wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DUMSA_5.1

Total questions: 61

Worksheet time: 31mins

Name
Class
Date
1.

What is the RFC number that act as a best practice guide for NAT?

a)

RFC 1939

b)

RFC 1950

c)

RFC 1918

d)

RFC 793

2.

URL Filtering employs a technology, which educates users on web usage policy in real time. What is the name of that technology?

a)

WebCheck

b)

UserCheck

c)

Harmony Endpoint

d)

URL categorization

3.

Name one limitation of using Security Zones in the network?

a)

Security zones will not work in Automatic NAT rules

b)

Security zone will not work in Manual NAT rules

c)

Security zones will not work in firewall policy layer

d)

Security zones cannot be used in network topology

4.

Choose what BEST describes users on Gaia Platform.

a)

There are two default users and neither can be deleted.

b)

There are two default users and one cannot be deleted.

c)

There is one default user that can be deleted.

d)

There is one default user that cannot be deleted.

5.

Which type of Check Point license ties the package license to the IP address of the Security Management Server?

a)

Central

b)

Corporate

c)

Local

d)

Formal

6.

Which of the following is NOT an advantage to using multiple LDAP servers?

a)

You achieve a faster access time by placing LDAP servers containing the database at remote sites

b)

You achieve compartmentalization by allowing a large number of users to be distributed across several servers

c)

Information on a user is hidden, yet distributed across several servers

d)

You gain High Availability by replicating the same information on several servers

7.

When an Admin logs into SmartConsole and sees a lock icon on a gateway object and cannot edit that object, what does that indicate?

a)

The gateway is not powered on.

b)

Incorrect routing to reach the gateway.

c)

The Admin would need to login to Read-Only mode

d)

Another Admin has made an edit to that object and has yet to publish the change.

8.

In order to modify Security Policies, the administrator can use which of the following tools? (Choose the best answer.)

a)

SmartConsole and WebUI on the Security Management Server.

b)

SmartConsole or mgmt_cli (API) on any computer where SmartConsole is installed.

c)

Command line of the Security Management Server or mgmt_cli.exe on any Windows computer.

d)

mgmt_cli (API) or WebUI on Security Gateway and SmartConsole on the Security Management Server.

9.

A SAM rule is implemented to provide what function or benefit?

a)

Allow security audits.

b)

Handle traffic as defined in the policy.

c)

Monitor sequence activity.

d)

Block suspicious activity.

10.

Is it possible to have more than one administrator connected to a Security Management Server at once?

a)

Yes, but only if all connected administrators connect with read-only permissions.

b)

Yes, but objects edited by one administrator will be locked for editing by others until the session is published.

c)

No, only one administrator at a time can connect to a Security Management Server

d)

Yes, but only one of those administrators will have write-permissions. All others will have read-only permission.

11.

In order to see real-time and historical graph views of Security Gateway statistics in SmartView Monitor, what feature needs to be enabled on the Security Gateway?

a)

Logging & Monitoring

b)

None - the data is available by default

c)

Monitoring Blade

d)

SNMP

12.

What is the default shell for the command line interface?

a)

Clish

b)

Admin

c)

Normal

d)

Expert

13.

When configuring Anti-Spoofing, which tracking options can an Administrator select?

a)

Log, Alert, None

b)

Log, Allow Packets, Email

c)

Drop Packet, Alert, None

d)

Log, Send SNMP Trap, Email

14.

Which of the following log queries would show only dropped packets with source address of 192.168.1.1 and destination address of 172.26.1.1?

a)

src:192.168.1.1 OR dst:172.26.1.1 AND action:Drop

b)

src:192.168.1.1 AND dst:172.26.1.1 AND action:Drop

c)

192.168.1.1 AND 172.26.1.1 AND drop

d)

192.168.1.1 OR 172.26.1.1 AND action:Drop

15.

Core Protections are installed as part of what Policy?

a)

Access Control Policy

b)

Desktop Firewall Policy

c)

Mobile Access Policy

d)

Threat Prevention Policy

16.

In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?

a)

"Inspect", "Bypass"

b)

"Inspect", "Bypass", "Categorize"

c)

"Inspect", "Bypass", "Block"

d)

"Detect", "Bypass"

17.

Fill in the blank: Browser-based Authentication sends users to a web page to acquire identities using ____________.

a)

Captive Portal and Transparent Kerberos Authentication

b)

UserCheck

c)

User Directory

d)

Captive Portal

18.

With URL Filtering, what portion of the traffic is sent to the Check Point Online Web Service for analysis?

a)

The complete communication is sent for inspection.

b)

The IP address of the source machine.

c)

The end user credentials.

d)

The host portion of the URL.

19.

Choose what BEST describes the reason why querying logs now are very fast.

a)

The amount of logs being stored is less than previous versions.

b)

New Smart-1 appliances double the physical memory install.

c)

Indexing Engine indexes logs for faster search results.

d)

SmartConsole now queries results directly from the Security Gateway.

20.

Rugged appliances are small appliances with ruggedized hardware and like Quantum Spark appliance they use which operating system?

a)

Centos Linux

b)

Gaia embedded

c)

Gaia

d)

Red Hat Enterprise Linux version 5

21.

Which application is used for the central management and deployment of licenses and packages?

a)

SmartProvisioning

b)

SmartLicense

c)

SmartUpdate

22.

Which Check Point software blade prevents malicious files from entering a network using virus signatures and anomaly-based protections from ThreatCloud?

a)

Firewall

b)

Application Control

c)

Anti-spam and Email Security

d)

Anti-Virus

23.

Why is a Central License the preferred and recommended method of licensing?

a)

Central Licensing is actually not supported with Gaia.

b)

Central Licensing is the only option when deploying Gaia

c)

Central Licensing ties to the IP address of a gateway and can be changed to any gateway if needed.

d)

Central Licensing ties to the IP address of the management server and is not dependent on the IP of any gateway in the event it changes.

24.

What default layers are included when creating a new policy layer?

a)

Application Control, URL Filtering and Threat Prevention

b)

Access Control, Threat Prevention and HTTPS Inspection

c)

Firewall, Application Control and IPSec VPN

d)

Firewall, Application Control and IPS

25.

After a new Log Server is added to the environment and the SIC trust has been established with the SMS what will the gateways do?

a)

The gateways can only send logs to an SMS and cannot send logs to a Log Server. Log Servers are proprietary log archive servers.

b)

Gateways will send new firewall logs to the new Log Server as soon as the SIC trust is set up between the SMS and the new Log Server.

c)

The firewalls will detect the new Log Server after the next policy install and redirect the new logs to the new Log Server.

d)

Logs are not automatically forwarded to a new Log Server. SmartConsole must be used to manually configure each gateway to send its logs to the server.

26.

Name the utility that is used to block activities that appear to be suspicious.

a)

Penalty Box

b)

Drop Rule in the rulebase

c)

Suspicious Activity Monitoring (SAM)

d)

Stealth rule

27.

When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?

a)

The URL and server certificate are sent to the Check Point Online Web Service

b)

The full URL, including page data, is sent to the Check Point Online Web Service

c)

The host part of the URL is sent to the Check Point Online Web Service

d)

The URL and IP address are sent to the Check Point Online Web Service

28.

Name the pre-defined Roles included in Gaia OS.

a)

AdminRole, and MonitorRole

b)

ReadWriteRole, and ReadOnly Role

c)

AdminRole, cloningAdminRole, and Monitor Role

d)

AdminRole

29.

Gaia has two default user accounts that cannot be deleted. What are those user accounts?

a)

Admin and Default

b)

Expert and Clish

c)

Control and Monitor

d)

Admin and Monitor

30.

Which single Security Blade can be turned on to block both malicious files from being downloaded as well as block websites known to host malware?

a)

Anti-Bot

b)

None - both Anti-Virus and Anti-Bot are required for this

c)

Anti-Virus

d)

None - both URL Filtering and Anti-Virus are required for this

31.

Log query results can be exported to what file format?

a)

Word Document (docx)

b)

Comma Separated Value (csv)

c)

Portable Document Format (pdf)

d)

Text (txt)

32.

There are four policy types available for each policy package. What are those policy types?

a)

Access Control, Threat Prevention, Mobile Access and HTTPS Inspection

b)

Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection

c)

There are only three policy types: Access Control, Threat Prevention and NAT.

d)

Access Control, Threat Prevention, NAT and HTTPS Inspection

33.

Which tool allows for the automatic updating of the Gaia OS and Check Point products installed on the Gaia OS?

a)

CPASE - Check Point Automatic Service Engine

b)

CPAUE - Check Point Automatic Update Engine

c)

CPDAS - Check Point Deployment Agent Service

d)

CPUSE - Check Point Upgrade Service Engine

34.

The purpose of the Communication Initialization process is to establish a trust between the Security Management Server and the Check Point gateways. Which statement best describes this Secure Internal Communication (SIC)?

a)

After successful initialization, the gateway can communicate with any Check Point node that possesses a SIC certificate signed by the same ICA.

b)

Secure Internal Communications authenticates the security gateway to the SMS before http communications are allowed.

c)

A SIC certificate is automatically generated on the gateway because the gateway hosts a subordinate CA to the SMS ICA.

d)

New firewalls can easily establish the trust by using the expert password defined on the SMS and the SMS IP address.

35.

What are the types of Software Containers?

a)

Smart Console, Security Management, and Security Gateway

b)

Security Management, Security Gateway, and Endpoint Security

c)

Security Management, Log & Monitoring, and Security Policy

d)

Security Management, Standalone, and Security Gateway

36.

Stateful Inspection compiles and registers connections where?

a)

Connection Cache

b)

State Cache

c)

State Table

d)

Network Table

37.

Security Zones do no work with what type of defined rule?

a)

Application Control rule

b)

Manual NAT rule

c)

IPS bypass rule

d)

Firewall rule

38.

Most Check Point deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?

a)

Enterprise Network Security Appliances

b)

Rugged Appliances

c)

Scalable Platforms

d)

Small Business and Branch Office Appliances

39.

URL Filtering cannot be used to:

a)

Control Bandwidth issues

b)

Control Data Security

c)

Improve organizational security

d)

Decrease legal liability

40.

Which SmartConsole application shows correlated logs and aggregated data to provide an overview of potential threats and attack patterns?

a)

SmartEvent

b)

SmartView Tracker

c)

SmartLog

d)

SmartView Monitor

41.

Which of the following is used to extract state related information from packets and store that information in state tables?

a)

STATE Engine

b)

TRACK Engine

c)

RECORD Engine

d)

INSPECT Engine

42.

Which part of SmartConsole allows administrators to add, edit, delete, and clone objects?

a)

Object Browser

b)

Object Editor

c)

Object Navigator

d)

Object Explorer

43.

How do logs change when the "Accounting" tracking option is enabled on a traffic rule?

a)

Involved traffic logs will be forwarded to a log server.

b)

Provides log details view email to the Administrator.

c)

Involved traffic logs are updated every 10 minutes to show how much data has passed on the connection.

d)

Provides additional information to the connected user.

44.

Which of these is NOT a feature or benefit of Application Control?

a)

Eliminate unknown and unwanted applications in your network to reduce IT complexity and application risk.

b)

Identify and control which applications are in your IT environment and which to add to the IT environment.

c)

Scans the content of files being downloaded by users in order to make policy decisions.

d)

Automatically identify trusted software that has authorization to run

45.

What is the purpose of Captive Portal?

a)

It manages user permission in SmartConsole

b)

It provides remote access to SmartConsole

c)

It authenticates users, allowing them access to the Internet and corporate resources

d)

It authenticates users, allowing them access to the Gaia OS

46.

Which type of Check Point license is tied to the IP address of a specific Security Gateway and cannot be transferred to a gateway that has a different IP address?

a)

Formal

b)

Central

c)

Corporate

d)

Local

47.

Which of the following is NOT supported by Bridge Mode on the Check Point Security Gateway?

a)

Data Loss Prevention

b)

Antivirus

c)

Application Control

d)

NAT

48.

True or False: More than one administrator can log into the Security Management Server with SmartConsole with write permission at the same time.

a)

True, every administrator works on a different database that is independent of the other administrators

b)

False, this feature has to be enabled in the Global Properties.

c)

True, every administrator works in a session that is independent of the other administrators

d)

False, only one administrator can login with write permission

49.

When configuring LDAP with User Directory integration, changes applied to a User Directory template are:

a)

Not reflected for any users unless the local user template is changed.

b)

Not reflected for any users who are using that template.

c)

Reflected for all users who are using that template and if the local user template is changed as well.

d)

Reflected immediately for all users who are using that template.

50.

Which Threat Prevention profile uses sanitization technology?

a)

Cloud/data Center

b)

perimeter

c)

Sandbox

d)

Guest Network

51.

The competition between stateful inspection and proxies was based on performance, protocol support, and security. Considering stateful inspections and proxies, which statement is correct?

a)

Stateful Inspection is limited to Layer 3 visibility, with no Layer 4 to Layer 7 visibility capabilities.

b)

When it comes to performance, proxies were significantly faster than stateful inspection firewalls.

c)

Proxies offer far more security because of being able to give visibility of the payload (the data).

d)

When it comes to performance, stateful inspection was significantly faster than proxies.

52.

What are the Threat Prevention software components available on the Check Point Security Gateway?

a)

IPS, Threat Emulation and Threat Extraction

b)

IPS, Anti-Bot, Anti-Virus, SandBlast and Macro Extraction

c)

IPS, Anti-Bot, Anti-Virus, Threat Emulation and Threat Extraction

d)

IDS, Forensics, Anti-Virus, Sandboxing

53.

You have enabled Extended Log as a tracking option to a security rule. However, you are still not seeing any data type information. What is the MOST likely reason?

a)

Identity Awareness is not enabled.

b)

Log Trimming is enabled.

c)

Logging has disk space issues.

d)

Content Awareness is not enabled.

54.

Identity Awareness allows easy configuration for network access and auditing based on what three items?

a)

Client machine IP address.

b)

Network location, the identity of a user and the identity of a machine.

c)

Log server IP address.

d)

Gateway proxy IP address.

55.

What are the three deployment options available for a security gateway?

a)

Standalone, Distributed, and Bridge Mode

b)

Bridge Mode, Remote, and Standalone

c)

Remote, Standalone, and Distributed

d)

Distributed, Bridge Mode, and Remote

56.

In which scenario will an administrator need to manually define Proxy ARP?

a)

When they configure an Automatic Static NAT which translates to an IP address that does not belong to one of the firewall's interfaces.

b)

When they configure an Automatic Hide NAT which translates to an IP address that does not belong to one of the firewall's interfaces.

c)

When they configure a Manual Static NAT which translates to an IP address that does not belong to one of the firewall's interfaces.

d)

When they configure a Manual Hide NAT which translates to an IP address that belongs to one of the firewall's interfaces.

57.

Which of the following is NOT a component of a Distinguished Name?

a)

Common Name

b)

Country

c)

User container

d)

Organizational Unit

58.

A network administrator has informed you that they have identified a malicious host on the network, and instructed you to block it. Corporate policy dictates that firewall policy changes cannot be made at this time. What tool can you use to block this traffic?

a)

Anti-Bot protection

b)

Anti-Malware protection

c)

Policy-based routing

d)

Suspicious Activity Monitoring (SAM) rules

59.

What command from the CLI would be used to view current licensing?

a)

license view

b)

fw ctl tab -t license -s

c)

show license -s

d)

cplic print

60.

In a Distributed deployment, the Security Gateway and the Security Management software are installed on what platforms?

a)

Different computers or appliances.

b)

The same computer or appliance.

c)

Both on virtual machines or both on appliances but not mixed.

d)

In Azure and AWS cloud environments.

61.

Which of the following licenses are considered temporary?

a)

Plug-and-play (Trial) and Evaluation

b)

Perpetual and Trial

c)

Evaluation and Subscription

d)

Subscription and Perpetual