[Nov 12, 2021] Get New 156-915.80 Certification Practice Test Questions Exam Dumps [Q209-Q232]

Share

[Nov 12, 2021] Get New 156-915.80 Certification Practice Test Questions Exam Dumps

Real 156-915.80 Exam Dumps Questions Valid 156-915.80 Dumps PDF


Who should take the 156-915.80 exam

The Check Point Certified Security Expert certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled in System Security Consultant and Server Managers. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Check Point Certified Security Expert Update - R80 (CCSE) 156-915.80 Exam certification provides proof of this advanced knowledge and skill. If a person has the prerequisite CCSE certification and skills required of a Check Point Certified Security Expert Update - R80 (CCSE) 156-915.80 Exam then he should take this exam.

 

NEW QUESTION 209
Charles requests a Website while using a computer not in the net_singapore network.

What is TRUE about his location restriction?

  • A. Source setting in Source column always takes precedence.
  • B. Source setting in User Properties always takes precedence.
  • C. It depends on how the User Auth object is configured; whether User Properties or Source Restriction takes precedence.
  • D. As location restrictions add up, he would be allowed from net_singapore and net_sydney.

Answer: C

 

NEW QUESTION 210
You are a Security Administrator who has installed Security Gateway R80 on your network. You need to allow a specific IP address range for a partner site to access your intranet Web server. To limit the partner's access for HTTP and FTP only, you did the following:
1) Created manual Static NAT rules for the Web server.
2) Cleared the following settings in the Global Properties > Network Address Translation screen:
-Allow bi-directional NAT
-Translate destination on client side
Do the above settings limit the partner's access?

  • A. Yes. This will ensure that traffic only matches the specific rule configured for this traffic, and that the Gateway translates the traffic after accepting the packet.
  • B. No. The first setting is not applicable. The second setting will reduce performance.
  • C. No. The first setting is only applicable to automatic NAT rules. The second setting will force translation by the kernel on the interface nearest to the client.
  • D. Yes. Both of these settings are only applicable to automatic NAT rules.

Answer: C

 

NEW QUESTION 211
Which file gives you a list of all security servers in use, including port number?

  • A. $FWDIR/conf/serversd.conf
  • B. $FWDIR/conf/fwauthd.conf
  • C. $FWDIR/conf/servers.conf
  • D. $FWDIR/conf/conf.conf

Answer: B

 

NEW QUESTION 212
You find that Gateway fw2 can NOT be added to the cluster object. What are possible reasons for that?
Exhibit:

1) fw2 is a member in a VPN community.
2) ClusterXL software blade is not enabled on fw2.
3) fw2 is a DAIP Gateway.

  • A. 1 or 3
  • B. 1 or 2
  • C. 2 or 3
  • D. All

Answer: A

 

NEW QUESTION 213
Which command shows the current connections distributed by CoreXL FW instances?

  • A. fw ctl multik stat
  • B. fw ctl affinity -l
  • C. fw ctl instances -v
  • D. fw ctl iflist

Answer: A

Explanation:
Explanation
The fw ctl multik stat and fw6ctl multik stat (multi-kernel statistics) commands show information for each kernel instance. The state and processing core number of each instance is displayed, along with:
* The number of connections currently being handled.
* The peak number of concurrent connections the instance has handled since its inception.

 

NEW QUESTION 214
Match the ClusterXL modes with their configurations.
Exhibit:

  • A. A-2, B-3, C-4, D-1
  • B. A-2, B-3, C-1, D-5
  • C. A-5, B-2, C-4, D-1
  • D. A-3, B-5, C-1, D-4

Answer: D

 

NEW QUESTION 215
What is the purpose of Priority Delta in VRRP?

  • A. When a box is up, Effective Priority = Priority + Priority Delta
  • B. When an Interface is up, Effective Priority = Priority + Priority Delta
  • C. When a box fail, Effective Priority = Priority - Priority Delta
  • D. When an Interface fail, Effective Priority = Priority - Priority Delta

Answer: D

Explanation:
Section: (none)
Explanation/Reference:
Explanation:
Each instance of VRRP running on a supported interface may monitor the link state of other interfaces.
The monitored interfaces do not have to be running VRRP. If a monitored interface loses its link state, then VRRP will decrement its priority over a VRID by the specified delta value and then will send out a new VRRP HELLO packet. If the new effective priority is less than the priority a backup platform has, then the backup platform will beging to send out its own HELLO packet. Once the master sees this packet with a priority greater than its own, then it releases the VIP.
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk38524

 

NEW QUESTION 216
Which one of the following is true about Threat Emulation?

  • A. Takes less than a second to complete
  • B. Works on MS Office and PDF files only
  • C. Takes minutes to complete (less than 3 minutes)
  • D. Always delivers a file

Answer: C

 

NEW QUESTION 217
When deploying multiple clustered firewalls on the same subnet, what does the firewall administrator need to configure to prevent CCP broadcasts being sent to the wrong cluster?

  • A. Set the fwha_mac_magic parameter in the $FWDIR/boot/fwkern.conf file
  • B. Set the cluster global ID using the command "cphaconf cluster_id set <value>"
  • C. Set the fwha_mac_magic_forward parameter in the $CPDIR/boot/modules/ha_boot.
    conf
  • D. Set the cluster global ID using the command "fw ctt set cluster_id <value>"

Answer: B

Explanation:
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk25977

 

NEW QUESTION 218
The Firewall kernel is replicated multiple times, therefore:

  • A. The Firewall kernel only touches the packet if the connection is accelerated
  • B. The Firewall can run different policies per core
  • C. The Firewall can run the same policy on all cores
  • D. The Firewall kernel is replicated only with new connections and deletes itself once the connection times out

Answer: C

Explanation:
On a Security Gateway with CoreXL enabled, the Firewall kernel is replicated multiple times. Each replicated copy, or instance, runs on one processing core. These instances handle traffic concurrently, and each instance is a complete and independent inspection kernel. When CoreXL is enabled, all the kernel instances in the Security Gateway process traffic through the same interfaces and apply the same security policy.
Reference:
https://sc1.checkpoint.com/documents/R77/CP_R77_PerformanceTuning_WebAdmin/6731
.htm

 

NEW QUESTION 219
Jennifer McHanry is CEO of ACME. She recently bought her own personal iPad. She wants use her iPad to access the internal Finance Web server. Because the iPad is not a member of the Active Directory domain, she cannot identify seamlessly with AD Query.
However, she can enter her AD credentials in the Captive Portal and then get the same access as on her office computer. Her access to resources is based on rules in the R80 Firewall Rule Base.
To make this scenario work, the IT administrator must:
1) Enable Identity Awareness on a gateway and select Captive Portal as one of the Identity Sources.
2) In the Portal Settings window in the User Access section, make sure that Name and password login is selected.
3) Create a new rule in the Firewall Rule Base to let Jennifer McHanry access network destinations. Select accept as the Action.
Ms. McHanry tries to access the resource but is unable. What should she do?

  • A. Have the security administrator select the Action field of the Firewall Rule "Redirect HTTP connections to an authentication (captive) portal"
  • B. Install the Identity Awareness agent on her iPad
  • C. Have the security administrator select Any for the Machines tab in the appropriate Access Role
  • D. Have the security administrator reboot the firewall

Answer: A

 

NEW QUESTION 220
What API command below creates a new host with the name "New Host" and IP address of
"192.168.0.10"?

  • A. add host name "New Host" ip-address "192.168.0.10"
  • B. new host name "New Host" ip-address "192.168.0.10"
  • C. set host name "New Host" ip-address "192.168.0.10"
  • D. create host name "New Host" ip-address "192.168.0.10"

Answer: A

Explanation:
Sample Command with SmartConsole CLI You can use the add host command to create a new host and then publish the changes. > add host name "Sample_Host" ip-address "192.0.2.3" > publish

 

NEW QUESTION 221
NAT rules are prioritized in which order?
1. Automatic Static NAT
2. Automatic Hide NAT
3. Manual/Pre-Automatic NAT
4. Post-Automatic/Manual NAT rules

  • A. 4, 3, 1, 2
  • B. 3, 1, 2, 4
  • C. 1, 4, 2, 3
  • D. 1, 2, 3, 4

Answer: B

 

NEW QUESTION 222
Which web services protocol is used to communicate to the Check Point R80 identity Awareness Web APi?

  • A. SOAP
  • B. XML-RPC
  • C. REST
  • D. XLANG

Answer: C

Explanation:
Section: (none)
Explanation/Reference:
Explanation:
The Identity Web API uses the REST protocol over SSL. The requests and responses are HTTP and in JSON format.
Reference: https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/ CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.10/ WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/148699

 

NEW QUESTION 223
In R80 spoofing is defined as a method of:

  • A. Detecting people using false or wrong authentication logins
  • B. Making packets appear as if they come from an authorized IP address.
  • C. Disguising an illegal IP address behind an authorized IP address through Port Address Translation.
  • D. Hiding your firewall from unauthorized users.

Answer: B

Explanation:
Explanation
IP spoofing replaces the untrusted source IP address with a fake, trusted one, to hijack connections to your network. Attackers use IP spoofing to send malware and bots to your protected network, to execute DoS attacks, or to gain unauthorized access.
References:

 

NEW QUESTION 224
Can you implement a complete IPv6 deployment without IPv4 addresses?

  • A. No. SmartCenter cannot be accessed from everywhere on the Internet.
  • B. Yes. Only one TCP stack (IPv6 or IPv4) can be used at the same time.
  • C. No. IPv4 addresses are required for management.
  • D. Yes, There is no requirement for managing IPv4 addresses.

Answer: D

 

NEW QUESTION 225
Which statement is NOT TRUE about Delta synchronization?

  • A. Using UDP Multicast or Broadcast on port 8116
  • B. Quicker than Full Sync
  • C. Using UDP Multicast or Broadcast on port 8161
  • D. Transfers changes in the Kernel labels between cluster members

Answer: C

 

NEW QUESTION 226
In order to get info about assignment (FW, SND) of all CPUs in your SGW, what is the most accurate CLI command?

  • A. fw ctl sdstat
  • B. cpinfo
  • C. fw ctl multik stat
  • D. fw ctl affinity -l -a -r -v

Answer: D

 

NEW QUESTION 227
Which command will reset the kernel debug options to default settings?

  • A. fw ctl debug set 0
  • B. fw ctl debug 0
  • C. fw ctl dbg resetall
  • D. fw ctl dbg -a 0

Answer: B

Explanation:
Reset the debugs to the default.
In case someone changed the setting in the past and since then the firewall was not rebooted we should set all back to the defaults.

 

NEW QUESTION 228
Using mgmt_cli, what is the correct syntax to import a host object called Server_1 from the CLI?

  • A. mgmt_cli add-host "Server_1" ip_ address "10.15.123.10" - format txt
  • B. mgmt_ cli add object-host "Server_ 1" ip-address "10.15.123.10" - format json
  • C. mgmt_ cli add host name "Server_ 1" ip-address "10.15.123.10" - format json
  • D. mgmt_cli add object "Server_ 1" ip-address "10.15.123.10" - format json

Answer: C

Explanation:
Example:
mgmt_cli add host name "New Host 1" ip-address "192.0.2.1" --format json
* "--format json" is optional. By default the output is presented in plain text.
Reference: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add- host~v1.1%20

 

NEW QUESTION 229
A Threat Prevention profile is a set of configurations based on the following. (Choose all that apply.)

  • A. Anti-Virus settings, Anti-Bot settings, Threat Emulation settings, Intrusion-prevention settings, HTTPS inspection settings
  • B. Anti-Virus settings, Anti-Bot settings, Threat Emulation settings, Intrusion-prevention settings
  • C. Anti-Bot settings, Threat Emulation settings, Intrusion-prevention settings, HTTPS inspection settings
  • D. Anti-Virus settings, Anti-Bot settings, Threat Emulation settings

Answer: D

 

NEW QUESTION 230
CORRECT TEXT
Fill in the blank. The command that typically generates the firewall application, operating system, and hardware specific drivers is _________ .

Answer:

Explanation:
snapshot

 

NEW QUESTION 231
You have existing dbedit scripts from R77. Can you use them with R80.10?

  • A. dbedit is not supported in R80.10
  • B. dbedit scripts are being replaced by mgmt._cli in R80.10
  • C. dbedit is fully supported in R80.10
  • D. You can use dbedit to modify threat prevention or access policies, but not create or modify layers

Answer: B

Explanation:
Explanation/Reference:
Explanation:
dbedit (or GuiDbEdit) uses the cpmi protocol which is gradually being replaced by the new R80.10 automation architecture. cpmi clients are still supported in R80.10, but there are some functionalities that cannot be managed by cpmi anymore. For example, the Access and Threat policies do not have a cpmi representation. They can be managed only by the new mgmt_cli and not by cpmi clients. There are still many tables that have an inner cpmi representation (for example, network objects, services, servers, and global properties) and can still be managed using cpmi.
Reference: https://www.checkpoint.com/downloads/product-related/r80.10-mgmt-architecture-overview.pdf

 

NEW QUESTION 232
......

156-915.80 Exam Dumps - PDF Questions and Testing Engine: https://www.lead2passed.com/CheckPoint/156-915.80-practice-exam-dumps.html