NEW
Font size
WorksheetsDUMSA_3.1
Total questions: 57
Worksheet time: 29mins
What are the advantages of a “shared policy” in R80?
Allows the administrator to share a policy between all the users identified by the Security Gateway
Allows the administrator to share a policy between all the administrators managing the Security Management Server
Allows the administrator to share a policy so that it is available to use in another Policy Package
Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway
To view statistics on detected threats, which Threat Tool would an administrator use?
Protections
IPS Protections
Profiles
ThreatWiki
What is the purpose of a Clean-up Rule?
Clean-up Rules do not serve any purpose.
Provide a metric for determining unnecessary rules.
To drop any traffic that is not explicitly allowed.
Used to better optimize a policy.
What are the two types of NAT supported by the Security Gateway?
Destination and Hide
Hide and Static
Static and Source
Source and Destination
Vanessa is attempting to log into the Gaia Web Portal and is able to log in successfully. Then she tries the same username and password for SmartConsole and gets the message shown in the screenshot. She has checked that the IP address of the Server is correct and the username and password she used to log into Gaia are also correct. What is the most likely reason?
Check Point R80 SmartConsole authentication is more secure than in previous versions and Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.
Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.
SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.
Authentication failed because Vanessa’s username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.
What is the most complete definition of the difference between the Install Policy button on the SmartConsole’s tab, and the Install Policy within a specific policy?
The Global one also saves and published the session before installation.
The Global one can install multiple selected policies at the same time.
The local one does not install the Anti-Malware policy along with the Network policy.
The second one pre-selects the installation for only the current policy and for the applicable gateways.
Which of the following is used to initially create trust between a Gateway and Security Management Server?
Internal Certificate Authority
Token
One-time Password
Certificate
John is the administrator of a R80 Security Management server managing a R77.30 Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John’s changes available to other administrators, and to save the database before installing a policy, what must John do?
Logout of the session
File > Save
Install database
Publish the session
Fill in the blanks: There are ________ types of software containers ________.
Three; security management, Security Gateway, and endpoint security
Three; Security gateway, endpoint security, and gateway management
Two; security management and endpoint security
Two; endpoint security and Security Gateway
In Office mode, a Security Gateway assigns a remote client to an IP address once ________.
the user connects and authenticates
office mode is initiated
the user requests a connection
the user connects
Which Identity Source(s) should be selected in Identity Awareness when there is a requirement for a higher level of security for sensitive servers?
AD Query
Terminal Servers Endpoint Identity Agent
Endpoint Identity Agent and Browser-Based Authentication
RADIUS and Account Logon
Which statement describes what Identity Sharing is in Identity Awareness?
Management servers can acquire and share identities with Security Gateways
Users can share identities with other users
Security Gateways can acquire and share identities with other Security Gateways
Administrators can share identities with other administrators
What is the most recommended installation method for Check Point appliances?
SmartUpdate installation
DVD media created with Check Point ISOMorphic
USB media created with Check Point ISOMorphic
Cloud based installation
Which of the following is NOT a role of the SmartCenter?
Status monitoring
Policy configuration
Certificate authority
Address translation
Which of the following is NOT a valid application navigation tab in the R80 SmartConsole?
Manage and Command Line
Logs and Monitor
Security Policies
Gateway and Servers
Phase 1 of the two-phase negotiation process conducted by IKE operates in ______ mode.
Main
Authentication
Quick
High Alert
What is the BEST method to deploy Identity Awareness for roaming users?
Use Office Mode
Use identity agents
Share user identities between gateways
Use captive portal
What is the purpose of the Clean-up Rule?
To drop any traffic not explicitly allowed and log the event
To allow all traffic as a failsafe when other rules fail
To prioritize cleanup tasks during maintenance windows
To reset the Security Gateway to a default policy state
What is the purpose of the Clean-up Rule?
To log all traffic that is not explicitly allowed or denied in the Rule Base
To clean up policies found inconsistent with the compliance blade reports
To remove all rules that could have a conflict with other rules in the database
To eliminate duplicate log entries in the Security Gateway
Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?
Application Control
Threat Emulation
Anti-Virus
Advanced Networking Blade
Back up and restores can be accomplished through __________.
SmartConsole, WebUI, or CLI
WebUI, CLI, or SmartUpdate
CLI, SmartUpdate, or SmartBackup
SmartUpdate, SmartBackup, or SmartConsole
What does it mean if Deyra sees the gateway status shown in the image? Choose the BEST answer.
SmartCenter Server cannot reach this Security Gateway
There is a blade reporting a problem
VPN software blade is reporting a malfunction
Security Gateway’s MGNT NIC card is disconnected
CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You suspect that the problem might be the Threat Prevention settings. The following Threat Prevention Profile has been created. How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.
Set High Confidence to Low and Low Confidence to Inactive.
Set the Performance Impact to Medium or lower.
The problem is not with the Threat Prevention Profile. Consider adding more memory to the appliance.
Set the Performance Impact to Very Low Confidence to Prevent.
Which icon in the WebUI indicates that read/write access is enabled?
Pencil
Padlock
Book
Eyeglasses
What is NOT an advantage of Stateful Inspection?
High Performance
Good Security
No Screening above Network layer
Transparency
Which of the following Windows Security Events will NOT map a username to an IP address in Identity Awareness?
Kerberos Ticket Renewed
Kerberos Ticket Requested
Account Logon
Kerberos Ticket Timed Out
Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or ________.
On all satellite gateway to satellite gateway tunnels
On specific tunnels for specific gateways
On specific tunnels in the community
On specific satellite gateway to central gateway tunnels
In Unified SmartConsole Gateways and Servers tab you can perform the following functions EXCEPT ________.
Upgrade the software version
Open WebUI
Open SSH
Open service request with Check Point Technical Support
Which Threat Prevention Software Blade provides protection from malicious software that can infect your network computers? (Choose the best answer.)
IPS
Anti-Virus
Anti-Malware
Content Awareness
When configuring Spoof Tracking, which tracking actions can an administrator select to be done when spoofed packets are detected?
Log, send snmp trap, email
Drop packet, alert, none
Log, alert, none
Log, allow packets, email
Access roles allow the firewall administrator to configure network access according to:
remote access clients.
a combination of computer or computer groups and networks.
users and user groups.
All of the above.
What are the three deployment considerations for a secure network?
Distributed, Bridge Mode, and Remote
Bridge Mode, Remote, and Standalone
Remote, Standalone, and Distributed
Standalone, Distributed, and Bridge Mode
Which option, when applied to a rule, allows traffic to VPN gateways in specific VPN communities?
All Connections (Clear or Encrypted)
Accept all encrypted traffic
Specific VPN Communities
All Site-to-Site VPN Communities
When a Security Gateways sends its logs to an IP address other than its own, which deployment option is installed?
Distributed
Standalone
Bridge
One of major features in R80.x SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB, and AdminC are editing the same Security Policy?
AdminC sees a lock icon which indicates that the rule is locked for editing by another administrator.
AdminA and AdminB are editing the same rule at the same time.
AdminB sees a pencil icon next the rule that AdminB is currently editing.
AdminA, AdminB and AdminC are editing three different rules at the same time.
When should you generate new licenses?
Before installing contract files.
After an RMA procedure when the MAC address or serial number of the appliance changes.
When the existing license expires, license is upgraded or the IP-address where the license is tied changes.
Only when the license is upgraded.
Fill in the blank: When a policy package is installed, ________ are also distributed to the target installation Security Gateways.
User and objects databases
Network databases
SmartConsole databases
User databases
Which of the following is NOT a method used by Identity Awareness for acquiring identity?
Remote Access
Cloud IdP (Identity Provider)
Active Directory Query
RADIUS
Which Check Point software blade provides Application Security and identity control?
Identity Awareness
Data Loss Prevention
URL Filtering
Application Control
How are the backups stored in Check Point appliances?
Saved as *.tar under /var/log/CPbackup/backups
Saved as *tgz under /var/CPbackup
Saved as *tar under /var/CPbackup
Saved as *tgz under /var/log/CPbackup/backups
You are going to perform a major upgrade. Which back up solution should you use to ensure your database can be restored on that device?
backup
logswitch
Database Revision
snapshot
Which tool is used to enable ClusterXL?
SmartUpdate
cpconfig
SmartConsole
sysconfig
What type of NAT is a one-to-one relationship where each host is translated to a unique address?
Source
Static
Hide
Destination
Which one of the following is a way that the objects can be manipulated using the new API integration in R80 Management?
Microsoft Publisher
JSON
Microsoft Word
RC4 Encryption
True or False: In a Distributed Environment, a Central License can be installed via CLI on a Security Gateway.
True, CLI is the prefer method for Licensing
False, Central License are handled via Security Management Server
False, Central License are installed via Gaia on Security Gateways
True, Central License can be installed with CPLIC command on a Security Gateway
Which of the following is NOT an identity source used for Identity Awareness?
Remote Access
UserCheck
AD Query
RADIUS
Fill in the blanks: Default port numbers for an LDAP server is _____ for standard connections and ______ SSL connections.
675, 389
389, 636
636, 290
290, 675
Which of the following is NOT supported by Bridge Mode Check Point Security Gateway
Antivirus
Data Loss Prevention
NAT
Application Control
Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?
All Site-to-Site VPN Communities
Accept all encrypted traffic
All Connections (Clear or Encrypted)
Specific VPN Communities
In which scenario is it a valid option to transfer a license from one hardware device to another?
From a 4400 Appliance to a 2200 Appliance
From a 4400 Appliance to an HP Open Server
From an IBM Open Server to an HP Open Server
From an IBM Open Server to a 2200 Appliance
Fill in the blanks: A ____ license requires an administrator to designate a gateway for attachment whereas a _____ license is automatically attached to a Security Gateway.
Formal; corporate
Local; formal
Local; central
Central; local
Which of the following is NOT a valid configuration screen of an Access Role Object?
Users
Networks
Time
Machines
What is the purpose of the Stealth Rule?
To prevent users from directly connecting to a Security Gateway.
To reduce the number of rules in the database.
To reduce the amount of logs for performance issues.
To hide the gateway from the Internet.
What key is used to save the current CPView page in a filename format cpview_ "cpview process ID". cap "number of captures"?
S
W
C
Space bar
Fill in the blank: It is Best Practice to have a ______ rule at the end of each policy layer.
Explicit Drop
Implied Drop
Explicit Cleanup
Implicit Drop
When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?
Access Role
User Group
SmartDirectory Group
Group Template
The ______ software blade package uses CPU-level and OS-level sandboxing in order to detect and block malware.
Next Generation Threat Prevention
Next Generation Threat Emulation
Next Generation Threat Extraction
Next Generation Firewall
