NEW
Font size
WorksheetsDUMSA_7.1
Total questions: 47
Worksheet time: 24mins
When you upload a package or license to the repository in SmartUpdate, where is it stored?
Security Gateway
Security Management Server
Check Point user center
SmartConsole installed device
What technologies are used to deny or permit network traffic?
Packet filtering, Stateful Inspection, and Application Layer Firewall
Stateful Inspection, Firewall Blade, and URL/Application Blade
Stateful Inspection, URL/Application Blade, and Threat Prevention
Firewall Blade, URL/Application Blade and IPS
Fill in the blanks: A Check Point software license consists of a _________ and _______.
Software container; software package
Software blade; software container
Software package; signature
Signature; software blade
Which one of the following is the preferred licensing model? Select the BEST answer.
Central licensing; ties license to SMS IP; no gateway dependency
Local licensing; ties license to gateway IP; no SMS dependency
Local licensing; ties license to gateway MAC; no SMS dependency
Central licensing; ties license to SMS MAC; no dependency on gateway
Which command is used to add users to or from existing roles?
add rba user
add user
add rba user
add user
An administrator wants only certain users on a specific network to access a resource. What is the best way to accomplish this?
Create rule allowing specific source IPs to target resource
Create Access Role object with users and networks as Source
Create inline layer with destination as target resource
Use a Legacy User at Location with LDAP group
Which component sequence best reflects where a Security Policy is created, stored, and enforced in a Check Point environment?
SmartConsole, Security Gateway, Security Management Servers
Security Management Server, SmartConsole, Security Gateways
SmartConsole, Security Management Server, Security Gateways
Security Gateways, SmartConsole, Security Management Server
What is the correct order of NAT priorities in Check Point?
Static NAT, IP pool NAT, hide NAT
Static NAT, hide NAT, IP pool NAT
IP pool NAT, static NAT, hide NAT
Static NAT, automatic NAT, hide NAT
While enabling Identity Awareness, the wizard fails to auto-detect the Windows domain. What is the MOST likely reason?
Security Gateway is not part of the domain
SmartConsole machine is not part of the domain
Security Management Server is not part of the domain
Identity Awareness not enabled on Global properties
Two administrators are logged into SmartConsole and objects are locked for editing. What action makes the objects available to others?
Save and install the Policy
Delete older database versions
Revert the session
Publish or discard the session
At what point is the Internal Certificate Authority (ICA) created in Check Point?
Upon individual certificate creation
At initial SmartConsole login
When an administrator manually creates one
During primary Security Management Server installation
AdminA and AdminB are both logged into SmartConsole. AdminB sees a lock icon on a rule. What does this indicate?
Rule is locked by AdminA because save was not pressed
Rule is locked by AdminA and becomes available when saved
Rule is locked by AdminA because it is being edited
Rule is locked by AdminA and will be available if the session is published
When LDAP is integrated with Check Point Security Management, it is referred to as what?
User Directory
User Administration
User Center
UserCheck
Which identity acquisition method lets a Security Gateway identify Active Directory users and computers?
UserCheck
Account Unit Query
User Directory Query
Active Directory Query
In NAT processing on a security gateway, which rule type is evaluated first when determining translation for outbound connections?
Proxy ARP NAT rules for local interfaces
Automatic NAT rules generated by objects
Manual static NAT rules for matched objects
Manual hide NAT rules with matched services
During Identity Awareness setup, what is the primary purpose of the Identity Awareness Wizard?
Enable identity sources and access roles
Lock administrator sessions during changes
Configure NAT priorities automatically
Publish administrator sessions to gateways
Which statement best describes Identity Awareness domain detection in a multi-domain environment?
Domains are assigned to users through NAT objects
Users are mapped to domains via identity sources and gateways
Domains are detected by gateway based on routing tables
Users are mapped to domains using LDAP OU matching
When multiple NAT rules could apply, what is the correct priority order used to resolve the translation?
Automatic NAT, Manual static NAT, Manual hide NAT
Manual static NAT, Manual hide NAT, Automatic NAT
Manual hide NAT, Automatic NAT, Manual static NAT
Proxy ARP, Manual static NAT, Automatic NAT
An administrator is making policy changes but wants to prevent others from modifying the same session. What feature should be used?
Session publish to commit policy changes
Session lock to reserve the editing session
Session discard to remove unpublished changes
Revert policy to previous install
Before installing access policy changes that include new Identity Awareness roles, which action ensures the changes are visible to other admins and gateways?
Publish the session to consolidate changes
Discard the session to clear conflicts
Lock the session to prevent installs
Enable automatic NAT generation
Which action should an administrator take if identity data seems mapped to the wrong domain after wizard configuration?
Publish and discard the current session
Re-run the wizard to select correct identity sources
Adjust NAT priorities to prefer static rules
Enable session lock while installing policy
Which methods can be used for mutual authentication between VPN gateways?
Pre-shared secret and PKI certificates
PKI certificates and DynamicID OTP
PKI certificates and Kerberos tickets
Pre-shared secrets and Kerberos ticket
In IKEv1 Aggressive Mode between gateways, what is the primary risk compared to Main Mode?
Longer negotiation time over WAN links
Identity exposure during initial exchange
Requirement for hardware acceleration modules
Inability to support domain-based VPNs
Which statement best describes a domain-based site-to-site VPN?
IKE is replaced by SSL for tunnel negotiation
Endpoints authenticate users with one-time passwords
Security gateways encrypt traffic between defined VPN domains
Tunnels are built only for individual host pairs
Which option correctly matches IKE Phase 1 and Phase 2 purposes?
Phase 1 builds ISAKMP SA; Phase 2 negotiates IPsec SAs
Phase 1 defines VPN domains; Phase 2 selects ciphers
Phase 1 exchanges user credentials; Phase 2 sets routing
Phase 1 negotiates IPsec SAs; Phase 2 discovers peer identity
When using PKI certificates for gateway authentication, what is required on each gateway?
A certificate signed by a trusted CA
A Kerberos ticket-granting ticket
A DynamicID OTP token device
A shared secret configured on both
For a domain-based VPN between separate management domains, which configuration avoids routing leaks during negotiation?
Restrict encryption domains to relevant subnets
Enable Aggressive Mode without peer ID
Configure Kerberos for mutual authentication
Use DES to reduce overhead on negotiation
Which method establishes identity between VPN gateways in certificate-based tunnels across different management systems?
Shared User Certificates
Mutually Trusted Certificate Authorities
Shared Secret Passwords
Unique Passwords
You need an IKE P2 SA only between two subnets, not all subnets in the default VPN domain. What is the recommended action?
Edit user.def.FWI on Management with range pair
Edit user.def.FW1 on Gateway with range pair
Create in-line layer rule with both networks and set VPN column
Set VPN Domain to 'User defined' on local gateway
In the Check Point three-tiered architecture, which is NOT a function of the Security Management Server?
Verify and compile Security Policies
Process and send alerts such as SNMP traps
Display policies and logs on administrator's workstation
Store firewall logs to hard drive storage
Fill in the blank: The _____ is used to obtain identification and security information about network users.
User index
UserCheck
User Directory
User server
Which Security Blade must be enabled to sanitize and remove potentially malicious content from files before they enter the network?
Threat Emulation
Anti-Malware
Anti-Virus
Threat Extraction
Fill in the blank: A(n) _____ rule is created by an administrator and configured to allow or block traffic based on specified criteria.
Inline
Explicit
Implicit drop
Implicit accept
On a Check Point gateway, which operational command is used to manage VPN tunnels interactively for troubleshooting?
vpn debug
vpn ike
vpn cert
vpn tu
Which Check Point supported authentication scheme typically requires a user to possess a token?
RADIUS
TACACS
SecurID
Check Point password
Which of the following is true about Stateful Inspection?
Stateful Inspection tracks state using two tables, one for incoming traffic and one for outgoing traffic
Stateful Inspection looks at both the headers of packets, as well as deeply examining their content
Stateful Inspection requires that a server reply to a request, in order to track a connection's state
Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic
Which option in tracking allows you to see the amount of data passed in the connection?
Logs
Accounting
Data
Advanced
Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, where Bob and Joe are both logged in:
Since they both are logged in on different interfaces, they will both be able to make changes.
When Joe logs in, Bob will be logged out automatically.
The database will be locked by Bob and Joe will not be able to make any changes.
Bob will receive a prompt that Joe has logged in.
Fill in the blank: An identity server uses a _____________ to trust a Terminal Server Identity Agent.
One-time password
Shared secret
Certificate
Token
Which icon in the WebUI indicates that read/write access is enabled?
Book
Eyeglasses
Padlock
Pencil
By default, which port is used to connect to the GAiA Portal?
80
443
8080
4434
In Check Point Gaia OS, which is the default command-line shell?
Clish
Bash
Expert
Admin
Gaia can be configured using the _____ or _____.
Command line interface; GAiA Portal
Web Ultimate Interface; Gaia Interface (SSH)
Gaia Interface; Gaia Ultimate Shell
GaiaUI; command line interface (serial console only)
AdminA and AdminB are both logged into SmartConsole. What does it mean if AdminB sees a lock icon on a rule? Choose the BEST answer.
Rule is locked by AdminA and will be made available if the session is published.
Rule is locked by AdminB because the rule is currently being edited.
Rule is locked by AdminB because the save button has not been pressed.
Rule is locked by AdminA and if the session is saved, the rule will be made available.
What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?
Automatic licensing
Verification tool
Verification licensing
Automatic Licensing and Verification tool
When dealing with policy layers, what two layer types can be utilized?
Inbound Layers and Outbound Layers
Ordered Layers and Inline Layers
R81.X does not support Layers.
Structured Layers and Overlap Layers
Which command shows detailed information about VPN tunnels?
cpview
vpn tu
vpn tu tlist
cat $FWDIR/conf/vpn.conf
