At what point is the Internal Certificate Authority (ICA) created?
-
A
During the primary Security Management Server installation process.
-
B
Upon creation of a certificate
-
C
When an administrator decides to create one
-
D
When an administrator initially logs into SmartConsole.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe Internal Certificate Authority (ICA) is created during the primary Security Management Server installation process. The ICA is a component that issues and manages certificates for Check Point products. The ICA is automatically installed and initialized when installing the Security Management Server. References: Check Point R81 Security Management Administration Guide, page 26.
In order for changes made to policy to be enforced by a Security Gateway, what action must an administrator perform?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationIn order for changes made to policy to be enforced by a Security Gateway, an administrator must perform Install Policy3. This action transfers the policy package from the Security Management Server to the Security Gateway and activates it. References: Check Point R81 Security Management Administration Guide
Fill in the blank: The _____ feature allows administrators to share a policy with other policy packages.
-
A
Concurrent policy packages
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe Shared policies feature allows administrators to share a policy with other policy packages. This can save time and effort when managing multiple gateways with similar security requirements. Shared policies can be applied to Access Control, Threat Prevention, and HTTPS Inspection layers. References: Check Point R81 Security Management Administration Guide, Check Point R81 SmartConsole R81 Resolved Issues
Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?
-
A
The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.
-
B
Licensed Check Point products for the Gala operating system and the Gaia operating system itself.
-
C
The CPUSE engine and the Gaia operating system.
-
D
The Gaia operating system only.
Reveal answer details
Close answer details
Correct answerB
ExplanationGaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for licensed Check Point products for the Gaia operating system and the Gaia operating system itself. CPUSE is an advanced tool that automates software updates and upgrades on Gaia platforms. It can download and install packages such as hotfixes, Jumbo Hotfix Accumulators, minor versions, major versions, and OS updates. References: [CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)], [Check Point R81]
In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?
-
A
-
B
"Inspect", "Bypass", "Categorize"
-
C
"Inspect", "Bypass", "Block"
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe actions available in the "Actions" column of a rule in HTTPS Inspection policy are "Inspect" and "Bypass". "Inspect" means that the HTTPS traffic will be decrypted and inspected according to the Access Control policy. "Bypass" means that the HTTPS traffic will not be decrypted and will be allowed without inspection. The other options are not valid actions for HTTPS Inspection policy.
Fill in the blank: An LDAP server holds one or more ______________.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationAn LDAP server holds one or more Account Units. An Account Unit is a logical representation of an LDAP server in the Check Point database. It defines the connection parameters, authentication methods, and user and group information that are retrieved from the LDAP server. An Account Unit allows the Security Gateway to use the LDAP server for user authentication and identity awareness. The other options are incorrect. A Server Unit is a logical representation of a Check Point server in the Check Point database. An Administrator Unit is a logical representation of an administrator or an administrator group in the Check Point database. An Account Server is not a valid term in Check Point terminology. References: [Check Point R81 Identity Awareness Administration Guide], [Check Point R81 Security Management Administration Guide], [Check Point R81 SmartConsole R81 Resolved Issues]
Which of the following commands is used to monitor cluster members in CLI?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe command show cluster state is used to monitor cluster members in CLI. It displays information such as the cluster mode, the cluster members, their status, their priority, and their interfaces. References: [ClusterXL Administration Guide], [Check Point CLI Reference Card]
When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition?
-
A
-
B
-
C
More than 10GB and less than 20 GB
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe correct answer is D because the recommended size of the root partition for a dedicated R80 SmartEvent server is at least 20GB. Any size, less than 20GB, or more than 10GB and less than 20GB are not sufficient for the SmartEvent server. References: Check Point R80.40 Installation and Upgrade Guide
John is the administrator of a R80 Security Management server managing R77.30 Check Point Security Gateway. John is currently updating the network objects and amending the rules using SmartConsole. To make John's changes available to other administrators, and to save the database before installing a policy, what must John do?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationTo make John's changes available to other administrators, and to save the database before installing a policy, John must publish the session. Publishing the session saves the changes to the database and makes them visible to other administrators. The other options do not achieve this goal. References: Publishing a Session
Question 10
Single choice
Which of the following describes how Threat Extraction functions?
-
A
Detect threats and provides a detailed report of discovered threats
-
B
Proactively detects threats
-
C
Delivers file with original content
-
D
Delivers PDF versions of original files with active content removed
Reveal answer details
Close answer details
Correct answerD
ExplanationThreat Extraction delivers PDF versions of original files with active content removed, such as macros, embedded objects, and scripts. This ensures that users receive clean and safe files in seconds. References: Check Point SandBlast Zero-Day Protection, Check Point Threat Extraction
Question 11
Single choice
A network administrator has informed you that they have identified a malicious host on the network, and instructed you to block it. Corporate policy dictates that firewall policy changes cannot be made at this time. What tool can you use to block this traffic?
-
A
-
B
-
C
-
D
Suspicious Activity Monitoring (SAM) rules
Reveal answer details
Close answer details
Correct answerD
ExplanationIf a network administrator has identified a malicious host on the network and instructed you to block it, but you cannot make any firewall policy changes at this time, you can use Suspicious Activity Monitoring (SAM) rules to block this traffic. SAM rules are temporary rules that allow you to block or limit traffic from specific sources or destinations without modifying the security policy. SAM rules are created and managed by SmartView Monitor and are enforced by the security gateway for a specified duration. Anti-Bot protection, Anti-Malware protection, and Policy-based routing are not tools that can be used to block traffic without changing the firewall policy. References: [Check Point R81 SmartView Monitor Administration Guide]
Question 12
Single choice
You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to accept your Terms of Service, and cannot access the Internet. How can you fix this? 
-
A
Right click Accept in the rule, select "More", and then check "Enable Identity Captive Portal"
-
B
On the firewall object, Legacy Authentication screen, check "Enable Identity Captive Portal"
-
C
In the Captive Portal screen of Global Properties, check "Enable Identity Captive Portal"
-
D
On the Security Management Server object, check the box "Identity Logging"
Reveal answer details
Close answer details
Correct answerA
ExplanationIdentity Captive Portal is a Check Point Identity Awareness web portal, to which users connect with their web browser to log in and authenticate, when using Browser-Based Authentication. To enable Identity Captive Portal for a specific rule, you need to right click Accept in the rule, select "More", and then check "Enable Identity Captive Portal". References: Identity Awareness Administration Guide R80, Identity awareness with captive portal in Checkpoint R80
Question 13
Single choice
Which option will match a connection regardless of its association with a VPN community?
-
A
All Site-to-Site VPN Communities
-
B
Accept all encrypted traffic
-
C
All Connections (Clear or Encrypted)
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationAccept all encrypted traffic is the option that will match a connection regardless of its association with a VPN community. This option allows encrypted traffic from any VPN peer, even if it is not defined in a VPN community. References: Site to Site VPN in R80.x - Tutorial for Beginners
Question 14
Single choice
SmartEvent does NOT use which of the following procedures to identity events:
-
A
Matching a log against each event definition
-
B
Create an event candidate
-
C
Matching a log against local exclusions
-
D
Matching a log against global exclusions
Reveal answer details
Close answer details
Correct answerC
ExplanationThe procedure that SmartEvent does not use to identify events is matching a log against local exclusions. Local exclusions are used to filter out logs that are not relevant for SmartLog, not SmartEvent. SmartEvent uses the other procedures to identify events based on event definitions, event candidates, and global exclusions . References: SmartLog R81 Administration Guide, , SmartEvent R81 Administration Guide, [Free Check Point CCSA Sample Questions and Study Guide]
Question 15
Single choice
A layer can support different combinations of blades What are the supported blades:
-
A
Firewall. URLF, Content Awareness and Mobile Access
-
B
Firewall (Network Access Control). Application & URL Filtering. Content Awareness and Mobile Access
-
C
Firewall. NAT, Content Awareness and Mobile Access
-
D
Firewall (Network Access Control). Application & URL Filtering and Content Awareness
Reveal answer details
Close answer details
Correct answerD
ExplanationA layer can support different combinations of blades, but the supported blades are Firewall (Network Access Control), Application & URL Filtering, and Content Awareness. These blades provide granular control over network traffic based on applications, users, content, and risk. Mobile Access is not a supported blade in a layer. References: Check Point R81 Security Management Administration Guide, page 101. Check Point R81 Security Gateway Administration Guide, page 11.
Question 16
Single choice
Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?
-
A
Both License (.lic) and Contract (.xml) files
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe file that is an electronically signed file used by Check Point to translate the features in the license into a code is cp.macro. This file contains a list of macros that define the license features and their values. It is located in the $FWDIR/conf directory on the Security Management Server or Security Gateway. References: [Check Point R81 Licensing Guide], [Check Point R80.40 Licensing Guide]
Question 17
Single choice
Which of the following commands is used to monitor cluster members?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 18
Single choice
What is the Transport layer of the TCP/IP model responsible for?
-
A
It transports packets as datagrams along different routes to reach their destination.
-
B
It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.
-
C
It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.
-
D
It deals with all aspects of the physical components of network connectivity and connects with different network types.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe Transport layer of the TCP/IP model is responsible for managing the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application. It also provides error detection and correction, flow control, and multiplexing. The Transport layer uses protocols such as TCP and UDP. References: Check Point Security Engineering Study Guide, p. 10-11
Question 19
Single choice
Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility. Which statement is true?
-
A
Manual NAT can offer more flexibility than Automatic NAT.
-
B
Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.
-
C
Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading.
-
D
Automatic NAT can offer more flexibility than Manual NAT.
Reveal answer details
Close answer details
Correct answerA
ExplanationManual NAT can offer more flexibility than Automatic NAT because it allows the administrator to define the NAT rules in any order and position. Automatic NAT creates the NAT rules automatically and places them at the top or bottom of the NAT Rule Base. References: Check Point R81 Firewall Administration Guide, Check Point R81 Security Management Administration Guide
Question 20
Single choice
Gaia has two default user accounts that cannot be deleted. What are those user accounts?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationGaia has two default user accounts that cannot be deleted. They are Admin and Monitor. Admin is the user account that has full administrative privileges and can access both WebUI and CLI. Monitor is the user account that has read-only privileges and can access only WebUI2. The other options are not default user accounts in Gaia.
Question 21
Single choice
Which SmartConsole tab shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe SmartConsole tab that shows logs and detects security threats, providing a centralized display of potential attack patterns from all network devices, is Logs and Monitor, p. 24. The Logs and Monitor tab allows administrators to view logs from various sources, such as Security Gateways, SmartEvent servers, and SmartReporter servers. Gateway and Servers, Manage Setting, and Security Policies are other tabs in SmartConsole that have different functions. References: Check Point CCSA - R81:Practice Test & Explanation, [Check Point SmartConsole R81 Help]
Question 22
Single choice
Fill in the blanks: The Application Layer Firewalls inspect traffic through the ______ layer(s) of the TCP/IP model and up to and including the ______ layer.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe Application Layer Firewalls inspect traffic through the Lower layer(s) of the TCP/IP model and up to and including the Application layer. The lower layers are the Physical, Data Link, and Network layers, which deal with the transmission and routing of packets. The Application layer is the highest layer of the TCP/IP model, which provides services and protocols for specific applications such as HTTP, FTP, SMTP, etc. The Application Layer Firewalls can inspect the content and context of the traffic and enforce granular security policies based on various criteria such as user identity, application identity, content type, etc. References: [Check Point R81 Firewall Administration Guide]
Question 23
Single choice
Which policy type is used to enforce bandwidth and traffic control rules?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe policy type that is used to enforce bandwidth and traffic control rules is QoS. QoS stands for Quality of Service and is a software blade that allows administrators to prioritize network traffic according to various criteria such as source, destination, service, application, user, etc. QoS can also limit the bandwidth consumption of certain traffic types or guarantee a minimum bandwidth for critical applications. References: [Check Point R81 QoS Administration Guide]
Question 24
Single choice
If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed:
-
A
Rename the hostname of the Standby member to match exactly the hostname of the Active member.
-
B
Change the Standby Security Management Server to Active.
-
C
Change the Active Security Management Server to Standby.
-
D
Manually synchronize the Active and Standby Security Management Servers.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe correct answer is A because renaming the hostname of the Standby member to match exactly the hostname of the Active member is not a recommended step to prevent data loss. The hostname of the Standby member should be different from the hostname of the Active member. The other steps are necessary to ensure a smooth failover and synchronization between the Active and Standby Security Management Servers. References: Check Point R81.20 Administration Guide, 156-315.81 Checkpoint Exam Info and Free Practice Test
Question 25
Single choice
Which option in a firewall rule would only match and allow traffic to VPN gateways for one Community in common?
-
A
All Connections (Clear or Encrypted)
-
B
Accept all encrypted traffic
-
C
-
D
All Site-to-Site VPN Communities
Reveal answer details
Close answer details
Correct answerC
ExplanationSpecific VPN Communities is the option that would only match and allow traffic to VPN gateways for one Community in common. This option allows you to define a specific VPN community that includes the VPN gateways that are allowed to communicate with each other. The other options are either too broad or too narrow for this scenario. References: [Site to Site VPN in R80.x - Tutorial for Beginners]
Question 26
Single choice
Identity Awareness allows easy configuration for network access and auditing based on what three items?
-
A
Client machine IP address.
-
B
Network location, the identity of a user and the identity of a machine.
-
C
-
D
Gateway proxy IP address.
Reveal answer details
Close answer details
Correct answerB
ExplanationIdentity Awareness is a blade that enables administrators to define access rules based on the identity of users and machines, rather than just IP addresses. Identity Awareness allows easy configuration for network access and auditing based on three items: network location, the identity of a user, and the identity of a machine. Network location refers to the source or destination network segment of the traffic. The identity of a user refers to the username or group membership of the user who initiates or receives the traffic. The identity of a machine refers to the hostname or certificate of the machine that initiates or receives the traffic. References: [Check Point R81 Identity Awareness Administration Guide]
Question 27
Single choice
Which of the following is TRUE regarding Gaia command line?
-
A
Configuration changes should be done in mgmt_di and use CLISH for monitoring. Expert mode is used only for OS level tasks
-
B
Configuration changes should be done in mgmt_cli and use expert-mode for OS-level tasks.
-
C
Configuration changes should be done in expert-mode and CLISH is used for monitoring
-
D
All configuration changes should be made in CLISH and expert-mode should be used for OS-level tasks.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe statement that is true regarding Gaia command line is that all configuration changes should be made in CLISH and expert-mode should be used for OS-level tasks. CLISH is the default shell of Gaia CLI that provides a limited set of commands for basic configuration and troubleshooting. Expert mode is an advanced shell that allows running Linux commands and accessing the file system. Configuration changes should not be done in expert-mode, as they may cause inconsistencies or errors in the system. The other statements are false regarding Gaia command line.
Question 28
Single choice
Which two Identity Awareness commands are used to support identity sharing?
-
A
Policy Decision Point (PDP) and Policy Enforcement Point (PEP)
-
B
Policy Enforcement Point (PEP) and Policy Manipulation Point (PMP)
-
C
Policy Manipulation Point (PMP) and Policy Activation Point (PAP)
-
D
Policy Activation Point (PAP) and Policy Decision Point (PDP)
Reveal answer details
Close answer details
Correct answerA
ExplanationThe answer is A because Identity Awareness commands are used to support identity sharing between Security Gateways. Policy Decision Point (PDP) is the Security Gateway that collects identities from various sources and shares them with other gateways. Policy Enforcement Point (PEP) is the Security Gateway that enforces the policy based on the identities received from the PDP12 References: Check Point R81 Identity Awareness Administration Guide, Check Point R81 Security Management Administration Guide
Question 29
Single choice
Fill in the blanks: Default port numbers for an LDAP server is ______ for standard connections and _______ SSL connections.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe default port numbers for an LDAP server are 389 for standard connections and 636 for SSL connections. LDAP (Lightweight Directory Access Protocol) is a protocol that allows access to directory services over TCP/IP. Therefore, the correct answer is B. 389, 636.
Question 30
Single choice
Which two of these Check Point Protocols are used by ?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe two Check Point Protocols that are used by are FWD and LEA. FWD is the Firewall Daemon that handles communication between different Check Point components, such as Security Management Server, Security Gateway, SmartConsole, etc. LEA is the Log Export API that allows external applications to retrieve logs from the Security Gateway or Security Management Server. Therefore, the correct answer is B. FWD and LEA. References: Border Gateway Protocol - Check Point Software, Check Point IPS Datasheet, List of valid protocols for services? - Check Point CheckMates
Question 31
Single choice
What is the main difference between Static NAT and Hide NAT?
-
A
Static NAT only allows incoming connections to protect your network.
-
B
Static NAT allow incoming and outgoing connections. Hide NAT only allows outgoing connections.
-
C
Static NAT only allows outgoing connections. Hide NAT allows incoming and outgoing connections.
-
D
Hide NAT only allows incoming connections to protect your network.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe main difference between Static NAT and Hide NAT is that Static NAT allows incoming and outgoing connections, while Hide NAT only allows outgoing connections. Static NAT translates a single IP address to another single IP address, while Hide NAT translates a group of IP addresses to a single IP address. Static NAT is used to expose internal servers to external networks, while Hide NAT is used to hide internal hosts from external networks. References: Check Point R81 Firewall Administration Guide
Question 32
Single choice
Security Zones do no work with what type of defined rule?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationSecurity Zones are a feature of Application Control and Identity Awareness that allow you to define groups of network objects based on their level of trust. Security Zones do not work with Manual NAT rules, because Manual NAT rules are applied before the Application Control and Identity Awareness policy is enforced. References: Check Point R81 Security Management Administration Guide
Question 33
Single choice
Stateful Inspection compiles and registers connections where?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationStateful Inspection compiles and registers connections in the State Table. The State Table is a database that stores information about active connections and sessions on the Security Gateway. The other options are not valid names for the database that stores connection information. References: 1: Policy Types 2: CPUSE 3: SIC : [Software Containers] : [Stateful Inspection]
Question 34
Single choice
Phase 1 of the two-phase negotiation process conducted by IKE operates in ______ mode.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 35
Single choice
Which of the following is true about Stateful Inspection?
-
A
Stateful Inspection tracks state using two tables, one for incoming traffic and one for outgoing traffic
-
B
Stateful Inspection looks at both the headers of packets, as well as deeply examining their content.
-
C
Stateful Inspection requires that a server reply to a request, in order to track a connection's state
-
D
Stateful Inspection requires two rules, one for outgoing traffic and one for incoming traffic.
Reveal answer details
Close answer details
Correct answerB
ExplanationStateful Inspection is true about looking at both the headers of packets, as well as deeply examining their content. Stateful Inspection inspects packets at all layers of the OSI model and maintains information about the state and context of each connection in a state table. References: Certified Security Administrator (CCSA) R81.20 Course Overview, page 6.
Question 36
Single choice
Which of the following is NOT supported by Bridge Mode on the Check Point Security Gateway?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationBridge Mode is a deployment option for Check Point Security Gateway that allows it to act as a transparent bridge between two network segments, without changing the IP addressing scheme. Bridge Mode supports most of the security features, such as Data Loss Prevention, Antivirus, Application Control, etc. However, Bridge Mode does not support NAT, because NAT requires modifying the IP addresses or ports of the packets, which contradicts the transparent nature of Bridge Mode. References: Check Point R81 Security Gateway Technical Administration Guide
Question 37
Single choice
Fill in the blanks: The _______ collects logs and sends them to the _______.
-
A
Log server; Security Gateway
-
B
Log server; security management server
-
C
Security management server; Security Gateway
-
D
Security Gateways; log server
Reveal answer details
Close answer details
Correct answerD
ExplanationThe Security Gateways collect logs and send them to the log server. The Security Gateways are the components that enforce the security policy on network traffic and generate logs for each connection that matches a rule with a tracking option. The log server is the component that receives and stores the logs from the Security Gateways and provides a centralized interface for viewing and analyzing them. The log server can be either a dedicated server or integrated with the Security Management Server. References: [Check Point R81 Security Management Administration Guide]
Question 38
Single choice
In SmartEvent, a correlation unit (CU) is used to do what?
-
A
Collect security gateway logs, Index the logs and then compress the logs.
-
B
Receive firewall and other software blade logs in a region and forward them to the primary log server.
-
C
Analyze log entries and identify events.
-
D
Send SAM block rules to the firewalls during a DOS attack.
Reveal answer details
Close answer details
Correct answerC
ExplanationA correlation unit (CU) is a component of SmartEvent that analyzes log entries on log servers and identifies events based on predefined or custom rules. A CU receives logs from one or more log servers and forwards them to the SmartEvent server, where they are stored in the events database
Question 39
Single choice
Which option would allow you to make a backup copy of the OS and Check Point configuration, without stopping Check Point processes?
-
A
All options stop Check Point processes
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe snapshot option would allow you to make a backup copy of the OS and Check Point configuration, without stopping Check Point processes. A snapshot is a full system backup, including network interfaces, routing tables, and Check Point products and configuration. The other options require stopping Check Point processes or do not backup the OS. References: Check Point Security Management Administration Guide R81, p. 15-16
Question 40
Single choice
Fill in the blank: By default, the SIC certificates issued by R80 Management Server are based on the ____________ algorithm.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationBy default, the SIC certificates issued by R80 Management Server are based on the SHA- 256 algorithm. SHA-256 is a secure hash algorithm that produces a 256-bit digest. SHA-200, MD5, and SHA-128 are not valid algorithms for SIC certificates. References: SHA-1 and SHA-256 certificates in Check Point Internal CA (ICA)
Question 41
Single choice
When a Security Gateways sends its logs to an IP address other than its own, which deployment option is installed?
-
A
-
B
-
C
Reveal answer details
Close answer details
Correct answerA
ExplanationWhen a Security Gateway sends its logs to an IP address other than its own, it means that the Security Gateway and the Log Server are installed on different machines. This is a characteristic of a Distributed deployment. Therefore, the correct answer is A
Question 42
Single choice
What is a role of Publishing?
-
A
The Publish operation sends the modifications made via SmartConsole in the private session and makes them public
-
B
The Security Management Server installs the updated policy and the entire database on Security Gateways
-
C
The Security Management Server installs the updated session and the entire Rule Base on Security Gateways
-
D
Modifies network objects, such as servers, users, services, or IPS profiles, but not the Rule Base
Reveal answer details
Close answer details
Correct answerA
ExplanationThe Publish operation sends the modifications made via SmartConsole in the private session and makes them public is the correct answer. This is because publishing is the process of saving your changes to the database and making them available to other administrators. Publishing also allows you to install policies on Security Gateways. References: [Publishing Changes]
Question 43
Single choice
What is required for a certificate-based VPN tunnel between two gateways with separate management systems?
-
A
-
B
-
C
-
D
Mutually Trusted Certificate Authorities
Reveal answer details
Close answer details
Correct answerD
ExplanationThis answer is correct because for a certificate-based VPN tunnel, both gateways need to have a certificate issued by a certificate authority (CA) that they trust. A CA is a trusted entity that verifies the identity of the gateways and signs their certificates. The gateways can either use the same CA or different CAs, as long as they trust each other's CA. This way, the gateways can authenticate each other using their certificates and establish a secure VPN tunnel. The other answers are not correct because they are either irrelevant or incompatible with certificate-based VPN tunnel. Shared secret passwords and unique passwords are used for pre-shared key (PSK) authentication, which is a different method than certificate authentication. PSK authentication is less secure and more vulnerable to brute force attacks than certificate authentication. Shared user certificates are not used for gateway authentication, but for user authentication, which is a different level of authentication than gateway authentication. User authentication is optional and can be used in addition to gateway authentication to provide more granular access control. Configure server settings for P2S VPN Gateway connections - certificate authentication VPN certificates and how they work Create Certificate Based Site to Site VPN between 2 Check Point Gateways HowTo Set Up Certificate Based VPNs with Check Point Appliances
Question 44
Single choice
What are the three deployment considerations for a secure network?
-
A
Distributed, Bridge Mode, and Remote
-
B
Bridge Mode, Remote, and Standalone
-
C
Remote, Standalone, and Distributed
-
D
Standalone, Distributed, and Bridge Mode
Reveal answer details
Close answer details
Correct answerC
ExplanationThe three deployment considerations for a secure network are Remote, Standalone, and Distributed. Remote deployment means that the Security Management Server and Security Gateway are installed on different machines. Standalone deployment means that the Security Management Server and Security Gateway are installed on the same machine. Distributed deployment means that there are multiple Security Gateways managed by one or more Security Management Servers. Therefore, the correct answer is C. Remote, Standalone, and Distributed.
Question 45
Single choice
When doing a Stand-Alone Installation, you would install the Security Management Server with which other Check Point architecture component?
-
A
None, Security Management Server would be installed by itself.
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationWhen doing a Stand-Alone Installation, you would install the Security Management Server with none of the other Check Point architecture components. A Stand-Alone Installation is a type of installation that combines the Security Management Server and the Security Gateway on one computer or appliance, p. 14. SmartConsole, SecureClient, and SmartEvent are not Check Point architecture components, but software applications that can be installed separately.
Question 46
Single choice
The Network Operations Center administrator needs access to Check Point Security devices mostly for troubleshooting purposes. You do not want to give her access to the expert mode, but she still should be able to run tcpdump. How can you achieve this requirement?
-
A
Add tcpdump to CLISH using add command.Create a new access role.Add tcpdump to the role.Create new user with any UID and assign role to the user.
-
B
Add tcpdump to CLISH using add command.Create a new access role.Add tcpdump to the role.Create new user with UID 0 and assign role to the user.
-
C
Create a new access role.Add expert-mode access to the role.Create new user with UID 0 and assign role to the user.
-
D
Create a new access role.Add expert-mode access to the role.Create new user with any UID and assign role to the user.
Reveal answer details
Close answer details
Correct answerA
ExplanationTo achieve the requirement of giving the Network Operations Center administrator access to Check Point Security devices mostly for troubleshooting purposes, but not to the expert mode, and still allowing her to run tcpdump, you need to: Add tcpdump to CLISH using add command. This command adds a new command to the Command Line Interface Shell (CLISH) that allows running tcpdump without entering the expert mode . Create a new access role. This option defines a set of permissions and commands that can be assigned to a user or a group of users. Add tcpdump to the role. This option grants the permission to run tcpdump to the role. Create new user with any UID and assign role to the user. This option creates a new user account with any User ID (UID) and assigns the role that has tcpdump permission to the user. References: [How to add a new command to CLISH], [Check Point R81 Gaia Administration Guide], [Check Point R81 Identity Awareness Administration Guide]
Question 47
Single choice
The SmartEvent R80 Web application for real-time event monitoring is called:
-
A
-
B
-
C
There is no Web application for SmartEvent
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationSmartView is the web application for real-time event monitoring in SmartEvent R80 and above. It provides a unified view of security events across the network and allows for quick investigation and response. References: SmartEvent R80.40 Administration Guide, SmartView
Question 48
Single choice
Which path below is available only when CoreXL is enabled?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe path that is available only when CoreXL is enabled is the medium path. The medium path is used to handle packets that require deeper inspection by the Firewall and IPS blades, but do not need to go through the slow path . The slow path is used to handle packets that require stateful or out-of-state inspection by other blades, such as Application Control or VPN . The firewall path and the accelerated path are available regardless of CoreXL status . References: [CoreXL R81 Administration Guide], [], [Check Point Security Gateway Architecture and Packet Flow], [Free Check Point CCSA Sample Questions and Study Guide]
Question 49
Single choice
What is the order of NAT priorities?
-
A
IP pool NAT static NAT. hide NAT
-
B
Static NAT hide NAT, IP pool NAT
-
C
Static NAT, IP pool NAT hide NAT
-
D
Static NAT automatic NAT hide NAT
Reveal answer details
Close answer details
Correct answerC
ExplanationThe order of NAT priorities is Static NAT, IP pool NAT, and hide NAT. Static NAT has the highest priority because it is a one-to-one mapping of a private IP address to a public IP address. IP pool NAT has the second highest priority because it is a one-to-many mapping of a private IP address to a pool of public IP addresses. Hide NAT has the lowest priority because it is a many-to-one mapping of multiple private IP addresses to a single public IP address. References: Check Point R81 Security Gateway Administration Guide, page 23.
Question 50
Single choice
You want to verify if there are unsaved changes in GAiA that will be lost with a reboot. What command can be used?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe command show config-state can be used to verify if there are unsaved changes in GAiA that will be lost with a reboot . The other commands are not valid in GAiA. References: [Check Point GAiA Administration Guide], []
Question 51
Single choice
When configuring Anti-Spoofing, which tracking options can an Administrator select?
-
A
-
B
Log, Allow Packets, Email
-
C
-
D
Log, Send SNMP Trap, Email
Reveal answer details
Close answer details
Correct answerA
ExplanationLog, Alert, and None are the tracking options that an Administrator can select when configuring Anti- Spoofing. Log means that the packet will be logged in SmartView Tracker. Alert means that the packet will trigger an alert in SmartView Monitor. None means that no action will be taken. The other options are not valid tracking options.
Question 52
Single choice
An administrator wishes to enable Identity Awareness on the Check Point firewalls. However they allow users to use company issued or personal laptops. Since the administrator cannot manage the personal laptops, which of the following methods would BEST suit this company?
-
A
-
B
Browser-Based Authentication
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationBrowser-Based Authentication is the best method for enabling Identity Awareness on the Check Point firewalls for users who use company issued or personal laptops. Browser-Based Authentication redirects users to a web page where they enter their credentials to access the network resources. This method does not require any installation or configuration on the user's device and supports any operating system and browser. AD Query is a method that queries Active Directory servers for user login events and maps them to IP addresses. This method does not work for personal laptops that are not joined to the domain. Identity Agents are software agents that run on Windows or macOS devices and provide user and machine identity information to the firewall. This method requires installation and management of the agents on each device, which may not be feasible for personal laptops. Terminal Servers Agent is a method that identifies users who connect to Windows Terminal Servers or Citrix servers via RDP or ICA protocols. This method does not apply to laptops that connect directly to the network910 References: Identity Awareness Reference Architecture and Best Practices, Part 10 - Identity
Question 53
Single choice
What does it mean if Deyra sees the gateway status:  Choose the BEST answer.
-
A
SmartCenter Server cannot reach this Security Gateway
-
B
There is a blade reporting a problem
-
C
VPN software blade is reporting a malfunction
-
D
Security Gateway's MGNT NIC card is disconnected.
Reveal answer details
Close answer details
Correct answerB
ExplanationIf Deyra sees the gateway status as shown in the image, it means that there is a blade reporting a problem. The red "X" in the status column indicates that one or more blades on the Security Gateway have a problem that requires attention. The other options are not correct, as they do not match the status shown in the image. If the SmartCenter Server cannot reach this Security Gateway, the status column would show a yellow triangle with an exclamation mark. If the VPN software blade is reporting a malfunction, the blades column would show a red "X" on the VPN icon. If the Security Gateway's MGNT NIC card is disconnected, the IP column would show "N/A" instead of the IP address. References: Remote Access VPN R81 Administration Guide, Check Point R81.10 
Question 54
Single choice
Which statement describes what Identity Sharing is in Identity Awareness?
-
A
Management servers can acquire and share identities with Security Gateways
-
B
Users can share identities with other users
-
C
Security Gateways can acquire and share identities with other Security Gateways
-
D
Administrators can share identifies with other administrators
Reveal answer details
Close answer details
Correct answerC
ExplanationIdentity Sharing is a feature that allows Security Gateways to acquire and share identities with other Security Gateways, enabling identity-based access control across different network segments or domains. Management servers, users, and administrators do not share identities with Security Gateways. References: Identity Awareness R81.10 Administration Guide, Check Point R81.10
Question 55
Single choice
Which of the following is NOT a tracking log option in R80. x?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 56
Single choice
Which icon in the WebUI indicates that read/write access is enabled?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe icon in the WebUI that indicates that read/write access is enabled is the Pencil icon . The Pencil icon appears next to the name of the device when it is in Read/Write mode, which allows making changes to the configuration. The Padlock icon indicates that read-only access is enabled, which prevents making changes to the configuration. The Book icon indicates that online help is available, which provides information and guidance on using the WebUI. The Eyeglasses icon indicates that a view-only mode is enabled, which allows viewing the configuration without logging in. References: Gaia R81.10 Administration Guide, WebUI Overview
Question 57
Single choice
John is using Management HA. Which Smartcenter should be connected to for making changes?
-
A
-
B
-
C
connect virtual IP of Smartcenter HA
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe SmartCenter that should be connected to for making changes is the active SmartCenter. The active SmartCenter is the one that is currently synchronizing its configuration with the secondary SmartCenter and handling the communication with the gateways . The primary SmartCenter is the one that was initially configured as the main server, but it may become inactive if a failover occurs. The virtual IP of SmartCenter HA is used to access the SmartConsole, not to make changes. References: [Security Management Server High Availability (HA) R81 Administration Guide], [], [How to configure ClusterXL High Availability on Security Management Server]
Question 58
Single choice
When you upload a package or license to the appropriate repository in SmartUpdate. where is the package or license stored?
-
A
SmartConsole installed device
-
B
-
C
Security Management Server
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen you upload a package or license to the appropriate repository in SmartUpdate, the package or license is stored on the Security Management Server. SmartUpdate is a tool that allows you to centrally manage software updates and licenses for all Check Point products on your network. References: : Check Point R81 Security Management Administration Guide, page 16.
Question 59
Single choice
True or False: The destination server for Security Gateway logs depends on a Security Management Server configuration.
-
A
False, log servers are configured on the Log Server General Properties
-
B
True, all Security Gateways will only forward logs with a SmartCenter Server configuration
-
C
True, all Security Gateways forward logs automatically to the Security Management Server
-
D
False, log servers are enabled on the Security Gateway General Properties
Reveal answer details
Close answer details
Correct answerB
ExplanationThe destination server for Security Gateway logs depends on a Security Management Server configuration. This is true because the Security Management Server defines the log servers that receive logs from the Security Gateways. The log servers can be either the Security Management Server itself or a dedicated Log Server. References: Check Point R81 Logging and Monitoring Administration Guide, Check Point R81 Quantum Security Gateway Guide
Question 60
Single choice
What needs to be configured if the NAT property `Translate destination on client side' is not enabled in Global properties?
-
A
A host route to route to the destination IP
-
B
Use the file local.arp to add the ARP entries for NAT to work
-
C
Nothing, the Gateway takes care of all details necessary
-
D
Enabling `Allow bi-directional NAT' for NAT to work correctly
Reveal answer details
Close answer details
Correct answerC
ExplanationIf the NAT property `Translate destination on client side' is not enabled in Global properties, nothing needs to be configured on the client side, because the Gateway takes care of all details necessary. The Gateway translates the destination IP address before sending the packet to the client, so the client does not need to know about the NAT rule or add any host route or ARP entry. References: Check Point Security Engineering Study Guide, p. 136-137
|