

b)

a combination of computer or computer groups and networks.

c)

users and user groups.

d)

All of the above.

32.

What are the three deployment considerations for a secure network?

a)

Distributed, Bridge Mode, and Remote

b)

Bridge Mode, Remote, and Standalone

c)

Remote, Standalone, and Distributed

d)

Standalone, Distributed, and Bridge Mode

33.

Which option, when applied to a rule, allows traffic to VPN gateways in specific VPN communities?

a)

All Connections (Clear or Encrypted)

b)

Accept all encrypted traffic

c)

Specific VPN Communities

d)

All Site-to-Site VPN Communities

34.

When a Security Gateways sends its logs to an IP address other than its own, which deployment option is installed?

a)

Distributed

b)

Standalone

c)

Bridge

35.

One of major features in R80.x SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB, and AdminC are editing the same Security Policy?

a)

AdminC sees a lock icon which indicates that the rule is locked for editing by another administrator.

b)

AdminA and AdminB are editing the same rule at the same time.

c)

AdminB sees a pencil icon next the rule that AdminB is currently editing.

d)

AdminA, AdminB and AdminC are editing three different rules at the same time.

36.

When should you generate new licenses?

a)

Before installing contract files.

b)

After an RMA procedure when the MAC address or serial number of the appliance changes.

c)

When the existing license expires, license is upgraded or the IP-address where the license is tied changes.

d)

Only when the license is upgraded.

37.

Fill in the blank: When a policy package is installed, ________ are also distributed to the target installation Security Gateways.

a)

User and objects databases

b)

Network databases

c)

SmartConsole databases

d)

User databases

38.

Which of the following is NOT a method used by Identity Awareness for acquiring identity?

a)

Remote Access

b)

Cloud IdP (Identity Provider)

c)

Active Directory Query

d)

RADIUS

39.

Which Check Point software blade provides Application Security and identity control?

a)

Identity Awareness

b)

Data Loss Prevention

c)

URL Filtering

d)

Application Control

40.

How are the backups stored in Check Point appliances?

a)

Saved as *.tar under /var/log/CPbackup/backups

b)

Saved as *tgz under /var/CPbackup

c)

Saved as *tar under /var/CPbackup

d)

Saved as *tgz under /var/log/CPbackup/backups

41.

You are going to perform a major upgrade. Which back up solution should you use to ensure your database can be restored on that device?

a)

backup

b)

logswitch

c)

Database Revision

d)

snapshot

42.

Which tool is used to enable ClusterXL?

a)

SmartUpdate

b)

cpconfig

c)

SmartConsole

d)

sysconfig

43.

What type of NAT is a one-to-one relationship where each host is translated to a unique address?

a)

Source

b)

Static

c)

Hide

d)

Destination

44.

Which one of the following is a way that the objects can be manipulated using the new API integration in R80 Management?

a)

Microsoft Publisher

b)

JSON

c)

Microsoft Word

d)

RC4 Encryption

45.

True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway.

a)

True, CLI is the prefer method for Licensing

b)

False, Central License are handled via Security Management Server

c)

False, Central License are installed via Gaia on Security Gateways

d)

True, Central License can be installed with CPLIC command on a Security Gateway

46.

Which of the following is NOT an identity source used for Identity Awareness?

a)

Remote Access

b)

UserCheck

c)

AD Query

d)

RADIUS

47.

Fill in the blanks: Default port numbers for an LDAP server is _____ for standard connections and ______ SSL connections.

a)

675, 389

b)

389, 636

c)

636, 290

d)

290, 675

48.

Which of the following is NOT supported by Bridge Mode Check Point Security Gateway

a)

Antivirus

b)

Data Loss Prevention

c)

NAT

d)

Application Control

49.

Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?

a)

All Site-to-Site VPN Communities

b)

Accept all encrypted traffic

c)

All Connections (Clear or Encrypted)

d)

Specific VPN Communities

50.

In which scenario is it a valid option to transfer a license from one hardware device to another?

a)

From a 4400 Appliance to a 2200 Appliance

b)

From a 4400 Appliance to an HP Open Server

c)

From an IBM Open Server to an HP Open Server

d)

From an IBM Open Server to a 2200 Appliance

51.

Fill in the blanks: A ____ license requires an administrator to designate a gateway for attachment whereas a _____ license is automatically attached to a Security Gateway.

a)

Formal; corporate

b)

Local; formal

c)

Local; central

d)

Central; local

52.

Which of the following is NOT a valid configuration screen of an Access Role Object?

a)

Users

b)

Networks

c)

Time

d)

Machines

53.

What is the purpose of the Stealth Rule?

a)

To prevent users from directly connecting to a Security Gateway.

b)

To reduce the number of rules in the database.

c)

To reduce the amount of logs for performance issues.

d)

To hide the gateway from the Internet.

54.

What key is used to save the current CPView page in a filename format cpview_ "cpview process ID". cap "number of captures"?

a)

S

b)

W

c)

C

d)

Space bar

55.

Fill in the blank: It is Best Practice to have a ______ rule at the end of each policy layer.

a)

Explicit Drop

b)

Implied Drop

c)

Explicit Cleanup

d)

Implicit Drop

56.

When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?

a)

Access Role

b)

User Group

c)

SmartDirectory Group

d)

Group Template

57.

The ______ software blade package uses CPU-level and OS-level sandboxing in order to detect and block malware.

a)

Next Generation Threat Prevention

b)

Next Generation Threat Emulation

c)

Next Generation Threat Extraction

d)

Next Generation Firewall