NEW
Font size
WorksheetsDUMSA_4.1
Total questions: 62
Worksheet time: 31mins
Fill in the blank: Once a certificate is revoked from the Security GateWay by the Security Management Server, the certificate information is _______.
Sent to the Internal Certificate Authority.
Sent to the Security Administrator.
Stored on the Security Management Server.
Stored on the Certificate Revocation List.
Which type of attack can a firewall NOT prevent?
Network Bandwidth Saturation
Buffer Overflow
SYN Flood
SQL Injection
R80 is supported by which of the following operating systems:
Windows only
Gaia only
Gaia, SecurePlatform, and Windows
SecurePlatform only
What Check Point technologies deny or permit network traffic?
Application Control, DLP
Packet Filtering, Stateful Inspection, Application Layer Firewall
ACL, SandBlast, MPT
IPS, Mobile Threat Protection
How do you manage Gaia?
Through CLI and WebUI
Through CLI only
Through SmartDashboard only
Through CLI, WebUI, and SmartDashboard
What licensing feature is used to verify licenses and activate new licenses added to the License and Contracts repository?
Verification tool
Verification licensing
Automatic licensing
Automatic licensing and Verification tool
The “Hit count” feature allows tracking the number of connections that each rule matches. Will the Hit count feature work independently from logging and track the hits even if the Track option is set to “None”?
No, it will not work independently. Hit Count will be shown only for rules with Track options set as Log or alert
Yes, it will work independently as long as “analyze all rules” tick box is enabled on the Security Gateway
No, it will not work independently because hit count requires all rules to be logged
Yes, it will work independently because when you enable Hit Count, the SMS collects the data from supported Security Gateways
How many layers make up the TCP/IP model?
2
7
6
4
In SmartConsole, objects are used to represent physical and virtual network components and also some logical components. These objects are divided into several categories. Which of the following is NOT an objects category?
Limit
Resource
Custom Application / Site
Network Object
Which of the following is used to enforce changes made to a Rule Base?
Publish database
Save changes
Install policy
Activate policy
What is UserCheck?
Messaging tool used to verify a user’s credentials
Communication tool used to inform a user about a website or application they are trying to access
Administrator tool used to monitor users on their network
Communication tool used to notify an administrator when a new user is created
When doing a Stand-Alone Installation, you would install the Security Management Server with which other Check Point architecture component?
None, Security Management Server would be installed by itself.
SmartConsole
SecureClient
SmartEvent
Fill in the blank: An Endpoint identity agent uses a __________ for user authentication.
Shared secret
Token
Username/password or Kerberos Ticket
Certificate
What is the purpose of a Stealth Rule?
A rule used to hide a server's IP address from the outside world.
A rule that allows administrators to access SmartDashboard from any device.
To drop any traffic destined for the firewall that is not otherwise explicitly allowed.
A rule at the end of your policy to drop any traffic that is not explicitly allowed.
To view the policy installation history for each gateway, which tool would an administrator use?
Revisions
Gateway installations
Installation history
Gateway history
Which SmartConsole tab shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?
Gateway and Servers
Logs and Monitor
Manage Seeting
Security Policies
Which of the following is NOT a valid deployment option for R80?
All-in-one (stand-alone)
Log server
SmartEvent
Multi-domain management server
You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to accept your Terms of Service, and cannot access the Internet. How can you fix this?
Right click Accept in the rule, select "More", and then check "Enable Identity Captive Portal"
On the firewall object, Legacy Authentication screen, check "Enable Identity Captive Portal"
In the Captive Portal screen of Global Properties, check "Enable Identity Captive Portal"
On the Security Management Server object, check the box "Identity Logging"
Identity Awareness allows the Security Administrator to configure network access based on which of the following?
Name of the application, identity of the user, and identity of the machine
Identity of the machine, username, and certificate
Network location, identity of a user, and identity of a machine
Browser-Based Authentication, identity of a user, and network location
Which option will match a connection regardless of its association with a VPN community?
All Site-to-Site VPN Communities
Accept all encrypted traffic
All Connections (Clear or Encrypted)
Specific VPN Communities
Which of the following is NOT a tracking log option in R80.x?
Log
Full Log
Detailed Log
Extended Log
Which information is included in the "Extended Log" tracking option, but is not included in the "Log" tracking option?
file attributes
application information
Where is the “Hit Count” feature enabled or disabled in SmartConsole?
On the Policy Package
On each Security Gateway
On the Policy layer
In Global Properties for the Security Management Server
Which tool is used to enable cluster membership on a Gateway?
SmartUpdate
cpconfig
SmartConsole
sysconfig
Which key is created during Phase 2 of a site-to-site VPN?
Pre-shared secret
Diffie-Hellman Public Key
Symmetrical IPSec key
Diffie-Hellman Private Key
Each cluster, at a minimum, should have at least _________ interfaces.
Five
Two
Three
Four
Examine the sample Rule Base. What will be the result of a verification of the policy from SmartConsole?
No errors or Warnings
Verification Error. Empty Source-List in Rule 5 (Mail Inbound)
Verification Error. Rule 4 (Web Inbound) hides Rule 6 (Webmaster access)
Verification Error. Rule 7 (Clean-Up Rule) hides Implicit Clean-up Rule
You are the Check Point administrator for Alpha Corp. You received a call that one of the users is unable to browse the Internet on their new tablet which is connected to the company wireless, which goes through a Check Point Gateway. How would you review the logs to see what is blocking this traffic?
Open SmartLog and connect remotely to the wireless controller
Open SmartEvent to see why they are being blocked
Open SmartDashboard and review the logs tab
From SmartConsole, go to the Log & Monitor and filter for the IP address of the tablet.
What is a role of Publishing?
The Publish operation sends the modifications made via SmartConsole in the private session and makes them public
The Security Management Server installs the updated policy and the entire database on Security Gateways
The Security Management Server installs the updated session and the entire Rule Base on Security Gateways
Modifies network objects, such as servers, users, services, or IPS profiles, but not the Rule Base
Which software blade enables Access Control policies to accept, drop, or limit web site access based on user, group, and/or machine?
Application Control
Data Awareness
Identity Awareness
Threat Emulation
__________ is the Gaia command that turns the server off.
sysdown
exit
halt
shut-down
Which option in a firewall rule would only match and allow traffic to VPN gateways for one Community in common?
All Connections (Clear or Encrypted)
Accept all encrypted traffic
Specific VPN Communities
All Site-to-Site VPN Communities
Which SmartConsole tab is used to monitor network and security performance?
Manage & Settings
Security Policies
Gateway & Servers
Logs & Monitor
Which of the following is NOT a policy type available for each policy package?
Threat Emulation
Access Control
Desktop Security
Threat Prevention
An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security Management Server (SMS). While configuring the VPN community to specify the pre-shared secret, the administrator did not find a box to input the pre-shared secret. Why does it not allow him to specify the pre-shared secret?
The Gateway is an SMB device
The checkbox “Use only Shared Secret for all external members” is not checked
Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS
Pre-shared secret is already configured in Global Properties
Which of the following technologies extracts detailed information from packets and stores that information in state tables?
INSPECT Engine
Next-Generation Firewall
Packet Filtering
Application Layer Firewall
What object type would you use to grant network access to an LDAP user group?
Access Role
User Group
SmartDirectory Group
Group Template
View the rule below. What does the pen-symbol in the left column mean?
Those rules have been published in the current session.
Rules have been edited by the logged in administrator, but the policy has not been published yet.
Another user has currently locked the rules for editing.
The configuration lock is present. Click the pen symbol in order to gain the lock.
What data MUST be supplied to the SmartConsole System Restore window to restore a backup?
Server, Username, Password, Path, Version
Username, Password, Path, Version
Server, Protocol, Username, Password, Destination Path
Server, Protocol, Username, Password, Path
Which repositories are installed on the Security Management Server by SmartUpdate?
License and Update
Package Repository and Licenses
Update and License & Contract
License & Contract and Package Repository
Which back up method uses the command line to create an image of the OS?
System backup
Save Configuration
Migrate
snapshot
To quickly review when Threat Prevention signatures were last updated, which Threat Tool would an administrator use?
Protections
IPS Protections
Profiles
ThreatWiki
Which of the following is considered to be the more secure and preferred VPN authentication method?
Password
Certificate
When a Security Gateway sends its logs to an IP address other than its own, which deployment option is installed?
Distributed
Standalone
Bridge Mode
Targeted
In ____________ NAT, the ____________ is translated.
Hide; source
Static; source
Simple; source
Hide; destination
An administrator wishes to enable Identity Awareness on the Check Point firewalls. However they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?
AD Query
Browser-Based Authentication
Identity Agents
Terminal Servers Agent
Which of the following situations would not require a new license to be generated and installed?
The Security Gateway is upgraded.
The existing license expires.
The license is upgraded.
The IP address of the Security Management or Security Gateway has changed.
When should you generate new licenses?
Before installing contract files.
After a device upgrade.
When the existing license expires, license is upgraded or the IP-address associated with the license changes.
Only when the license is upgraded.
Which of the following is NOT a valid deployment option for R80?
All-in-one (stand-alone)
CloudGuard
Distributed
Bridge Mode
Which backup utility captures the most information and tends to create the largest archives?
backup
snapshot
Database Revision
migrate export
Which of the following commands is used to monitor cluster members in CLI?
show cluster state
show active cluster
show clusters
show running cluster
When enabling tracking on a rule, what is the default option?
Accounting Log
Extended Log
Log
Detailed Log
Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?
The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.
Licensed Check Point products for the Gaia operating system and the Gaia operating system itself.
The CPUSE engine and the Gaia operating system.
The Gaia operating system only.
Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?
Both License (.lic) and Contract (.xml) files
cp.macro
Contract file (.xml)
license File (.lic)
Can you use the same layer in multiple policies or rulebases?
Yes - a layer can be shared with multiple policies and rules.
No - each layer must be unique.
No - layers cannot be shared or reused, but an identical one can be created.
Yes - but it must be copied and pasted with a different name.
Security Gateway software blades must be attached to what?
Security Gateway
Security Gateway container
Management server
Management container
Which tool allows you to monitor the top bandwidth on smart console?
Logs & Monitoring
Smart Event
Gateways & Severs Tab
SmartView Monitor
A security zone is a group of one or more network interfaces from different centrally managed gateways. What is considered part of the zone?
The zone is based on the network topology and determined according to where the interface leads to.
Security Zones are not supported by Check Point firewalls.
The firewall rule can be configured to include one or more subnets in a zone.
The local directly connected subnet defined by the subnet IP and subnet mask.
When comparing Stateful Inspection and Packet Filtering, what is a benefit that Stateful Inspection offers over Packer Filtering?
Stateful Inspection offers unlimited connections because of virtual memory usage.
Stateful Inspection offers no benefits over Packet Filtering.
Stateful Inspection does not use memory to record the protocol used by the connection.
Only one rule is required for each connection.
Fill in the blanks: Gaia can be configured using ______ the ______.
Command line interface; WebUI
Gaia Interface; GaiaUI
WebUI; Gaia Interface
GaiaUI; command line interface
An administrator can use section titles to more easily navigate between large rule bases. Which of these statements is FALSE?
Section titles are not sent to the gateway side.
These sections are simple visual divisions of the Rule Base and do not hinder the order of rule enforcement.
A Sectional Title can be used to disable multiple rules by disabling only the sectional title.
Sectional Titles do not need to be created in the SmartConsole.
A stateful inspection firewall works by registering connection data and compiling this information. Where is the information stored?
In the system SMEM memory pool.
In State tables.
In the Sessions table.
In a CSV file on the firewall hard drive located in $FWDIR/conf/.
