Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Checkpoint > CTPS > 156-590

156-590 Check Point Certified Threat Prevention Specialist (CTPS) Question and Answers

Question # 4

You have to issue a Log filter to view IPS logs generated for user John Doe.

Which of the following is the correct filter?

A.

user:"John-Doe" AND (action:drop OR action:reject OR action:block)

B.

user:John Doe AND (action:drop OR action:reject OR action:block)

C.

user:"John Doe" AND (action:drop OR action:reject OR action:block)

D.

user:'John Doe' AND (action:drop OR action:reject OR action:block)

Full Access
Question # 5

How are SNORT rules constructed?

A.

The rule is contained on two lines. There are two logical sections: Rule Header and Rule Payload.

B.

The rule is contained on two lines. There are two logical sections: Rule Header and Rule Options.

C.

The rule is contained on one line. There are two logical sections: Rule Header and Rule Payload.

D.

The rule is contained on a single line. There are two logical sections: Rule Header and Rule Options.

Full Access
Question # 6

What does ThreatCloud DGA Protection defend against?

A.

Known malicious IPs

B.

Infected URLs

C.

Infected files

D.

Newly created domains

Full Access
Question # 7

What are the three Preconfigured Threat Prevention Profiles?

A.

Inbound, Outbound, Etherbound.

B.

Perimeter, Datacenter, East-West Communication.

C.

North-South, East-West, Lateral Movement.

D.

Basic, Optimized, Strict.

Full Access
Question # 8

Which DNS Protection mechanism has been introduced with R81.20?

A.

Propagation of a Bogus IP as a response to a DNS request.

B.

Malware DNS Trap.

C.

ThreatCloud DNS Tunneling Protection.

D.

Synchronization of the /etc/hosts file from Protection servers.

Full Access
Question # 9

What is a distinct limitation of Active Streaming compared to Passive Streaming in conjunction with Anti-Virus?

A.

Only scheduled scans are possible.

B.

File size limits.

C.

There is no limitation.

D.

Only a subset of file types supported.

Full Access
Question # 10

Using IPS can send a large part of traffic to F2F path.

Which command can you use to enforce traffic quotas?

A.

fw dos rate

B.

fwaccel rate

C.

fw ctl dos

D.

fwaccel dos rate

Full Access
Question # 11

Which is NOT true of Threat Prevention policy application?

A.

Only applied after traffic is accepted by Access Control Policy

B.

Traffic is matched against all applicable layers at the same time

C.

Only applies first matched rule

D.

Applied as ordered layer

Full Access
Question # 12

What is necessary to do in order for the IPS Core Protection to take effect?

A.

Nothing is to be done, since the Core Protection settings are immediately active.

B.

Install the Access Control Policy.

C.

Install the Threat Prevention Policy.

D.

Perform "Install Database" on the Management Server.

Full Access
Question # 13

Which is NOT an available setting under Custom Policy Tools?

A.

IPS Protections

B.

UserCheck

C.

Indicators

D.

Malicious Activity Detection

Full Access
Question # 14

IPS stands for?

A.

Invasion Prevention Software

B.

Intrusion Prevention System

C.

Intrusion Prevention Software

D.

Invasion Prevention System

Full Access
Question # 15

What kind of blade is the IPS considered?

A.

Preventative

B.

Pre-infection

C.

Inline

D.

Post-infection

Full Access
Question # 16

What is the primary benefit of DNS Trap?

A.

Infected host identification

B.

Blocking known bad URLs

C.

Blocking outbound malicious DNS queries

D.

Blocking inbound malicious DNS queries

Full Access
Question # 17

What type of layer is the threat Prevention?

A.

It can be ordered or inline

B.

Inline

C.

Post Access Control follow-up layer

D.

Ordered

Full Access
Question # 18

That Tracking option can be used to capture additional data for analysis by Check Point TAC?

A.

Alert

B.

Forensics

C.

SNMP

D.

User Defined

Full Access
Question # 19

Who owns and maintains the CVE program and database?

A.

Check Point

B.

US Department of Homeland Security (DHS)

C.

MITRE Corporation

D.

National Institute of Standards and Technology (NIST)

Full Access
Question # 20

Mike wants to block all files in the event of internal failure; what option should he choose?

A.

open system

B.

fail-close

C.

fail-open

D.

closed system

Full Access
Question # 21

What action is taken by Threat Prevention for traffic that does not match any Threat Prevention rules?

A.

Reject

B.

Drop

C.

Accept

D.

Detect

Full Access
Question # 22

Which statement is true concerning the Custom Policy Tools?

A.

Block List files - Configure disallowed files.

B.

Allow List Files - Configure allowed files.

C.

Indicators - Configure indicators for benign activity.

D.

Profiles - Edit profiles which are only available for Autonomous Threat Prevention.

Full Access