NEW
Font size
WorksheetsDUMSA_6.1
Total questions: 67
Worksheet time: 34mins
Fill in the blank: SmartConsole, SmartEvent GUI client, and ______ allow viewing of billions of consolidated logs and shows them as prioritized security events.
SmartView Web Application
SmartTracker
SmartMonitor
SmartReporter
To increase security, the administrator has modified the Core protection 'Host Port Scan' from 'Medium' to 'High' Predefined Sensitivity. Which Policy should the administrator install after Publishing the changes?
The Access Control and Threat Prevention Policies.
The Access Control Policy.
The Access Control & HTTPS Inspection Policy.
The Threat Prevention Policy.
When changes are made to a Rule base, it is important to __________ to enforce changes.
Publish database
Activate policy
Install policy
Save changes
The Online Activation method is available for Check Point manufactured appliances. How does the administrator use the Online Activation method?
The SmartLicensing GUI tool must be launched from the SmartConsole for the Online Activation tool to start automatically.
No action is required if the firewall has internet access and a DNS server to resolve domain names.
Using the Gaia First Time Configuration Wizard, the appliance connects to the Check Point User Center and downloads all necessary licenses and contracts.
The cpinfo command must be run on the firewall with the switch -online-license-activation.
Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility. Which statement is true?
Manual NAT can offer more flexibility than Automatic NAT.
Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.
Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading.
Automatic NAT can offer more flexibility than Manual NAT.
Fill in the blank: The _____ feature allows administrators to share a policy with other policy packages.
Concurrent policy packages
Concurrent policies
Global Policies
Shared policies
When dealing with rule base layers, what two layer types can be utilized?
Ordered Layers and Inline Layers
Inbound Layers and Outbound Layers
R81.10 does not support Layers
Structured Layers and Overlap Layers
Application Control/URL filtering database library is known as:
Application database
AppWiki
Application-Forensic Database
Application Library
What kind of NAT enables Source Port Address Translation by default?
Automatic Static NAT
Manual Hide NAT
Automatic Hide NAT
Manual Static NAT
Name the authentication method that requires token authenticator.
SecureID
Radius
DynamicID
TACACS
Secure Internal Communication (SIC) is handled by what process?
CPM
HTTPS
FWD
CPD
What is the main difference between Static NAT and Hide NAT?
Static NAT only allows incoming connections to protect your network.
Static NAT allow incoming and outgoing connections. Hide NAT only allows outgoing connections.
Static NAT only allows outgoing connections. Hide NAT allows incoming and outgoing connections.
Hide NAT only allows incoming connections to protect your network.
A Check Point Software license consists of two components, the Software Blade and the Software Container. There are ______ types of Software Containers: ________.
Two; Security Management and Endpoint Security
Two; Endpoint Security and Security Gateway
Three; Security Management, Security Gateway, and Endpoint Security
Three; Security Gateway, Endpoint Security, and Gateway Management
Fill in the blank: With the User Directory Software Blade, you can create user definitions on a(n) __________ Server.
SecurID
LDAP
NT domain
SMTP
What is the default tracking option of a rule?
Tracking
Log
None
Alert
Which of the following cannot be configured in an Access Role Object?
Networks
Users
Time
Machines
When using Automatic Hide NAT, what is enabled by default?
Source Port Address Translation (PAT)
Static NAT
Static Route
HTTPS Inspection
Which is a main component of the Check Point security management architecture?
Identity Collector
Endpoint VPN client
SmartConsole
Proxy Server
Which default Gaia user has full read/write access?
admin
superuser
monitor
altuser
Which of the following is considered a "Subscription Blade", requiring renewal every 1-3 years?
IPS blade
IPSEC VPN Blade
Identity Awareness Blade
Firewall Blade
DLP and Geo Policy are examples of what type of Policy?
Inspection Policies
Shared Policies
Unified Policies
Standard Policies
Fill in the blanks: The Application Layer Firewalls inspect traffic through the ______ layer(s) of the TCP/IP model and up to and including the ______ layer.
Upper; Application
First two; Internet
Lower; Application
First two; Transport
Fill in the blanks: The ______ collects logs and sends them to the ______.
Log server; Security Gateway
Log server; security management server
Security management server; Security Gateway
Security Gateways; log server
When a SAM rule is required on Security Gateway to quickly block suspicious connections which are not restricted by the Security Policy, what actions does the administrator need to take?
SmartView Monitor should be opened and then the SAM rule/s can be applied immediately. Installing policy is not required.
The policy type SAM must be added to the Policy Package and a new SAM rule must be applied. Simply Publishing the changes applies the SAM rule on the firewall.
The administrator must work on the firewall CLI (for example with SSH and PuTTY) and the command 'sam block' must be used with the right parameters.
The administrator should open the LOGS & MONITOR view and find the relevant log. Right clicking on the log entry will show the Create New SAM rule option.
Which policy type is used to enforce bandwidth and traffic control rules?
Access Control
Threat Emulation
Threat Prevention
QoS
To provide updated malicious data signatures to all Threat Prevention blades, the Threat Prevention gateway does what with the data?
Cache the data to speed up its own function.
Share the data to the ThreatCloud for use by other Threat Prevention blades.
Log the traffic for Administrator viewing.
Delete the data to ensure an analysis of the data is done each time.
Which product correlates logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?
SmartDashboard
SmartEvent
SmartView Monitor
SmartUpdate
Which two Identity Awareness daemons are used to support identity sharing?
Policy Activation Point (PAP) and Policy Decision Point (PDP)
Policy Manipulation Point (PMP) and Policy Activation Point (PAP)
Policy Enforcement Point (PEP) and Policy Manipulation Point (PMP)
Policy Decision Point (PDP) and Policy Enforcement Point (PEP)
What is the default shell of Gaia CLI?
clish
Monitor
Read-only
Bash
How many users can have read/write access in Gaia Operating System at one time?
One
Three
Two
Infinite
In SmartConsole, on which tab are Permissions and Administrators defined?
Manage and Settings
Logs and Monitor
Security Policies
Gateways and Servers
The Gateway Status view in SmartConsole shows the overall status of Security Gateways and Software Blades. What does the Status Attention mean?
Cannot reach the Security Gateway.
The gateway and all its Software Blades are working properly.
At least one Software Blade has a minor issue, but the gateway works.
Cannot make SIC between the Security Management Server and the Security Gateway
In order for changes made to policy to be enforced by a Security Gateway, what action must an administrator perform?
Publish changes
Save changes
Install policy
Install database
What is the main objective when using Application Control?
To filter out specific content.
To assist the firewall blade with handling traffic.
To see what users are doing.
Ensure security and privacy of information.
What are the three main components of Check Point security management architecture?
SmartConsole, Security Management, and Security Gateway
SmartConsole, Standalone, and Security Management
SmartConsole, Security policy, and Logs & Monitoring
GUI-Client, Security Management, and Security Gateway
In which deployment is the security management server and Security Gateway installed on the same appliance?
Standalone
Remote
Distributed
Bridge Mode
Where can administrator edit a list of trusted SmartConsole clients?
cpconfig on a Security Management Server, in the WebUI logged into a Security Management Server.
In cpconfig on a Security Management Server, in the WebUI logged into a Security Management Server, in SmartConsole: Manage and Settings > Permissions and Administrators > Advanced > Trusted Clients.
WebUI client logged to Security Management Server, SmartDashboard: Manage and Settings > Permissions and Administrators > Advanced > Trusted Clients, via cpconfig on a Security Gateway.
Only using SmartConsole: Manage and Settings > Permissions and Administrators > Advanced > Trusted Clients.
The default shell of the Gaia CLI is cli.sh. How do you change from the cli.sh shell to the advanced shell to run Linux commands?
Execute the command 'enable' in the cli.sh shell
Execute the 'conf t' command in the cli.sh shell
Execute the command 'expert' in the cli.sh shell
Execute the 'exit' command in the cli.sh shell
Check Point licenses come in two forms. What are those forms?
Central and Local.
Access Control and Threat Prevention.
On-premise and Public Cloud.
Security Gateway and Security Management.
In SmartEvent, a correlation unit (CU) is used to do what?
Collect security gateway logs, Index the logs and then compress the logs.
Receive firewall and other software blade logs in a region and forward them to the primary log server.
Analyze log entries and identify events.
Send SAM block rules to the firewalls during a DOS attack.
What is NOT an advantage of Packet Filtering?
Application Independence
High Performance
Scalability
Low Security and No Screening above Network Layer
What are the two elements of address translation rules?
Original packet and translated packet
Manipulated packet and original packet
Translated packet and untranslated packet
Untranslated packet and manipulated packet
Which software blade does NOT accompany the Threat Prevention policy?
IPS
Application Control and URL Filtering
Threat Emulation
Anti-virus
Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.
Network location, the identity of a user and the active directory membership.
Network location, the identity of a user and the identity of a machine.
Network location, the telephone number of a user and the UID of a machine
Geographical location, the identity of a user and the identity of a machine
Which Check Point Software Wade provides visibility of users, groups and machines while also providing access control through identity-based policies?
Firewall
Identity Awareness
Application Control
URL Filtering
For Automatic Hide NAT rules created by the administrator what is a TRUE statement?
Source Port Address Translation (PAT) is enabled by default
Automate NAT rules are supported for Network objects only.
Automatic NAT rules are supported for Host objects only.
Source Port Address Translation (PAT) is disabled by default
What is the user ID of a user that have all the privileges of a root user?
User ID 1
User ID 2
User ID 0
User ID 99
Which command shows the installed licenses in Expert mode?
print cplic
show licenses
fwlic print
cplic print
What are two basic rules Check Point recommending for building an effective security policy?
Accept Rule and Drop Rule
Cleanup Rule and Stealth Rule
Explicit Rule and Implied Rule
NAT Rule and Reject Rule
Which type of Endpoint Identity Agent includes packet tagging and computer authentication?
Full
Custom
Complete
Light
Which of the following is TRUE regarding Gaia command line?
Configuration changes should be done in mgmt_di and use CLISH for monitoring. Expert mode is used only for OS level tasks
Configuration changes should be done in mgmt_cli and use expert-mode for OS-level tasks.
Configuration changes should be done in expert-mode and CLISH is used for monitoring
All configuration changes should be made in CLISH and expert-mode should be used for OS-level tasks.
When a gateway requires user information for authentication, what order does it query servers for user information?
First - Internal user database, then LDAP servers in order of priority, finally the generic external user profile
First the Internal user database, then generic external user profile, finally LDAP servers in order of priority.
First the highest priority LDAP server, then the internal user database, then lower priority LDAP servers, finally the generic external profile
The external generic profile, then the internal user database finally the LDAP servers in order of priority.
Fill in the blank RADIUS Accounting gets _____ data from requests generated by the accounting client
Location
Payload
Destination
Identity
SmartConsole provides a consolidated solution for everything that is necessary for the security of an organization, such as the following
Security Policy Management and Log Analysis
Security Policy Management. Log Analysis. System Health Monitoring. Multi-Domain Security Management.
Security Policy Management Log Analysis and System Health Monitoring
Security Policy Management. Threat Prevention rules. System Health Monitoring and Multi-Domain Security Management.
By default, which port does the WebUI listen on?
8080
80
4434
443
Fill in the blank Backup and restores can be accomplished through
SmartUpdate, SmartBackup, or SmartConsole
WebUI, CLI, or SmartUpdate
CLI, SmartUpdate, or SmartBackup
SmartConsole, WebUI, or CLI
Which of the following is NOT a type of Endpoint Identity Agent?
Custom
Terminal
Full
Light
An administrator wishes to use Application objects in a rule in their policy but there are no Application objects listed as options to add when clicking the "+" to add new items to the "Services & Applications" column of a rule. What should be done to fix this?
Drag-and-drop the needed Application objects from the Object Explorer into the new rule
Enable the "Application Control" blade on a gateway
Enable "Applications & URL Filtering" on the policy layer where the rule is being created
First create some applications to add to the rule
Which Threat Prevention Software Blade provides comprehensive protection against malicious and unwanted network traffic, focusing on application and server vulnerabilities?
IPS
Anti-Virus
Anti-Spam
Anti-bot
Using AD Query, the security gateway connections to the Active Directory Domain Controllers use what protocol?
Windows Management Instrumentation (WMI)
Hypertext Transfer Protocol Secure (HTTPS)
Lightweight Directory Access Protocol (LDAP)
Remote Desktop Protocol (RDP)
Which of the completed statements is NOT true? The WebUI can be used to manage Operating System user accounts and
add users to your Gaia system.
assign privileges to users.
assign user rights to their home directory in the Security Management Server.
edit the home directory of the user.
Fill in the blank RADIUS protocol uses _____ to communicate with the gateway
UDP
CCP
TDP
HTTP
Choose what BEST describes a Session
Ends when policy is pushed to the Security Gateway
Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out
Locks the policy package for editing
Starts when an Administrator publishes all the changes made on SmartConsole
Where can alerts be viewed?
SmartView Monitor
Threat Prevention policy
SmartUpdate
CLI of the gateway
If there is an Accept Implied Policy set to "First", what is the reason Jorge cannot see any logs?
Log Implied Rule was not set correctly on the track column on the rules base
Track log column is set to Log instead of Full Log
Track log column is set to none
Log Implied Rule was not selected on Global Properties
A layer can support different combinations of blades What are the supported blades:
Firewall, URLF, Content Awareness and Mobile Access
Firewall (Network Access Control), Application & URL Filtering, Content Awareness and Mobile Access
Firewall, NAT, Content Awareness and Mobile Access
Firewall (Network Access Control), Application & URL Filtering and Content Awareness
Fill in the blank Once a license is activated, a __________ should be installed.
contract file
security gateway
VPN certificate
policy package
