Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Checkpoint > CCSE > 156-315.82

156-315.82 Check Point Certified Security Expert R82 Question and Answers

Question # 4

John wants to execute a command on all members of an ElasticXL Cluster. Which command-line shell should he use?

A.

Expert

B.

Clish

C.

gClish

D.

Global API

Full Access
Question # 5

What is crucial in translating services, specifically destination ports, in a NAT rule?

A.

This can only be accomplished with the Automatic NAT Rule with “Translate Destination on Server Side” enabled.

B.

This can only be accomplished with Automatic NAT Rule in conjunction with Bi-Directional NAT.

C.

This can only be accomplished with the Automatic NAT Rule with “Automatic ARP Configuration” enabled.

D.

This has to be done with a Manual NAT Rule.

Full Access
Question # 6

When a solution is configured with Route-Based VPN method, what interfaces are used?

A.

The Gaia Portal Web User Interface, WebUI

B.

Only the internal interfaces, which are included in a special Route-Based Domain, Network Group object

C.

Virtual Tunnel Interfaces, VTI

D.

External interface with a secondary IP address

Full Access
Question # 7

From where can you open SmartEvent Settings & Policy App?

A.

Menu > Global Properties > Log and Alert

B.

Logs & Events > New tab > External Apps

C.

Logs & Events > Logs > External Apps

D.

Security Policies > Manage Policies > External Apps

Full Access
Question # 8

After upgrading the Primary Security Management Server from R81.20 to R82, Bob wants to use Central Deployment in SmartConsole R82 for the first time. How many installations, Jumbo Hotfixes, Hotfixes, or Upgrade Packages, can run at the same time?

A.

Up to 3 Gateways

B.

Up to 10 Gateways

C.

Up to 5 Gateways

D.

Only 1 Gateway

Full Access
Question # 9

The Management Server Database is exported during an Advanced Upgrade and later imported on a freshly deployed Management Server. The items that go along with this export include:

A.

Only objects are exported and imported with the database. Policies, certificates, and other settings are not included.

B.

Only objects and policies are exported with the database. Certificates are stored in a reserved area and cannot be exported.

C.

Network and routing configuration and all settings of the Check Point environment.

D.

Objects, policies, certificates, and other settings of the Check Point environment.

Full Access
Question # 10

What should be upgraded first in Advanced Upgrade Method?

A.

Dedicated Log Server

B.

Secondary Management Server

C.

Primary Management Server

D.

Security Gateway

Full Access
Question # 11

How many members are supported by an ElasticXL Cluster?

A.

Maximum three members per site with a maximum of three sites.

B.

Three members per site with a maximum of two sites.

C.

Maximum two members per site with a maximum of three sites.

D.

Up to four members per site with a maximum of two sites.

Full Access
Question # 12

How many packets are used in Aggressive Mode for negotiation?

A.

3

B.

4

C.

8

D.

6

Full Access
Question # 13

Choose the best answer about IKEv2.

A.

IKEv2 uses a two-phase concept like IKEv1; they are called Parent and Child.

B.

IKEv2 uses a two-phase concept like IKEv1; they are called Main and Quick.

C.

IKEv2 uses a two-phase concept like IKEv1; they are called Main and Aggressive.

D.

IKEv2 does not use the same phase concept as IKEv1.

Full Access
Question # 14

Which components can be upgraded using Central Deployment Tool, CDT?

A.

Gateways / Cluster Members

B.

Multi-Domain Servers, Management Servers, and Gateways

C.

Gateways, Clusters, and Management Servers

D.

Gateways, Clusters, and Standalone Deployments

Full Access
Question # 15

Alice and Bob are tasked by their security team lead with deploying Advanced Security Monitoring for all their Check Point Security systems. Which of the features and capabilities of SmartEvent is included?

A.

Full threat visibility

B.

Medium threat visibility

C.

Low threat visibility

D.

High threat visibility

Full Access
Question # 16

With R81 and higher, what are the two types of database dumps?

A.

CPD Dump and CPM Dump

B.

CPM Dump and Monitoring Dump

C.

Legacy Dump and Modern Dump

D.

FWD Dump and AUM Dump

Full Access
Question # 17

Which of the interface ports are bonded after the initial setup and configuration of an ElasticXL Cluster?

A.

magg1 and Sync

B.

Mgmt and Sync

C.

Management and magg1

D.

Management and Sync

Full Access
Question # 18

In Management HA, the failover is:

A.

Always manual.

B.

Automatic by default, but can be changed to manual.

C.

Manual by default, but can be changed to automatic.

D.

Always automatic.

Full Access
Question # 19

Alice wants to upgrade the current Security Management machine to R82, and she wants to check the Deployment Agent status over Gaia Clish. Which of the following Gaia Clish commands is correct?

A.

show agent status

B.

show installer packages

C.

show uninstaller status

D.

show installer status

Full Access
Question # 20

What does Central Deployment in SmartConsole allow administrators to do?

A.

Central Deployment cannot be used in SmartConsole. SmartUpdate is the GUI client that allows Central Deployment features to be used.

B.

Perform a version/release upgrade on multiple Gateways/Cluster Members.

C.

Install only Jumbo Hot Fixes to Gateways. Major version upgrades on Gateways must be done using CPUSE.

D.

Deploy a preconfigured Gaia and Security policy to a Gateway that has a SIC trust with the Management Server and no previous configuration.

Full Access
Question # 21

Alice and Bob are concurrently logged in to SmartConsole under Logs & Events to check the IKE “Key Install” between a working Site-to-Site VPN tunnel between site Alpha and site Bravo. Which of the following IKE versions are available?

A.

IKE

B.

IKEv1 & IKEv3

C.

IKEv1 & IKEv2

D.

IKEv2 & IKEv4

Full Access
Question # 22

What is the oldest software version on a Security Gateway that an R82 Security Management Server is supported to manage?

A.

R81

B.

There is no backward compatibility, and all Gateways must be installed with the same version as the Security Management Server.

C.

R80.10

D.

R77.30

Full Access
Question # 23

Which of the following is a trigger for synchronization between Active and Standby servers?

A.

Publishing a session in SmartConsole.

B.

Making a change in a network object and clicking OK.

C.

Running the Save operation from the SmartConsole toolbar or menu.

D.

After 10 seconds of inactivity in SmartConsole.

Full Access
Question # 24

Alice and Bob are tasked to integrate a Check Point IPsec VPN solution. Which of the following statements is true?

A.

Confidentiality — Uses standard authentication methods.

B.

Integrity — All VPN data is encrypted.

C.

Authenticity — All VPN data is encrypted.

D.

Confidentiality — All VPN data is encrypted.

Full Access
Question # 25

Alice knows about the Check Point Management HA installation from Bob and needs to know which Check Point Security Management Server is currently in the “Active” state. Alice uses the Check Point SmartConsole tool. Which Check Point console location is needed to look up the Management High Availability status?

A.

SmartView Tracker > Log Search > HA Status

B.

SmartUpdate > Package Repository > Management High Availability

C.

Gaia Portal > Overall View > Management High Availability

D.

Check Point SmartConsole > Menu > Management High Availability

Full Access
Question # 26

What network is automatically assigned to the Sync bonding group in an ElasticXL Cluster?

A.

192.168.2.0/24

B.

192.0.2.0/24

C.

192.20.0.0/24

D.

169.254.0.0/24

Full Access
Question # 27

According to the policy installation flow, the transfer stage, CPTA, is invoked by the FWM process, which initiates the Transfer/Commit phase. On the Security Gateway side, a process receives the policy files and first stores them into a temporary directory. Which directory for the Commit phase is correct for receiving these files?

A.

$FWDIR/state/_tmp/FW1

B.

$CPDIR/state/local/FW-1

C.

$FWDIR/state/local/FW1

D.

$FWDIR/state/local/FW-1

Full Access
Question # 28

Which Management Server process receives an install command when installing a policy?

A.

The CPM process is involved in installing a policy to the gateway.

B.

The CPWD process invokes the install function.

C.

The FWM process is involved in installing the policy.

D.

The FWD process is involved in installing a policy.

Full Access
Question # 29

How do you export the Management Database in the Advanced Upgrade method?

A.

By using migrate_server in Clish.

B.

By using $CPDIR/bin/migrate_server in Expert mode.

C.

By using migrate in Clish.

D.

By using $FWDIR/scripts/migrate_server in Expert mode.

Full Access
Question # 30

What is true when using the In-place upgrade method?

A.

Only cluster members are allowed to be upgraded with this method.

B.

Only Management Servers are allowed to be upgraded with this method. Security Gateways must be upgraded using Central Deployment or a fresh installation.

C.

Only the Primary and Secondary Management Servers are allowed to be upgraded with this method.

D.

Any of the Management Servers or Gateways are allowed to be upgraded using this method.

Full Access
Question # 31

Can a VPN Gateway be a member of more than one VPN Community?

A.

No, it can be used only in one VPN.

B.

Yes, it is possible, but with correct modifications of the vpn_route.conf file on each VPN Gateway.

C.

Yes, if it does not pair with another VPN Gateway in more than one VPN Community.

D.

Yes, it can be used in more than one VPN Community if all VPN Gateways are managed with the same Security Management Server.

Full Access
Question # 32

What are the key components of an Access Role object?

A.

Name, Subnet, Mask-length, User Group, LDAP Account Unit

B.

Name, IP Address, Mask-Length, LDAP Account Unit, Remote Access Client

C.

Name, LDAP Account Unit, Remote Access Client, Subnet, Host Object Type

D.

Name, Networks, Users, Machines, Remote Access Clients

Full Access
Question # 33

The IPsec VPN solution lets the Security Gateway encrypt and decrypt traffic to and from other Security Gateways and clients. The VPN tunnel guarantees:

A.

Confidentiality, Identity, and Authenticity

B.

Confidentiality, Identity, and Availability

C.

Confidentiality, Integrity, and Authenticity

D.

Confidentiality, Integrity, and Availability

Full Access
Question # 34

The ability to make more than one server Active at the same time in Security Management High Availability is known as:

A.

The statement is not true; only one server can be Active at a time.

B.

Active-Active mode.

C.

Multi-Active Security Management Server mode.

D.

Collision Mode.

Full Access
Question # 35

When creating a VPN tunnel with a third-party product, which object should you create in SmartConsole to represent the remote side?

A.

Externally Managed VPN Gateway

B.

Gateway

C.

Host

D.

Interoperable Object

Full Access
Question # 36

Which command will allow an administrator to manually load policy files on the gateway?

A.

fw fetch

B.

load

C.

fw install

D.

policy

Full Access
Question # 37

According to the policy installation flow, the transfer stage, CPTA, is invoked by the FWM process, which initiates the Transfer/Commit phase. On the Security Gateway side, a process receives the policy files and first stores them into a temporary directory. Which directory for the Transfer is correct for receiving these files?

A.

$FWDIR/state/local/FW1

B.

$FWDIR/state/_tmp/FW1

C.

$FWDIR/state/_tmp/FW-1

D.

$CPDIR/state/_tmp/FWM1

Full Access
Question # 38

Which tool can be used to automate upgrades and Hotfix installations?

A.

CPUSE

B.

CDT

C.

DA

D.

API

Full Access