wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

DUMSA_7.1

Total questions: 47

Worksheet time: 24mins

Name
Class
Date
1.

When you upload a package or license to the repository in SmartUpdate, where is it stored?

a)

Security Gateway

b)

Security Management Server

c)

Check Point user center

d)

SmartConsole installed device

2.

What technologies are used to deny or permit network traffic?

a)

Packet filtering, Stateful Inspection, and Application Layer Firewall

b)

Stateful Inspection, Firewall Blade, and URL/Application Blade

c)

Stateful Inspection, URL/Application Blade, and Threat Prevention

d)

Firewall Blade, URL/Application Blade and IPS

3.

Fill in the blanks: A Check Point software license consists of a _________ and _______.

a)

Software container; software package

b)

Software blade; software container

c)

Software package; signature

d)

Signature; software blade

4.

Which one of the following is the preferred licensing model? Select the BEST answer.

a)

Central licensing; ties license to SMS IP; no gateway dependency

b)

Local licensing; ties license to gateway IP; no SMS dependency

c)

Local licensing; ties license to gateway MAC; no SMS dependency

d)

Central licensing; ties license to SMS MAC; no dependency on gateway

5.

Which command is used to add users to or from existing roles?

a)

add rba user roles

b)

add user

c)

add rba user

d)

add user roles

6.

An administrator wants only certain users on a specific network to access a resource. What is the best way to accomplish this?

a)

Create rule allowing specific source IPs to target resource

b)

Create Access Role object with users and networks as Source

c)

Create inline layer with destination as target resource

d)

Use a Legacy User at Location with LDAP group

7.

Which component sequence best reflects where a Security Policy is created, stored, and enforced in a Check Point environment?

a)

SmartConsole, Security Gateway, Security Management Servers

b)

Security Management Server, SmartConsole, Security Gateways

c)

SmartConsole, Security Management Server, Security Gateways

d)

Security Gateways, SmartConsole, Security Management Server

8.

What is the correct order of NAT priorities in Check Point?

a)

Static NAT, IP pool NAT, hide NAT

b)

Static NAT, hide NAT, IP pool NAT

c)

IP pool NAT, static NAT, hide NAT

d)

Static NAT, automatic NAT, hide NAT

9.

While enabling Identity Awareness, the wizard fails to auto-detect the Windows domain. What is the MOST likely reason?

a)

Security Gateway is not part of the domain

b)

SmartConsole machine is not part of the domain

c)

Security Management Server is not part of the domain

d)

Identity Awareness not enabled on Global properties

10.

Two administrators are logged into SmartConsole and objects are locked for editing. What action makes the objects available to others?

a)

Save and install the Policy

b)

Delete older database versions

c)

Revert the session

d)

Publish or discard the session

11.

At what point is the Internal Certificate Authority (ICA) created in Check Point?

a)

Upon individual certificate creation

b)

At initial SmartConsole login

c)

When an administrator manually creates one

d)

During primary Security Management Server installation

12.

AdminA and AdminB are both logged into SmartConsole. AdminB sees a lock icon on a rule. What does this indicate?

a)

Rule is locked by AdminA because save was not pressed

b)

Rule is locked by AdminA and becomes available when saved

c)

Rule is locked by AdminA because it is being edited

d)

Rule is locked by AdminA and will be available if the session is published

13.

When LDAP is integrated with Check Point Security Management, it is referred to as what?

a)

User Directory

b)

User Administration

c)

User Center

d)

UserCheck

14.

Which identity acquisition method lets a Security Gateway identify Active Directory users and computers?

a)

UserCheck

b)

Account Unit Query

c)

User Directory Query

d)

Active Directory Query

15.

In NAT processing on a security gateway, which rule type is evaluated first when determining translation for outbound connections?

a)

Proxy ARP NAT rules for local interfaces

b)

Automatic NAT rules generated by objects

c)

Manual static NAT rules for matched objects

d)

Manual hide NAT rules with matched services

16.

During Identity Awareness setup, what is the primary purpose of the Identity Awareness Wizard?

a)

Enable identity sources and access roles

b)

Lock administrator sessions during changes

c)

Configure NAT priorities automatically

d)

Publish administrator sessions to gateways

17.

Which statement best describes Identity Awareness domain detection in a multi-domain environment?

a)

Domains are assigned to users through NAT objects

b)

Users are mapped to domains via identity sources and gateways

c)

Domains are detected by gateway based on routing tables

d)

Users are mapped to domains using LDAP OU matching

18.

When multiple NAT rules could apply, what is the correct priority order used to resolve the translation?

a)

Automatic NAT, Manual static NAT, Manual hide NAT

b)

Manual static NAT, Manual hide NAT, Automatic NAT

c)

Manual hide NAT, Automatic NAT, Manual static NAT

d)

Proxy ARP, Manual static NAT, Automatic NAT

19.

An administrator is making policy changes but wants to prevent others from modifying the same session. What feature should be used?

a)

Session publish to commit policy changes

b)

Session lock to reserve the editing session

c)

Session discard to remove unpublished changes

d)

Revert policy to previous install

20.

Before installing access policy changes that include new Identity Awareness roles, which action ensures the changes are visible to other admins and gateways?

a)

Publish the session to consolidate changes

b)

Discard the session to clear conflicts

c)

Lock the session to prevent installs

d)

Enable automatic NAT generation

21.

Which action should an administrator take if identity data seems mapped to the wrong domain after wizard configuration?

a)

Publish and discard the current session

b)

Re-run the wizard to select correct identity sources

c)

Adjust NAT priorities to prefer static rules

d)

Enable session lock while installing policy

22.

Which methods can be used for mutual authentication between VPN gateways?

a)

Pre-shared secret and PKI certificates

b)

PKI certificates and DynamicID OTP

c)

PKI certificates and Kerberos tickets

d)

Pre-shared secrets and Kerberos ticket

23.

In IKEv1 Aggressive Mode between gateways, what is the primary risk compared to Main Mode?

a)

Longer negotiation time over WAN links

b)

Identity exposure during initial exchange

c)

Requirement for hardware acceleration modules

d)

Inability to support domain-based VPNs

24.

Which statement best describes a domain-based site-to-site VPN?

a)

IKE is replaced by SSL for tunnel negotiation

b)

Endpoints authenticate users with one-time passwords

c)

Security gateways encrypt traffic between defined VPN domains

d)

Tunnels are built only for individual host pairs

25.

Which option correctly matches IKE Phase 1 and Phase 2 purposes?

a)

Phase 1 builds ISAKMP SA; Phase 2 negotiates IPsec SAs

b)

Phase 1 defines VPN domains; Phase 2 selects ciphers

c)

Phase 1 exchanges user credentials; Phase 2 sets routing

d)

Phase 1 negotiates IPsec SAs; Phase 2 discovers peer identity

26.

When using PKI certificates for gateway authentication, what is required on each gateway?

a)

A certificate signed by a trusted CA

b)

A Kerberos ticket-granting ticket

c)

A DynamicID OTP token device

d)

A shared secret configured on both

27.

For a domain-based VPN between separate management domains, which configuration avoids routing leaks during negotiation?

a)

Restrict encryption domains to relevant subnets

b)

Enable Aggressive Mode without peer ID

c)

Configure Kerberos for mutual authentication

d)

Use DES to reduce overhead on negotiation

28.

Which method establishes identity between VPN gateways in certificate-based tunnels across different management systems?

a)

Shared User Certificates

b)

Mutually Trusted Certificate Authorities

c)

Shared Secret Passwords

d)

Unique Passwords

29.

You need an IKE P2 SA only between two subnets, not all subnets in the default VPN domain. What is the recommended action?

a)

Edit user.def.FWI on Management with range pair

b)

Edit user.def.FW1 on Gateway with range pair

c)

Create in-line layer rule with both networks and set VPN column

d)

Set VPN Domain to 'User defined' on local gateway

30.

In the Check Point three-tiered architecture, which is NOT a function of the Security Management Server?

a)

Verify and compile Security Policies

b)

Process and send alerts such as SNMP traps

c)

Display policies and logs on administrator's workstation

d)

Store firewall logs to hard drive storage

31.

Fill in the blank: The _____ is used to obtain identification and security information about network users.

a)

User index

b)

UserCheck

c)

User Directory

d)

User server

32.

Which Security Blade must be enabled to sanitize and remove potentially malicious content from files before they enter the network?

a)

Threat Emulation

b)

Anti-Malware

c)

Anti-Virus

d)

Threat Extraction

33.

Fill in the blank: A(n) _____ rule is created by an administrator and configured to allow or block traffic based on specified criteria.

a)

Inline

b)

Explicit

c)

Implicit drop

d)

Implicit accept

34.

On a Check Point gateway, which operational command is used to manage VPN tunnels interactively for troubleshooting?

a)

vpn debug

b)

vpn ike

c)

vpn cert

d)

vpn tu

35.

Which Check Point supported authentication scheme typically requires a user to possess a token?

a)

RADIUS

b)

TACACS

c)

SecurID

d)

Check Point password

36.

Which of the following is true about Stateful Inspection?

a)

Stateful Inspection tracks state using two tables, one for incoming traffic and one for outgoing traffic

b)

Stateful Inspection looks at both the headers of packets, as well as deeply examining their content

c)

Stateful Inspection requires that a server reply to a request, in order to track a connection's state

d)

Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic

37.

Which option in tracking allows you to see the amount of data passed in the connection?

a)

Logs

b)

Accounting

c)

Data

d)

Advanced

38.

Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, where Bob and Joe are both logged in:

a)

Since they both are logged in on different interfaces, they will both be able to make changes.

b)

When Joe logs in, Bob will be logged out automatically.

c)

The database will be locked by Bob and Joe will not be able to make any changes.

d)

Bob will receive a prompt that Joe has logged in.

39.

Fill in the blank: An identity server uses a _____________ to trust a Terminal Server Identity Agent.

a)

One-time password

b)

Shared secret

c)

Certificate

d)

Token

40.

Which icon in the WebUI indicates that read/write access is enabled?

a)

Book

b)

Eyeglasses

c)

Padlock

d)

Pencil

41.

By default, which port is used to connect to the GAiA Portal?

a)

80

b)

443

c)

8080

d)

4434

42.

In Check Point Gaia OS, which is the default command-line shell?

a)

Clish

b)

Bash

c)

Expert

d)

Admin

43.

Gaia can be configured using the _____ or _____.

a)

Command line interface; GAiA Portal

b)

Web Ultimate Interface; Gaia Interface (SSH)

c)

Gaia Interface; Gaia Ultimate Shell

d)

GaiaUI; command line interface (serial console only)

44.

AdminA and AdminB are both logged into SmartConsole. What does it mean if AdminB sees a lock icon on a rule? Choose the BEST answer.

a)

Rule is locked by AdminA and will be made available if the session is published.

b)

Rule is locked by AdminB because the rule is currently being edited.

c)

Rule is locked by AdminB because the save button has not been pressed.

d)

Rule is locked by AdminA and if the session is saved, the rule will be made available.

45.

What licensing feature automatically verifies current licenses and activates new licenses added to the License and Contracts repository?

a)

Automatic licensing

b)

Verification tool

c)

Verification licensing

d)

Automatic Licensing and Verification tool

46.

When dealing with policy layers, what two layer types can be utilized?

a)

Inbound Layers and Outbound Layers

b)

Ordered Layers and Inline Layers

c)

R81.X does not support Layers.

d)

Structured Layers and Overlap Layers

47.

Which command shows detailed information about VPN tunnels?

a)

cpview

b)

vpn tu

c)

vpn tu tlist

d)

cat $FWDIR/conf/vpn.conf