WorksheetsDUMSA_8.1
Total questions: 53
Worksheet time: 27mins
Which command shows the installed licenses?
cplic print
print cplic
fwllic print
show licenses
Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?
SmartManager
SmartConsole
Security Gateway
Security Management Server
What is the Transport layer of the TCP/IP model responsible for?
It transports packets as datagrams along different routes to reach their destination.
It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.
It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.
It deals with all aspects of the physical components of network connectivity and connects with different network types.
What needs to be configured if the NAT property 'Translate destination on client side' is not enabled in Global properties?
Proxy ARP for the translated destination address on the gateway
A static route to the original destination address on the client
Policy-based routing for all NATed connections
DHCP reservation for the translated destination address
In the Check Point Security Management Architecture, which component(s) can store logs?
SmartConsole
Security Management Server and Security Gateway
Security Management Server
SmartConsole and Security Management Server
If the NAT property "Translate destination on client side" is not enabled in Global properties, what needs to be configured on the client side?
A host route to route to the destination IP
Use the file local.arp to add the ARP entries for NAT to work
Nothing; the Gateway takes care of all details necessary
Enable "Allow bi-directional NAT" for NAT to work correctly
In order to install a license, it must first be added to the blank.
User Center
SmartConsole
Security Gateway
Security Management Server
When logging in for the first time to a Security management Server through SmartConsole, a fingerprint is saved to the:
Security Management Server’s /home/.fgpt file and is available for future SmartConsole authentications.
Windows registry is available for future Security Management Server authentications.
There is no memory used for saving a fingerprint anyway.
SmartConsole cache is available for future Security Management Server authentications.
Fill in the blank: By default, the SIC certificates issued by R80 Management Server are based on the algorithm.
SHA-256
SHA-200
MD5
Which message indicates IKE Phase 2 has completed successfully?
Quick Mode Complete
Aggressive Mode Complete
Main Mode Complete
IKE Mode Complete
Administrator Dave logs into R80 Management Server to review and makes some rule changes. He notices that there is a padlock sign next to the DNS rule in the Rule Base. What does this indicate?
It is an implied rule controlled by Global Properties and cannot be edited
The rule is currently locked by another administrator session
The rule is disabled and will not be enforced
The rule is encrypted by SIC and must be re-initialized
What Check Point tool is used to automatically update Check Point products for the Gaia OS?
Check Point INSPECT Engine
Check Point Upgrade Service Engine
Check Point Update Engine
Check Point Upgrade Installation Service
You are the Check Point administrator for Alpha Corp with an R80 Check Point estate. You have received a call by one of the management users stating that they are unable to browse the Internet with their new tablet connected to the company Wireless. The Wireless system goes through the Check Point Gateway. How do you review the logs to see what the problem may be?
Open SmartLog and connect remotely to the IP of the wireless controller
Open SmartView Tracker and filter the logs for the IP address of the tablet
What are the advantages of a "shared policy" in R80?
Allows the administrator to share a policy between all the users identified by the Security Gateway
Allows the administrator to share a policy between all the administrators managing the Security Management Server
Allows the administrator to share a policy so that it is available to use in another Policy Package
Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway
To view statistics on detected threats, which Threat Tool would an administrator use?
Protections
IPS Protections
Profiles
ThreatWiki
What is the purpose of a Clean-up Rule?
Clean-up Rules do not serve any purpose.
Provide a metric for determining unnecessary rules.
To drop any traffic that is not explicitly allowed.
Used to better optimize a policy.
What are the two types of NAT supported by the Security Gateway?
Destination and Hide
Hide and Static
Static and Source
Source and Destination
Vanessa is attempting to log into the Gaia Web Portal. She is able to login successfully. Then she tries the same username and password for SmartConsole but gets the message in the screenshot image below. She has checked that the IP address of the Server is correct and the username and password she used to login into Gaia is also correct. What is the most likely reason?
Check Point R80 SmartConsole authentication is more secure than in previous versions and Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.
Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.
SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.
Authentication failed because Vanessa’s username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.
What is the most complete definition of the difference between the Install Policy button on the SmartConsole’s tab, and the Install Policy within a specific policy?
The Global one also saves and published the session before installation.
The Global one can install multiple selected policies at the same time.
The local one does not install the Anti-Malware policy along with the Network policy.
The second one pre-select the installation for only the current policy and for the applicable gateways.
Which of the following is used to initially create trust between a Gateway and Security Management Server?
Internal Certificate Authority
Token
One-time Password
Certificate
When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?
Access Role
User Group
SmartDirectory Group
Group Template
The ______ software blade package uses CPU-level and OS-level sandboxing in order to detect and block malware.
Next Generation Threat Prevention
Next Generation Threat Emulation
Next Generation Threat Extraction
Next Generation Firewall
Fill in the blank: Once a certificate is revoked from the Security GateWay by the Security Management Server, the certificate information is ________.
Sent to the Internal Certificate Authority.
Sent to the Security Administrator.
Stored on the Security Management Server.
Stored on the Certificate Revocation List.
Which type of attack can a firewall NOT prevent?
Network Bandwidth Saturation
Buffer Overflow
SYN Flood
SQL Injection
R80 is supported by which of the following operating systems:
Windows only
Linux only
Windows and Linux
macOS only
What Check Point technologies deny or permit network traffic?
Application Control, DLP
Packet Filtering, Stateful Inspection, Application Layer Firewall
ACL, SandBlast, MPT
IPS, Mobile Threat Protection
How do you manage Gaia?
Through CLI and WebUI
Through CLI only
Through SmartDashboard only
Through CLI, WebUI, and SmartDashboard
What licensing feature is used to verify licenses and activate new licenses added to the License and Contracts repository?
Verification tool
Verification licensing
Automatic licensing
Automatic licensing and Verification tool
The Hit count feature allows tracking the number of connections that each rule matches. Will the Hit count feature work independently from logging and track the hits even if the Track option is set to None?
No; Hit Count will be shown only for rules with Track options set as Log or Alert
Yes; Hit Count works regardless of the Track setting
Yes; Hit Count works when Track is set to None or Noise
No; Hit Count requires Track to be set to Detailed Log only
How many layers make up the TCP/IP model?
2
7
6
4
In a Distributed deployment, the Security Gateway and the Security Management software are installed on what platforms?
Different computers or appliances.
The same computer or appliance.
Both on virtual machines or both on appliances but not mixed.
In Azure and AWS cloud environments.
Which of the following licenses are considered temporary?
Plug-and-play (Trial) and Evaluation
Perpetual and Trial
Evaluation and Subscription
Subscription and Perpetual
Fill in the blanks: In _____ NAT, Only the ________ is translated.
Hide; source
Static; destination
Dynamic; destination
Bidirectional; service
Fill in the blank: SmartConsole, SmartEvent GUI client, and ______ allow viewing of billions of consolidated logs and shows them as prioritized security events.
SmartView Web Application
SmartTracker
SmartMonitor
SmartReporter
To increase security, the administrator has modified the Core protection 'Host Port Scan' from 'Medium' to 'High' Predefined Sensitivity. Which Policy should the administrator install after Publishing the changes?
The Access Control and Threat Prevention Policies.
The Access Control Policy.
When changes are made to a Rule base, it is important to ________ to enforce changes.
Publish database
Activate policy
Install policy
Save changes
The Online Activation method is available for Check Point manufactured appliances. How does the administrator use the Online Activation method?
The SmartLicensing GUI tool must be launched from the SmartConsole for the Online Activation tool to start automatically.
No action is required if the firewall has internet access and a DNS server to resolve domain names.
Using the Gaia First Time Configuration Wizard, the appliance connects to the Check Point User Center and downloads all necessary licenses and contracts.
Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility. Which statement is true?
Manual NAT can offer more flexibility than Automatic NAT.
Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.
Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading.
Automatic NAT can offer more flexibility than Manual NAT.
Fill in the blank: The _____ feature allows administrators to share a policy with other policy packages.
Concurrent policy packages
Concurrent policies
Global Policies
Shared policies
When dealing with rule base layers, what two layer types can be utilized?
Ordered Layers and Inline Layers
Inbound Layers and Outbound Layers
R81.10 does not support Layers
Structured Layers and Overlap Layers
Application Control/URL filtering database library is known as:
Application database
AppWiki
Application-Forensic Database
Application Library
If there is an Accept Implied Policy set to "First", what is the reason Jorge cannot see any logs?
Log Implied Rule was not set correctly on the track column on the rules base.
Track log column is set to Log instead of Full Log.
Track log column is set to none.
Log Implied Rule was not selected on Global Properties.
A layer can support different combinations of blades What are the supported blades:
Firewall. URLF, Content Awareness and Mobile Access
Firewall (Network Access Control). Application & URL Filtering. Content Awareness and Mobile Access
Firewall. NAT, Content Awareness and Mobile Access
Firewall (Network Access Control). Application & URL Filtering and Content Awareness
Fill in the blank Once a license is activated, a ____________ should be installed.
contract file
security policy
SmartConsole client
VPN certificate
When you upload a package or license to the appropriate repository in SmartUpdate, where is the package or license stored?
SmartConsole installed device
Check Point user center
Security Management Server
Security Gateway
What technologies are used to deny or permit network traffic?
Stateful Inspection, Firewall Blade, and URL/Application Blade
Packet Filtering, Stateful Inspection, and Application Layer Firewall
Firewall Blade, URL/Application Blade and IPS
Stateful Inspection, URL/Application Blade, and Threat Prevention
Fill in the blanks: A Check Point software license consists of a__________ and ________.
Software blade; software container
Software package; signature
Signature; software blade
Software container software package
Which one of the following is the preferred licensing model? Select the BEST answer
Local licensing because it ties the package license to the IP-address of the gateway and has no dependency of the Security Management Server.
Central licensing because it ties the package license to the IP-address of the Security Management Server and has no dependency on the gateway.
Central licensing because it ties the package license to the MAC-address of the Security Management Server's Mgmt-interface and has no dependency on the gateway.
Local licensing because it ties the package license to the MAC-address of the gateway management interface and has no Security Management Server dependency.
Which command is used to add users to or from existing roles?
add rba user
add user
add rba user
add user
If an administrator wants to restrict access to a network resource only allowing certain users to access it, and only when they are on a specific network what is the best way to accomplish this?
Create an inline layer where the destination is the target network resource. Define sub-rules allowing only specific sources to access the target resource.
Use a "New Legacy User at Location", specifying the LDAP user group that the users belong to, at the desired location.
Create a rule allowing only specific source IP addresses access to the target network resource.
Create an Access Role object, with specific users or user groups specified, and specific networks defined. Use this access role as the "Source" of an Access Control rule.
Fill in the blanks: A Security Policy is created in_____, stored in the_____ and Distributed to the various
Rule base. Security Management Server Security Gateways
The Check Point database. SmartConsole, Security Gateways
What is the order of NAT priorities?
IP pool NAT, static NAT, hide NAT
Static NAT, hide NAT, IP pool NAT
Static NAT, IP pool NAT, hide NAT
Static NAT, automatic NAT, hide NAT
While enabling the Identity Awareness blade, the Identity Awareness wizard does not automatically detect the Windows domain. Why does it not detect the Windows domain?
SmartConsole machine is not part of the domain
Security Gateway is not part of the domain
Identity Awareness is not enabled on Global properties
Security Management Server is not part of the domain
