WorksheetsDUMSA_5.1
Total questions: 61
Worksheet time: 31mins
What is the RFC number that act as a best practice guide for NAT?
RFC 1939
RFC 1950
RFC 1918
RFC 793
URL Filtering employs a technology, which educates users on web usage policy in real time. What is the name of that technology?
WebCheck
UserCheck
Harmony Endpoint
URL categorization
Name one limitation of using Security Zones in the network?
Security zones will not work in Automatic NAT rules
Security zone will not work in Manual NAT rules
Security zones will not work in firewall policy layer
Security zones cannot be used in network topology
Choose what BEST describes users on Gaia Platform.
There are two default users and neither can be deleted.
There are two default users and one cannot be deleted.
There is one default user that can be deleted.
There is one default user that cannot be deleted.
Which type of Check Point license ties the package license to the IP address of the Security Management Server?
Central
Corporate
Local
Formal
Which of the following is NOT an advantage to using multiple LDAP servers?
You achieve a faster access time by placing LDAP servers containing the database at remote sites
You achieve compartmentalization by allowing a large number of users to be distributed across several servers
Information on a user is hidden, yet distributed across several servers
You gain High Availability by replicating the same information on several servers
When an Admin logs into SmartConsole and sees a lock icon on a gateway object and cannot edit that object, what does that indicate?
The gateway is not powered on.
Incorrect routing to reach the gateway.
The Admin would need to login to Read-Only mode
Another Admin has made an edit to that object and has yet to publish the change.
In order to modify Security Policies, the administrator can use which of the following tools? (Choose the best answer.)
SmartConsole and WebUI on the Security Management Server.
SmartConsole or mgmt_cli (API) on any computer where SmartConsole is installed.
Command line of the Security Management Server or mgmt_cli.exe on any Windows computer.
mgmt_cli (API) or WebUI on Security Gateway and SmartConsole on the Security Management Server.
A SAM rule is implemented to provide what function or benefit?
Allow security audits.
Handle traffic as defined in the policy.
Monitor sequence activity.
Block suspicious activity.
Is it possible to have more than one administrator connected to a Security Management Server at once?
Yes, but only if all connected administrators connect with read-only permissions.
Yes, but objects edited by one administrator will be locked for editing by others until the session is published.
No, only one administrator at a time can connect to a Security Management Server
Yes, but only one of those administrators will have write-permissions. All others will have read-only permission.
In order to see real-time and historical graph views of Security Gateway statistics in SmartView Monitor, what feature needs to be enabled on the Security Gateway?
Logging & Monitoring
None - the data is available by default
Monitoring Blade
SNMP
What is the default shell for the command line interface?
Clish
Admin
Normal
Expert
When configuring Anti-Spoofing, which tracking options can an Administrator select?
Log, Alert, None
Log, Allow Packets, Email
Drop Packet, Alert, None
Log, Send SNMP Trap, Email
Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?
src:192.168.1.1 OR dst:172.26.1.1 AND action:Drop
src:192.168.1.1 AND dst:172.26.1.1 AND action:Drop
192.168.1.1 AND 172.26.1.1 AND drop
192.168.1.1 OR 172.26.1.1 AND action:Drop
Core Protections are installed as part of what Policy?
Access Control Policy
Desktop Firewall Policy
Mobile Access Policy
Threat Prevention Policy
In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?
"Inspect", "Bypass"
"Inspect", "Bypass", "Categorize"
"Inspect", "Bypass", "Block"
"Detect", "Bypass"
Fill in the blank: Browser-based Authentication sends users to a web page to acquire identities using ____________.
Captive Portal and Transparent Kerberos Authentication
UserCheck
User Directory
Captive Portal
With URL Filtering, what portion of the traffic is sent to the Check Point Online Web Service for analysis?
The complete communication is sent for inspection.
The IP address of the source machine.
The end user credentials.
The host portion of the URL.
Choose what BEST describes the reason why querying logs now are very fast.
The amount of logs being stored is less than previous versions.
New Smart-1 appliances double the physical memory install.
Indexing Engine indexes logs for faster search results.
SmartConsole now queries results directly from the Security Gateway.
Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?
Centos Linux
Gaia embedded
Gaia
Red Hat Enterprise Linux version 5
Which application is used for the central management and deployment of licenses and packages?
SmartProvisioning
SmartLicense
SmartUpdate
Which Check Point software blade prevents malicious files from entering a network using virus signatures and anomaly-based protections from ThreatCloud?
Firewall
Application Control
Anti-spam and Email Security
Anti-Virus
Why is a Central License the preferred and recommended method of licensing?
Central Licensing is actually not supported with Gaia.
Central Licensing is the only option when deploying Gaia
Central Licensing ties to the IP address of a gateway and can be changed to any gateway if needed.
Central Licensing ties to the IP address of the management server and is not dependent on the IP of any gateway in the event it changes.
What default layers are included when creating a new policy layer?
Application Control, URL Filtering and Threat Prevention
Access Control, Threat Prevention and HTTPS Inspection
Firewall, Application Control and IPSec VPN
Firewall, Application Control and IPS
After a new Log Server is added to the environment and the SIC trust has been established with the SMS what will the gateways do?
The gateways can only send logs to an SMS and cannot send logs to a Log Server. Log Servers are proprietary log archive servers.
Gateways will send new firewall logs to the new Log Server as soon as the SIC trust is set up between the SMS and the new Log Server.
The firewalls will detect the new Log Server after the next policy install and redirect the new logs to the new Log Server.
Logs are not automatically forwarded to a new Log Server. SmartConsole must be used to manually configure each gateway to send its logs to the server.
Name the utility that is used to block activities that appear to be suspicious.
Penalty Box
Drop Rule in the rulebase
Suspicious Activity Monitoring (SAM)
Stealth rule
When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?
The URL and server certificate are sent to the Check Point Online Web Service
The full URL, including page data, is sent to the Check Point Online Web Service
The host part of the URL is sent to the Check Point Online Web Service
The URL and IP address are sent to the Check Point Online Web Service
Name the pre-defined Roles included in Gaia OS.
AdminRole, and MonitorRole
ReadWriteRole, and ReadOnly Role
AdminRole, cloningAdminRole, and Monitor Role
AdminRole
Gaia has two default user accounts that cannot be deleted. What are those user accounts?
Admin and Default
Expert and Clish
Control and Monitor
Admin and Monitor
Which single Security Blade can be turned on to block both malicious files from being downloaded as well as block websites known to host malware?
Anti-Bot
None - both Anti-Virus and Anti-Bot are required for this
Anti-Virus
None - both URL Filtering and Anti-Virus are required for this
Log query results can be exported to what file format?
Word Document (docx)
Comma Separated Value (csv)
Portable Document Format (pdf)
Text (txt)
There are four policy types available for each policy package. What are those policy types?
Access Control, Threat Prevention, Mobile Access and HTTPS Inspection
Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection
There are only three policy types: Access Control, Threat Prevention and NAT.
Access Control, Threat Prevention, NAT and HTTPS Inspection
Which tool allows for the automatic updating of the Gaia OS and Check Point products installed on the Gaia OS?
CPASE - Check Point Automatic Service Engine
CPAUE - Check Point Automatic Update Engine
CPDAS - Check Point Deployment Agent Service
CPUSE - Check Point Upgrade Service Engine
The purpose of the Communication Initialization process is to establish a trust between the Security Management Server and the Check Point gateways. Which statement best describes this Secure Internal Communication (SIC)?
After successful initialization, the gateway can communicate with any Check Point node that possesses a SIC certificate signed by the same ICA.
Secure Internal Communications authenticates the security gateway to the SMS before http communications are allowed.
A SIC certificate is automatically generated on the gateway because the gateway hosts a subordinate CA to the SMS ICA.
New firewalls can easily establish the trust by using the expert password defined on the SMS and the SMS IP address.
What are the types of Software Containers?
Smart Console, Security Management, and Security Gateway
Security Management, Security Gateway, and Endpoint Security
Security Management, Log & Monitoring, and Security Policy
Security Management, Standalone, and Security Gateway
Stateful Inspection compiles and registers connections where?
Connection Cache
State Cache
State Table
Network Table
Security Zones do no work with what type of defined rule?
Application Control rule
Manual NAT rule
IPS bypass rule
Firewall rule
Most Check Point deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?
Enterprise Network Security Appliances
Rugged Appliances
Scalable Platforms
Small Business and Branch Office Appliances
URL Filtering cannot be used to:
Control Bandwidth issues
Control Data Security
Improve organizational security
Decrease legal liability
Which SmartConsole application shows correlated logs and aggregated data to provide an overview of potential threats and attack patterns?
SmartEvent
SmartView Tracker
SmartLog
SmartView Monitor
Which of the following is used to extract state related information from packets and store that information in state tables?
STATE Engine
TRACK Engine
RECORD Engine
INSPECT Engine
Which part of SmartConsole allows administrators to add, edit, delete, and clone objects?
Object Browser
Object Editor
Object Navigator
Object Explorer
How do logs change when the "Accounting" tracking option is enabled on a traffic rule?
Involved traffic logs will be forwarded to a log server.
Provides log details view email to the Administrator.
Involved traffic logs are updated every 10 minutes to show how much data has passed on the connection.
Provides additional information to the connected user.
Which of these is NOT a feature or benefit of Application Control?
Eliminate unknown and unwanted applications in your network to reduce IT complexity and application risk.
Identify and control which applications are in your IT environment and which to add to the IT environment.
Scans the content of files being downloaded by users in order to make policy decisions.
Automatically identify trusted software that has authorization to run
What is the purpose of Captive Portal?
It manages user permission in SmartConsole
It provides remote access to SmartConsole
It authenticates users, allowing them access to the Internet and corporate resources
It authenticates users, allowing them access to the Gaia OS
Which type of Check Point license is tied to the IP address of a specific Security Gateway and cannot be transferred to a gateway that has a different IP address?
Formal
Central
Corporate
Local
Which of the following is NOT supported by Bridge Mode on the Check Point Security Gateway?
Data Loss Prevention
Antivirus
Application Control
NAT
True or False: More than one administrator can log into the Security Management Server with SmartConsole with write permission at the same time.
True, every administrator works on a different database that is independent of the other administrators
False, this feature has to be enabled in the Global Properties.
True, every administrator works in a session that is independent of the other administrators
False, only one administrator can login with write permission
When configuring LDAP with User Directory integration, changes applied to a User Directory template are:
Not reflected for any users unless the local user template is changed.
Not reflected for any users who are using that template.
Reflected for all users who are using that template and if the local user template is changed as well.
Reflected immediately for all users who are using that template.
Which Threat Prevention profile uses sanitization technology?
Cloud/data Center
perimeter
Sandbox
Guest Network
The competition between stateful inspection and proxies was based on performance, protocol support, and security. Considering stateful inspections and proxies, which statement is correct?
Stateful Inspection is limited to Layer 3 visibility, with no Layer 4 to Layer 7 visibility capabilities.
When it comes to performance, proxies were significantly faster than stateful inspection firewalls.
Proxies offer far more security because of being able to give visibility of the payload (the data).
When it comes to performance, stateful inspection was significantly faster than proxies.
What are the Threat Prevention software components available on the Check Point Security Gateway?
IPS, Threat Emulation and Threat Extraction
IPS, Anti-Bot, Anti-Virus, SandBlast and Macro Extraction
IPS, Anti-Bot, Anti-Virus, Threat Emulation and Threat Extraction
IDS, Forensics, Anti-Virus, Sandboxing
You have enabled Extended Log as a tracking option to a security rule. However, you are still not seeing any data type information. What is the MOST likely reason?
Identity Awareness is not enabled.
Log Trimming is enabled.
Logging has disk space issues.
Content Awareness is not enabled.
Identity Awareness allows easy configuration for network access and auditing based on what three items?
Client machine IP address.
Network location, the identity of a user and the identity of a machine.
Log server IP address.
Gateway proxy IP address.
What are the three deployment options available for a security gateway?
Standalone, Distributed, and Bridge Mode
Bridge Mode, Remote, and Standalone
Remote, Standalone, and Distributed
Distributed, Bridge Mode, and Remote
In which scenario will an administrator need to manually define Proxy ARP?
When they configure an Automatic Static NAT which translates to an IP address that does not belong to one of the firewall's interfaces.
When they configure an Automatic Hide NAT which translates to an IP address that does not belong to one of the firewall's interfaces.
When they configure a Manual Static NAT which translates to an IP address that does not belong to one of the firewall's interfaces.
When they configure a Manual Hide NAT which translates to an IP address that belongs to one of the firewall's interfaces.
Which of the following is NOT a component of a Distinguished Name?
Common Name
Country
User container
Organizational Unit
A network administrator has informed you that they have identified a malicious host on the network, and instructed you to block it. Corporate policy dictates that firewall policy changes cannot be made at this time. What tool can you use to block this traffic?
Anti-Bot protection
Anti-Malware protection
Policy-based routing
Suspicious Activity Monitoring (SAM) rules
What command from the CLI would be used to view current licensing?
license view
fw ctl tab -t license -s
show license -s
cplic print
In a Distributed deployment, the Security Gateway and the Security Management software are installed on what platforms?
Different computers or appliances.
The same computer or appliance.
Both on virtual machines or both on appliances but not mixed.
In Azure and AWS cloud environments.
Which of the following licenses are considered temporary?
Plug-and-play (Trial) and Evaluation
Perpetual and Trial
Evaluation and Subscription
Subscription and Perpetual
