Unique Top-selling 156-315.81 Exams - New 2024 CheckPoint Pratice Exam [Q172-Q187]

Share

Unique Top-selling 156-315.81 Exams - New 2024 CheckPoint Pratice Exam

Check Point Certified Security Expert Dumps 156-315.81 Exam for Full Questions - Exam Study Guide

NEW QUESTION # 172
Which command lists firewall chain?

  • A. fw list chain
  • B. fw chain module
  • C. fwctl chain
  • D. fw tab -t chainmod

Answer: C

Explanation:
Explanation
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/T


NEW QUESTION # 173
Which of the following Central Deployment is NOT a limitation in R81.20 SmartConsole?

  • A. Security Gateways/Clusters in ClusterXL HA new mode
  • B. Security Gateway Clusters in Load Sharing mode
  • C. Dedicated Log Server
  • D. Dedicated SmartEvent Server

Answer: B

Explanation:
Explanation
Security Gateway Clusters in Load Sharing mode are not supported by the Central Deployment feature in R81.20 SmartConsole. According to the Check Point R81.20 Known Limitations article1, Central Deployment in SmartConsole does not support:
Connection from SmartConsole Client to the Management Server through a proxy server. In this case, use the applicable API command ClusterXL in Load Sharing mode VRRP Cluster Installation of a package on a VSX VSLS Cluster that contains more than 3 members.
On Multi-Domain Servers: Global Domain, or the MDS context
Standalone server
Standby Security Management Server or Multi-Domain Security Management
Scalable Platforms 40000 / 60000
SMB Appliances
The other options are supported by the Central Deployment feature in R81.20 SmartConsole. Dedicated Log Server, Dedicated SmartEvent Server, and Security Gateways/Clusters in ClusterXL HA new mode can be selected as targets for installing packages using the Central Deployment wizard.


NEW QUESTION # 174
Check Point Management (cpm) is the main management process in that it provides the architecture for a consolidates management console. CPM allows the GUI client and management server to communicate via web services using ___________.

  • A. TCP port 19009
  • B. TCP Port 18191
  • C. TCP Port 18209
  • D. TCP Port 18190

Answer: A

Explanation:
Explanation
Check Point Management (cpm) is the main management process that provides the architecture for a consolidated management console. CPM allows the GUI client and management server to communicate via web services using TCP port 19009 by default. References: CPM process


NEW QUESTION # 175
The Check Point history feature in R81 provides the following:

  • A. Policy Installation Date only
  • B. View install changes
  • C. Policy Installation Date, view install changes and install specific version
  • D. View install changes and install specific version

Answer: A


NEW QUESTION # 176
Which two Cluster Solutions are available under R81.10?

  • A. VRRP and IP Clustering
  • B. VRRPandHSRP
  • C. ClusterXL and VRitP
  • D. ClusterXL and NSRP

Answer: C


NEW QUESTION # 177
You work as a security administrator for a large company. CSO of your company has attended a security conference where he has learnt how hackers constantly modify their strategies and techniques to evade detection and reach corporate resources. He wants to make sure that his company has the tight protections in place. Check Point has been selected for the security vendor.
Which Check Point product protects BEST against malware and zero-day attacks while ensuring quick delivery of safe content to your users?

  • A. SandBlast
  • B. IPS AND Application Control
  • C. IPS, anti-virus and e-mail security
  • D. IPS, anti-virus and anti-bot

Answer: A


NEW QUESTION # 178
Which tool provides a list of trusted files to the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?

  • A. ThreatWiki
  • B. Whitelist Files
  • C. AppWiki
  • D. IPS Protections

Answer: B

Explanation:
Explanation
According to the Check Point website, Whitelist Files is the tool that provides a list of trusted files to the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed. Whitelist Files can be configured in SmartConsole under Threat Prevention > Policy > Whitelist Files. The other tools are either not related or not valid tools. References: Whitelist Files


NEW QUESTION # 179
Selecting an event displays its configurable properties in the Detail pane and a description of the event in the Description pane. Which is NOT an option to adjust or configure?

  • A. Policy
  • B. Severity
  • C. Automatic reactions
  • D. Threshold

Answer: A

Explanation:
Explanation
An event is a notification that something significant has occurred on a Check Point product or network. Events are generated by various sources, such as blades, gateways, servers, SmartEvent, etc. You can view and manage events in SmartConsole by using the view. Selecting an event displays its configurable properties in the Detail pane and a description of the event in the Description pane.
The configurable properties include:
Severity: The level of importance or urgency of the event. You can change the severity of an event by selecting a different value from the drop-down list.
Automatic reactions: The actions that are triggered when an event occurs. You can add, edit, or delete automatic reactions for an event by clicking on the icon or the pencil icon.
Threshold: The minimum number or frequency of occurrences of an event that triggers an automatic reaction. You can change the threshold of an event by entering a different value in the text box.
The policy is not an option to adjust or configure for an event. The policy is a set of rules that define how to handle events based on their source, type, severity, etc. You can create and manage policies in SmartEvent by using the Policies tab in the Logs & Monitor view. References: R81 Logging and Monitoring Administration Guide


NEW QUESTION # 180
What is the order of NAT priorities?

  • A. Static NAT, hide NAT, IP pool NAT
  • B. Static NAT, automatic NAT, hide NAT
  • C. Static NAT, IP pool NAT, hide NAT
  • D. IP pool NAT, static NAT, hide NAT

Answer: C


NEW QUESTION # 181
What is the minimum number of CPU cores required to enable CoreXL?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
Default number of CoreXL IPv4 FW instances:
Note: The real number of CoreXL FW instances depends on the current CoreXL license.
Number of
CPU cores Default number of
CoreXL IPv4
FW instances Default number of
Secure Network Distributors
(SNDs)
1 1
Note: CoreXL is disabled 0
Note: CoreXL is disabled
2 2 2
4 3 1
6 - 20 [Number of CPU cores] - 2 2
More than 20 (1) [Number of CPU cores] - 4 4


NEW QUESTION # 182
Which packet info is ignored with Session Rate Acceleration?

  • A. source port ranges
  • B. source ip
  • C. source port
  • D. same info from Packet Acceleration is used

Answer: C

Explanation:
Identifies connections by five attributes
- source address
- destination address
- source port
- destination port
- protocol


NEW QUESTION # 183
To help SmartEvent determine whether events originated internally or externally you must define using the Initial Settings under General Settings in the Policy Tab. How many options are available to calculate the traffic direction?

  • A. 4 Incoming; Outgoing; Internal; Other
  • B. 2 Internal; External
  • C. 3 Incoming; Outgoing; Network
  • D. 5 Network; Host; Objects; Services; API

Answer: A

Explanation:
Explanation
To help SmartEvent determine whether events originated internally or externally, you must define the traffic direction using the Initial Settings under General Settings in the Policy Tab. There are four options available to calculate the traffic direction: Incoming, Outgoing, Internal, and Other. Incoming means the source is external and the destination is internal. Outgoing means the source is internal and the destination is external.
Internal means both the source and the destination are internal. Other means both the source and the destination are external. References: SmartEvent R81 Administration Guide


NEW QUESTION # 184
In the Check Point Firewall Kernel Module, each Kernel is associated with a key, which specifies the type of traffic applicable to the chain module. For Wire Mode configuration, chain modules marked with
____________ will not apply.

  • A. ffff
  • B. 0
  • C. 1
  • D. 2

Answer: B

Explanation:
Explanation
In the Check Point Firewall Kernel Module, each kernel is associated with a key, which specifies the type of traffic applicable to the chain module. For Wire Mode configuration, chain modules marked with 1 will not apply, as they are related to NAT, VPN, or other features that are not supported in Wire Mode. Wire Mode is a mode of operation that allows transparent traffic forwarding without any inspection or modification by the firewall. References: Check Point Security Expert R81 Course, Wire Mode Configuration Guide


NEW QUESTION # 185
What is not a purpose of the deployment of Check Point API?

  • A. Create a customized GUI Client for manipulating the objects database
  • B. Execute an automated script to perform common tasks
  • C. Integrate Check Point products with 3rd party solution
  • D. Create products that use and enhance the Check Point solution

Answer: A

Explanation:
Explanation
The deployment of Check Point API does not have the purpose of creating a customized GUI Client for manipulating the objects database. The Check Point API is a web service that allows external applications to interact with the Check Point management server using standard methods such as HTTP(S) requests and JSON objects. The Check Point API can be used to execute an automated script to perform common tasks, create products that use and enhance the Check Point solution, and integrate Check Point products with 3rd party solutions. However, creating a customized GUI Client for manipulating the objects database is not a supported or intended use case of the Check Point API.


NEW QUESTION # 186
GAIA greatly increases operational efficiency by offering an advanced and intuitive software update agent, commonly referred to as the:

  • A. Check Point Software Update Daemon
  • B. Check Point Remote Installation Daemon (CPRID)
  • C. Check Point Software Update Agent
  • D. Check Point Update Service Engine

Answer: D

Explanation:
Explanation
GAIA greatly increases operational efficiency by offering an advanced and intuitive software update agent, commonly referred to as the Check Point Update Service Engine. This agent allows you to download and install software updates, hotfixes, upgrade packages, etc., from Check Point servers or from a local repository.
The Check Point Update Service Engine can be accessed via SmartConsole or via WebUI or CLI on GAIA.
References: [Gaia Administration Guide R81], page 77.


NEW QUESTION # 187
......

Best way to practice test for CheckPoint 156-315.81: https://evedumps.testkingpass.com/156-315.81-testking-dumps.html