wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DUMSA_8.1

Total questions: 53

Worksheet time: 27mins

Name
Class
Date
1.

Which command shows the installed licenses?

a)

cplic print

b)

print cplic

c)

fwllic print

d)

show licenses

2.

Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?

a)

SmartManager

b)

SmartConsole

c)

Security Gateway

d)

Security Management Server

3.

What is the Transport layer of the TCP/IP model responsible for?

a)

It transports packets as datagrams along different routes to reach their destination.

b)

It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.

c)

It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.

d)

It deals with all aspects of the physical components of network connectivity and connects with different network types.

4.

What needs to be configured if the NAT property 'Translate destination on client side' is not enabled in Global properties?

a)

Proxy ARP for the translated destination address on the gateway

b)

A static route to the original destination address on the client

c)

Policy-based routing for all NATed connections

d)

DHCP reservation for the translated destination address

5.

In the Check Point Security Management Architecture, which component(s) can store logs?

a)

SmartConsole

b)

Security Management Server and Security Gateway

c)

Security Management Server

d)

SmartConsole and Security Management Server

6.

If the NAT property "Translate destination on client side" is not enabled in Global properties, what needs to be configured on the client side?

a)

A host route to route to the destination IP

b)

Use the file local.arp to add the ARP entries for NAT to work

c)

Nothing; the Gateway takes care of all details necessary

d)

Enable "Allow bi-directional NAT" for NAT to work correctly

7.

In order to install a license, it must first be added to the blank.

a)

User Center

b)

SmartConsole

c)

Security Gateway

d)

Security Management Server

8.

When logging in for the first time to a Security management Server through SmartConsole, a fingerprint is saved to the:

a)

Security Management Server’s /home/.fgpt file and is available for future SmartConsole authentications.

b)

Windows registry is available for future Security Management Server authentications.

c)

There is no memory used for saving a fingerprint anyway.

d)

SmartConsole cache is available for future Security Management Server authentications.

9.

Fill in the blank: By default, the SIC certificates issued by R80 Management Server are based on the algorithm.

a)

SHA-256

b)

SHA-200

c)

MD5

10.

Which message indicates IKE Phase 2 has completed successfully?

a)

Quick Mode Complete

b)

Aggressive Mode Complete

c)

Main Mode Complete

d)

IKE Mode Complete

11.

Administrator Dave logs into R80 Management Server to review and makes some rule changes. He notices that there is a padlock sign next to the DNS rule in the Rule Base. What does this indicate?

a)

It is an implied rule controlled by Global Properties and cannot be edited

b)

The rule is currently locked by another administrator session

c)

The rule is disabled and will not be enforced

d)

The rule is encrypted by SIC and must be re-initialized

12.

What Check Point tool is used to automatically update Check Point products for the Gaia OS?

a)

Check Point INSPECT Engine

b)

Check Point Upgrade Service Engine

c)

Check Point Update Engine

d)

Check Point Upgrade Installation Service

13.

You are the Check Point administrator for Alpha Corp with an R80 Check Point estate. You have received a call by one of the management users stating that they are unable to browse the Internet with their new tablet connected to the company Wireless. The Wireless system goes through the Check Point Gateway. How do you review the logs to see what the problem may be?

a)

Open SmartLog and connect remotely to the IP of the wireless controller

b)

Open SmartView Tracker and filter the logs for the IP address of the tablet

14.

What are the advantages of a "shared policy" in R80?

a)

Allows the administrator to share a policy between all the users identified by the Security Gateway

b)

Allows the administrator to share a policy between all the administrators managing the Security Management Server

c)

Allows the administrator to share a policy so that it is available to use in another Policy Package

d)

Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway

15.

To view statistics on detected threats, which Threat Tool would an administrator use?

a)

Protections

b)

IPS Protections

c)

Profiles

d)

ThreatWiki

16.

What is the purpose of a Clean-up Rule?

a)

Clean-up Rules do not serve any purpose.

b)

Provide a metric for determining unnecessary rules.

c)

To drop any traffic that is not explicitly allowed.

d)

Used to better optimize a policy.

17.

What are the two types of NAT supported by the Security Gateway?

a)

Destination and Hide

b)

Hide and Static

c)

Static and Source

d)

Source and Destination

18.

Vanessa is attempting to log into the Gaia Web Portal. She is able to login successfully. Then she tries the same username and password for SmartConsole but gets the message in the screenshot image below. She has checked that the IP address of the Server is correct and the username and password she used to login into Gaia is also correct. What is the most likely reason?

a)

Check Point R80 SmartConsole authentication is more secure than in previous versions and Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.

b)

Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.

c)

SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.

d)

Authentication failed because Vanessa’s username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.

19.

What is the most complete definition of the difference between the Install Policy button on the SmartConsole’s tab, and the Install Policy within a specific policy?

a)

The Global one also saves and published the session before installation.

b)

The Global one can install multiple selected policies at the same time.

c)

The local one does not install the Anti-Malware policy along with the Network policy.

d)

The second one pre-select the installation for only the current policy and for the applicable gateways.

20.

Which of the following is used to initially create trust between a Gateway and Security Management Server?

a)

Internal Certificate Authority

b)

Token

c)

One-time Password

d)

Certificate

21.

When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?

a)

Access Role

b)

User Group

c)

SmartDirectory Group

d)

Group Template

22.

The ______ software blade package uses CPU-level and OS-level sandboxing in order to detect and block malware.

a)

Next Generation Threat Prevention

b)

Next Generation Threat Emulation

c)

Next Generation Threat Extraction

d)

Next Generation Firewall

23.

Fill in the blank: Once a certificate is revoked from the Security GateWay by the Security Management Server, the certificate information is ________.

a)

Sent to the Internal Certificate Authority.

b)

Sent to the Security Administrator.

c)

Stored on the Security Management Server.

d)

Stored on the Certificate Revocation List.

24.

Which type of attack can a firewall NOT prevent?

a)

Network Bandwidth Saturation

b)

Buffer Overflow

c)

SYN Flood

d)

SQL Injection

25.

R80 is supported by which of the following operating systems:

a)

Windows only

b)

Linux only

c)

Windows and Linux

d)

macOS only

26.

What Check Point technologies deny or permit network traffic?

a)

Application Control, DLP

b)

Packet Filtering, Stateful Inspection, Application Layer Firewall

c)

ACL, SandBlast, MPT

d)

IPS, Mobile Threat Protection

27.

How do you manage Gaia?

a)

Through CLI and WebUI

b)

Through CLI only

c)

Through SmartDashboard only

d)

Through CLI, WebUI, and SmartDashboard

28.

What licensing feature is used to verify licenses and activate new licenses added to the License and Contracts repository?

a)

Verification tool

b)

Verification licensing

c)

Automatic licensing

d)

Automatic licensing and Verification tool

29.

The Hit count feature allows tracking the number of connections that each rule matches. Will the Hit count feature work independently from logging and track the hits even if the Track option is set to None?

a)

No; Hit Count will be shown only for rules with Track options set as Log or Alert

b)

Yes; Hit Count works regardless of the Track setting

c)

Yes; Hit Count works when Track is set to None or Noise

d)

No; Hit Count requires Track to be set to Detailed Log only

30.

How many layers make up the TCP/IP model?

a)

2

b)

7

c)

6

d)

4

31.

In a Distributed deployment, the Security Gateway and the Security Management software are installed on what platforms?

a)

Different computers or appliances.

b)

The same computer or appliance.

c)

Both on virtual machines or both on appliances but not mixed.

d)

In Azure and AWS cloud environments.

32.

Which of the following licenses are considered temporary?

a)

Plug-and-play (Trial) and Evaluation

b)

Perpetual and Trial

c)

Evaluation and Subscription

d)

Subscription and Perpetual

33.

Fill in the blanks: In _____ NAT, Only the ________ is translated.

a)

Hide; source

b)

Static; destination

c)

Dynamic; destination

d)

Bidirectional; service

34.

Fill in the blank: SmartConsole, SmartEvent GUI client, and ______ allow viewing of billions of consolidated logs and shows them as prioritized security events.

a)

SmartView Web Application

b)

SmartTracker

c)

SmartMonitor

d)

SmartReporter

35.

To increase security, the administrator has modified the Core protection 'Host Port Scan' from 'Medium' to 'High' Predefined Sensitivity. Which Policy should the administrator install after Publishing the changes?

a)

The Access Control and Threat Prevention Policies.

b)

The Access Control Policy.

36.

When changes are made to a Rule base, it is important to ________ to enforce changes.

a)

Publish database

b)

Activate policy

c)

Install policy

d)

Save changes

37.

The Online Activation method is available for Check Point manufactured appliances. How does the administrator use the Online Activation method?

a)

The SmartLicensing GUI tool must be launched from the SmartConsole for the Online Activation tool to start automatically.

b)

No action is required if the firewall has internet access and a DNS server to resolve domain names.

c)

Using the Gaia First Time Configuration Wizard, the appliance connects to the Check Point User Center and downloads all necessary licenses and contracts.

38.

Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility. Which statement is true?

a)

Manual NAT can offer more flexibility than Automatic NAT.

b)

Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.

c)

Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading.

d)

Automatic NAT can offer more flexibility than Manual NAT.

39.

Fill in the blank: The _____ feature allows administrators to share a policy with other policy packages.

a)

Concurrent policy packages

b)

Concurrent policies

c)

Global Policies

d)

Shared policies

40.

When dealing with rule base layers, what two layer types can be utilized?

a)

Ordered Layers and Inline Layers

b)

Inbound Layers and Outbound Layers

c)

R81.10 does not support Layers

d)

Structured Layers and Overlap Layers

41.

Application Control/URL filtering database library is known as:

a)

Application database

b)

AppWiki

c)

Application-Forensic Database

d)

Application Library

42.

If there is an Accept Implied Policy set to "First", what is the reason Jorge cannot see any logs?

a)

Log Implied Rule was not set correctly on the track column on the rules base.

b)

Track log column is set to Log instead of Full Log.

c)

Track log column is set to none.

d)

Log Implied Rule was not selected on Global Properties.

43.

A layer can support different combinations of blades What are the supported blades:

a)

Firewall. URLF, Content Awareness and Mobile Access

b)

Firewall (Network Access Control). Application & URL Filtering. Content Awareness and Mobile Access

c)

Firewall. NAT, Content Awareness and Mobile Access

d)

Firewall (Network Access Control). Application & URL Filtering and Content Awareness

44.

Fill in the blank Once a license is activated, a ____________ should be installed.

a)

contract file

b)

security policy

c)

SmartConsole client

d)

VPN certificate

45.

When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored?

a)

SmartConsole installed device

b)

Check Point user center

c)

Security Management Server

d)

Security Gateway

46.

What technologies are used to deny or permit network traffic?

a)

Stateful Inspection, Firewall Blade, and URL/Application Blade

b)

Packet Filtering, Stateful Inspection, and Application Layer Firewall

c)

Firewall Blade, URL/Application Blade and IPS

d)

Stateful Inspection, URL/Application Blade, and Threat Prevention

47.

Fill in the blanks: A Check Point software license consists of a__________ and ________.

a)

Software blade; software container

b)

Software package; signature

c)

Signature; software blade

d)

Software container software package

48.

Which one of the following is the preferred licensing model? Select the BEST answer

a)

Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.

b)

Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway.

c)

Central licensing because it ties the package license to the MAC-address of the Security Management Server's Mgmt-interface and has no dependency on the gateway.

d)

Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency.

49.

Which command is used to add users to or from existing roles?

a)

add rba user roles

b)

add user

c)

add rba user

d)

add user roles

50.

If an administrator wants to restrict access to a network resource only allowing certain users to access it, and only when they are on a specific network what is the best way to accomplish this?

a)

Create an inline layer where the destination is the target network resource. Define sub-rules allowing only specific sources to access the target resource.

b)

Use a "New Legacy User at Location", specifying the LDAP user group that the users belong to, at the desired location.

c)

Create a rule allowing only specific source IP addresses access to the target network resource.

d)

Create an Access Role object, with specific users or user groups specified, and specific networks defined. Use this access role as the "Source" of an Access Control rule.

51.

Fill in the blanks: A Security Policy is created in_____, stored in the_____ and Distributed to the various

a)

Rule base. Security Management Server Security Gateways

b)

The Check Point database. SmartConsole, Security Gateways

52.

What is the order of NAT priorities?

a)

IP pool NAT, static NAT, hide NAT

b)

Static NAT, hide NAT, IP pool NAT

c)

Static NAT, IP pool NAT, hide NAT

d)

Static NAT, automatic NAT, hide NAT

53.

While enabling the Identity Awareness blade, the Identity Awareness wizard does not automatically detect the Windows domain. Why does it not detect the Windows domain?

a)

SmartConsole machine is not part of the domain

b)

Security Gateway is not part of the domain

c)

Identity Awareness is not enabled on Global properties

d)

Security Management Server is not part of the domain