A snapshot delivers a complete backup of SecurePlatform. The resulting file can be stored on servers or as a local file in /var/CPsnapshot/snapshots. How do you restore a local snapshot named MySnapshot.tgz?
-
A
As Expert user, type command snapshot - R to restore from a local file. Then, provide the correct file name.
-
B
As Expert user, type command revert --file MySnapshot.tgz.
-
C
As Expert user, type command snapshot -r MySnapshot.tgz.
-
D
Reboot the system and call the start menu. Select option Snapshot Management, provide the Expert password and select [L] for a restore from a local file. Then, provide the correct file name.
Reveal answer details
Close answer details
What are the SmartProvisioning Provisioning Profile indicators?
-
A
OK, Needs Attention, Uninitialized, Unknown
-
B
OK, Needs Attention, Agent is in local mode, Uninitialized, Unknown
-
C
OK, Waiting, Unknown, Not Installed, Not Updated, May be out of date
-
D
OK, In Use. Out of date, not used
Reveal answer details
Close answer details
Which external user authentication protocols are supported in SSL VPN?
-
A
LDAP, Active Directory, SecurID
-
B
DAP, SecurID, Check Point Password, OS Password, RADIUS, TACACS
-
C
LDAP, RADIUS, Active Directory, SecurID
-
D
LDAP, RADIUS, TACACS, SecurID
Reveal answer details
Close answer details
If both domain-based and route-based VPN's are configured, which will take precedence?
-
A
Must be chosen/configured manually by the Administrator in the Policy > Global Properties
-
B
Must be chosen/configured manually by the Administrator in the VPN community object
-
C
-
D
Reveal answer details
Close answer details
You want to upgrade a cluster with two members to VPN-1 NGX. The SmartCenter Server and both members are version VPN-1/Firewall-1 NG FP3, with the latest Hotfix. What is the correct upgrade procedure? 1. Change the version, in the General Properties of the gateway-cluster object. 2. Upgrade the SmartCenter Server, and reboot after upgrade. 3. Run cpstop on one member, while leaving the other member running. Upgrade one member at a time, and reboot after upgrade. 4. Reinstall the Security Policy.
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
You logged in to your firewall and discovered that the scheduled backup has been modified. Which of the below options is NOT a reason for the change?
-
A
Another administrator pushed a SmartProvisioning profile to the firewall
-
B
Another administrator issued a new backup command through the command line
-
C
Another administrator logged in to the WebUI and changed the setting without your knowledge
-
D
Another administrator updated the Backup Schedule using SmartUpdate
Reveal answer details
Close answer details
What is NOT true about Management Portal?
-
A
Choosing Accept control connections in Implied Rules includes Management Portal access
-
B
Management Portal requires a license
-
C
Default Port for Management Portal access is 4433
-
D
Management Portal could be reconfigured for using HTTP instead of HTTPS
Reveal answer details
Close answer details
What command will stop all (and only) Management Portal services?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
The file snapshot generates is very large, and can only be restored to:
-
A
The device that created it, after it has been upgraded
-
B
Individual members of a cluster configuration
-
C
Windows Server class systems
-
D
A device having exactly the same Operating System as the device that created the file
Reveal answer details
Close answer details
Question 10
Single choice
Can end users be forced to authenticate by using client certificates and username/password credentials?
-
A
Yes, but by manually changing the parameter :IsPasswordWarning to true in the $FWDIR/conf/ objects_5_0.C file, to allow for LDAP password remediation; and through the use of multiple-challenge login pages.
-
B
No, R71 only supports authentication by client certificates.
-
C
Yes, by editing the protection-level settings.
-
D
SSL VPN only supports server certificates.
Reveal answer details
Close answer details
Question 11
Single choice
What is a task of the SmartEvent Client?
-
A
Add events to the events database.
-
B
Display the received events.
-
C
Assign a severity level to an event.
-
D
Analyze each IPS log entry as it enters the Log server.
Reveal answer details
Close answer details
Question 12
Single choice
What firewall kernel table stores information about port allocations for Hide NAT connections?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Single choice
What is the command to upgrade an NG with Application Intelligence R55 SmartCenter running on SecurePlatform to VPN-1 NGX R65?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
When deploying a dedicated DLP Gateway behind a perimeter firewall on an interface leading to the internal network (there is only one internal network):
-
A
The DLP Gateway can inspect SMTP traffic if a MS Exchange server is located on the internal network, and it either sends e-mails directly to the Internet using SMTP or sends e-mails to the Internet in SMTP via a mail relay that is located on the perimeter's firewall DMZ network.
-
B
The DLP Gateway can inspect internal e-mails (e-mails between two users on the internal network) if the organization's internal mail server is located in the internal network and users are configured to send e-mails to this mail server using SMTP.
-
C
User's HTTPS and FTP traffic can be inspected by the R71 DLP Gateway.
-
D
The DLP Gateway can inspect e-mails (e-mails between two users on an internal or external network) if the organization's internal mail server is located on another network (not the internal network; for instance the DMZ or a different internal network) and users are configured to send e- mails to this mail server using SMTP.
Reveal answer details
Close answer details
Question 15
Single choice
Cody is notified by blacklist.org that his site has been reported as a spam relay, due to his SMTP Server being unprotected. Cody decides to implement an SMTP Security Server, to prevent the server from being a spam relay. Which of the following is the most efficient configuration method?
-
A
Configure the SMTP Security Server to perform MX resolving.
-
B
Configure the SMTP Security Server to perform filtering, based on IP address and SMTP protocols.
-
C
Configure the SMTP Security Server to work with an OPSEC based product, for content checking.
-
D
Configure the SMTP Security Server to apply a generic "from" address to all outgoing mail.
-
E
Configure the SMTP Security Server to allow only mail to or from names, within Cody's corporate domain.
Reveal answer details
Close answer details
Question 16
Single choice
What is the SmartEvent Analyzer's function?
-
A
Analyze log entries, looking for Event Policy patterns.
-
B
Generate a threat analysis report from the Analyzer database.
-
C
Display received threats and tune the Events Policy.
-
D
Assign severity levels to events.
Reveal answer details
Close answer details
Question 17
Single choice
Which command would you use to save the routing information before upgrading a Windows Gateway?
-
A
ipconfig -a > [filename].txt
-
B
ifconfig > [filename].txt
-
C
cp /etc/sysconfig/network.C [location]
-
D
netstat -rn > [filename].txt
Reveal answer details
Close answer details
Question 18
Single choice
When using IPS, what does Geo protection do?
-
A
To block traffic from and to a specific country
-
B
To block traffic from and to a specific person
-
C
To block traffic from and to a specific company
-
D
To block traffic from and to a specific city
Reveal answer details
Close answer details
Question 19
Single choice
How can you verify that SecureXL is running?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
After repairing a SmartWorkflow session:
-
A
The session moves to status Repaired and a new session can be started.
-
B
The session moves to status Awaiting Repair and must be resubmitted.
-
C
The session is continued with status Not approved and a new session must be started.
-
D
The session is discarded and a new session is automatically started.
Reveal answer details
Close answer details
Question 21
Single choice
Which version is the minimum requirement for SmartProvisioning?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
What cluster mode is represented in this case?
-
A
-
B
Load Sharing (multicast mode)
-
C
Load Sharing Unicast (Pivot) mode
-
D
Reveal answer details
Close answer details
Question 23
Single choice
Wayne configures an HTTP Security Server to work with the content vectoring protocol to screen forbidden sites. He has created a URI resource object using CVP with the following settings: Use CVP Allow CVP server to modify content Return data after content is approved He adds two rules to his Rule Base: one to inspect HTTP traffic going to known forbidden sites, the other to allow all other HTTP traffic. Wayne sees HTTP traffic going to those problematic sites is not prohibited. What could cause this behavior?
-
A
The Security Server Rule is after the general HTTP Accept Rule.
-
B
The Security Server is not communicating with the CVP server.
-
C
The Security Server is not configured correctly.
-
D
The Security Server is communicating with the CVP server, but no restriction is defined in the CVP server.
Reveal answer details
Close answer details
Question 24
Single choice
You need to publish SecurePlatform routes using the ospf routing protocol. What is the correct command structure, once entering the route command, to implement ospf successfully?
-
A
Run cpconfig utility to enable ospf routing
-
B
ip route ospf ospf network1 ospf network2
-
C
Enable Configure terminal Router ospf [id] Network [network] [wildmask] area [id]
-
D
Use DBedit utility to either the objects_5_0.c file
Reveal answer details
Close answer details
Question 25
Single choice
Your R7x-series Enterprise Security Management Server is running abnormally on Windows Server 2003 R2. You decide to try reinstalling the Security Management Server, but you want to try keeping the critical Security Management Server configuration settings intact (i.e., all Security Policies, databases, SIC, licensing etc. ) What is the BEST method to reinstall the Server and keep its critical configuration?
-
A
1. Insert the R77 CD-ROM and select the option to export the configuration using the latest upgrade utilities. 2. Follow steps suggested by upgrade_verification and re-export the configuration if needed. 3. Save the exported file *.tgz to a local directory c:/temp. 4. Uninstall all packages using Add/Remove Programs and reboot. 5. Install again using the R77 CD-ROM as a primary Security Management Server and reboot. 6. Run upgrade_import to import the configuration.
-
B
1. Create a data base revision control back up using SmartDashboard. 2. Create a compressed archive of the directories %FWDIR%/conf and %FWDIR%/lib and copy them to another networked machine. 3. Uninstall all packages using Add/Remove Programs and reboot. 4. Install again as a primary Security Management Server using the R77 CD-ROM. 5. Reboot and restore the two archived directories over the top of the new installation, choosing to overwrite existing files.
-
C
1. Download the latest utility upgrade_export and run from a local directory c:/temp to export the configuration into a *.tgz file. 2. Skip any upgrade_verification warnings since you are not upgrading. 3. Transfer the file *.tgz to another networked machine. 4. Download and run the utility cpclean and reboot. 5. Use the R77 CD-ROM to select option upgrade_import to import the configuration.
-
D
1. Download the latest utility upgrade_export and run from directory c:/temp to export the configuration into a *.tgz file. 2. Follow steps suggested by upgrade_verification. 3. Uninstall all packages using Add/Remove Programs and reboot. 4. Use SmartUpdate to reinstall the Security Management Server and reboot. 5. Transfer file *.tgz back to local directory /temp. 6. Run upgrade_import to import the configuration.
Reveal answer details
Close answer details
Question 26
Single choice
When restoring R75 using the command upgrade_import, which of the following items are NOT restored?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
Which procedure enables the SSL VPN blade on the gateway?
-
A
Log into SmartDashboard, Create a new rule with the source and destination addresses of the needed remote network, set the action to Encrypt and push the policy to that gateway.
-
B
Log into SmartDashboard, edit the properties of the Gateway, and select the SSL VPN check box.
-
C
Log into SmartDashboard, Select the VPN Communities tab and add the gateway to the appropriate community.
-
D
Log into WebUI on the gateway and check the SSL VPN Blade check box.
Reveal answer details
Close answer details
Question 28
Single choice
Remote clients are using IPSec VPN to authenticate via LDAP server to connect to the organization. Which gateway process is responsible for the authentication?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
A user attempts to initialize a network application using SSL Network Extender. The application fails to start. What is the MOST LIKELY solution?
-
A
Select the option Auto-detect client capabilities.
-
B
Select the option Enable SSL Network Extender Application Mode only.
-
C
Select the option Turn off all SSL tunneling clients.
-
D
Select the option Enable SSL Network Extender Network Mode only.
Reveal answer details
Close answer details
Question 30
Single choice
After Travis added new processing cores on his server, CoreXL did not use them. What would be the most plausible reason why? Travis did not:
-
A
edit the Gateway Properties and increase the kernel instances.
-
B
run cpconfig to increase the number of CPU cores.
-
C
edit the Gateway Properties and increase the number of CPU cores.
-
D
run cpconfig to increase the kernel instances.
Reveal answer details
Close answer details
Question 31
Single choice
You are preparing computers for a new ClusterXL deployment. For your cluster, you plan to use four machines with the following configurations: Cluster Member 1: OS: SecurePlatform, NICs: QuadCard, memory: 1 GB, Security Gateway only, version: R75 Cluster Member 2: OS: SecurePlatform, NICs: 4 Intel 3Com, memory: 1 GB, Security Gateway only, version: R75 Cluster Member 3: OS: SecurePlatform, NICs: 4 other manufacturers, memory: 512 MB, Security Gateway only, version: R75 Security Management Server: MS Windows 2003, NIC. Intel NIC (1), Security Gateway and primary Security Management Server installed, version: R75 Are these machines correctly configured for a ClusterXL deployment?
-
A
No, the Security Gateway cannot be installed on the Security Management Pro Server.
-
B
No, Cluster Member 3 does not have the required memory.
-
C
Yes, these machines are configured correctly for a ClusterXL deployment.
-
D
No, the Security Management Server is not running the same operating system as the cluster members.
Reveal answer details
Close answer details
Question 32
Single choice
In New Mode HA, the internal cluster IP VIP address is 10.4.8.3. An internal host 10.4.8.108 successfully pings its Cluster and receives replies. Review the ARP table from the internal Windows host 10.4.8.108. Based on this information, what is the active cluster member's IP address?
-
A
The active cluster member's IP address cannot be determined by this ARP cache.
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 33
Single choice
Your customer asks you about Check Point SmartWorkflow. His company must comply with various laws and regulations and therefore it is important for him to be able to see the changes made to a specific object. You explain to him that he can use the SmartWorkflow Software Blade to achieve this objective and show him some examples (Figures 1 - 3). How can the customer receive the required information?
-
A
The customer can check compliance. This function compares the logs with the compliance requirements and automatically reports which part of the selected compliance is fulfilled and which is not.
-
B
The customer can use the Check Point's SmartView Tracker to view the required information. He selects the log category Changed Objects.
-
C
The customer can use the Record Details. This feature enables administrators to track changes that have been made to objects over an extended period of time. These changes are recorded in Smartview Tracker as audit logs.
-
D
The customer can use the Check Point's SmartView Tracker directly to receive the required information. He selects the log category SmartWorkflow.
Reveal answer details
Close answer details
Question 34
Single choice
You have three Gateways in a mesh community. Each gateway's VPN Domain is their internal network as defined on the Topology tab setting All IP Addresses behind Gateway based on Topology information. You want to test the route-based VPN, so you created VTIs among the Gateways and created static route entries for the VTIs. However, when you test the VPN, you find out the VPN still go through the regular domain IPsec tunnels instead of the routed VTI tunnels. What is the problem and how do you make the VPN use the VTI tunnels?
-
A
Domain VPN takes precedence over the route-based VTI. To make the VPN go through VTI, remove the Gateways out of the mesh community and replace with a star community
-
B
Route-based VTI takes precedence over the Domain VPN. Troubleshoot the static route entries to insure that they are correctly pointing to the VTI gateway IP.
-
C
Route-based VTI takes precedence over the Domain VPN. To make the VPN go through VTI, use dynamic-routing protocol like OSPF or BGP to route the VTI address to the peer instead of static routes
-
D
Domain VPN takes precedence over the route-based VTI. To make the VPN go through VTI, use an empty group object as each Gateway's VPN Domain
Reveal answer details
Close answer details
Question 35
Single choice
At what router prompt would you save your OSPF configuration?
-
A
localhost.localdomain(config)#
-
B
localhost.localdomain(config-if)#
-
C
-
D
localhost.localdomain(config-router-ospf)#
Reveal answer details
Close answer details
Question 36
Single choice
State Synchronization is enabled on both members in a cluster, and the Security Policy is successfully installed. No protocols or services have been unselected for selective sync. Review the fw tab -t connections -s output from both members.  Is State Synchronization working properly between the two members?
-
A
Members A and B are not synchronized, because #VALS in the connections table are not close.
-
B
Members A and B are not synchronized, because #PEAK for both members is not close in the connections table.
-
C
Members A and B are synchronized, because #SLINKS are identical in the connections table.
-
D
Members A and B are synchronized, because ID for both members is identical in the connections table.
Reveal answer details
Close answer details
Question 37
Single choice
What is the reason for the following error? 
-
A
A third-party cluster solution is implemented.
-
B
Cluster membership is not enabled on the gateway.
-
C
Objects.C does not contain a cluster object.
-
D
Device Name contains non-ASCII characters.
Reveal answer details
Close answer details
Question 38
Single choice
When configuring site-to-site VPN High Availability (HA) with MEP, which of the following is correct?
-
A
MEP Gateways cannot be geographically separated machines.
-
B
The decision on which MEP Gateway to use is made on the MEP Gateway's side of the tunnel.
-
C
MEP Gateways must be managed by the same SmartCenter Server.
-
D
If one MEP Security Gateway fails, the connection is lost and the backup Gateway picks up the next connection.
Reveal answer details
Close answer details
Question 39
Single choice
Which Check Point QoS feature is used to dynamically allocate relative portions of available bandwidth?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 40
Single choice
How does a cluster member take over the VIP after a failover event?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 41
Single choice
Where do Gateways managed by SmartProvisioning fetch their assigned profiles?
-
A
-
B
The standalone SmartProvisioning server
-
C
The Security Management server or CMA
-
D
They are fetched locally from the individual device
Reveal answer details
Close answer details
Question 42
Single choice
Choose the BEST sequence for configuring user management in SmartDashboard, using an LDAP server.
-
A
Configure a workstation object for the LDAP server, configure a server object for the LDAP Account Unit, and enable LDAP in Global Properties.
-
B
Configure a server object for the LDAP Account Unit, and create an LDAP resource object.
-
C
Enable LDAP in Global Properties, configure a host-node object for the LDAP server, and configure a server object for the LDAP Account Unit.
-
D
Configure a server object for the LDAP Account Unit, enable LDAP in Global Properties, and create an LDAP resource object.
Reveal answer details
Close answer details
Question 43
Single choice
You use the snapshot feature to store your Connectra SSL VPN configuration. What do you expect to find?
-
A
Nothing; snapshot is not supported in Connectra SSL VPN.
-
B
The management configuration of the current product, on a management or stand-alone machine
-
C
A complete image of the local file system
-
D
Specified directories of the local file system.
Reveal answer details
Close answer details
Question 44
Single choice
Your customer wishes to install SmartWorkflow on top of R70 Security Management Server (Windows system). What is the required disk space?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 45
Single choice
Which describes the function of the account unit?
-
A
An Account Unit is the Check Point account that SmartDirectory uses to access an (LDAP) server
-
B
An Account Unit is a system account on the Check Point gateway that SmartDirectory uses to access an (LDAP) server
-
C
An Account Unit is the administration account on the LDAP server that SmartDirectory uses to access to (LDAP) server
-
D
An Account Unit is the interface which allows interaction between the Security Management server and Security Gateways, and the SmartDirectory (LDAP) server.
Reveal answer details
Close answer details
Question 46
Single choice
You are a Security Administrator preparing to deploy a new HFA (Hot fix Accumulator) to ten Security Gateways at five geographically separated locations. What is the BEST method to implement this HFA?
-
A
Send a Certified Security Engineer to each site to perform the update
-
B
Use SmartUpdate to install the packages to each of the Security Gateways remotely
-
C
Use a SSH connection to SCP the HFA to each Security Gateway. Once copied locally, initiate a remote installation command and monitor the installation progress with SmartView Monitor.
-
D
Send a CDROM with the HFA to each location and have local personnel install it
Reveal answer details
Close answer details
Question 47
Single choice
You have installed SecurePlatform R75 as Security Gateway operating system. As company requirements changed, you need the VTI features of R75. What should you do?
-
A
Only IPSO 3.9 supports VTI feature, so you have to replace your Security Gateway with Nokia appliances.
-
B
In SmartDashboard click on the OS drop down menu and choose SecurePlatform Pro. You have to reboot the Security Gateway in order for the change to take effect.
-
C
Type pro enable on your Security Gateway and reboot it.
-
D
You have to re-install your Security Gateway with SecurePlatform Pro R75, as SecurePlatform R75 does not support VTIs.
Reveal answer details
Close answer details
Question 48
Single choice
Which process is responsible for kernel table information sharing across all cluster members?
-
A
fwd daemon using an encrypted TCP connection
-
B
CPHA using an encrypted TCP connection
-
C
fw kernel using an encrypted TCP connection
-
D
cpd using an encrypted TCP connection
Reveal answer details
Close answer details
Question 49
Single choice
MEP VPN's use the Proprietary Probing Protocol to send special UDP RDP packets to port ____ to discover if an IP is accessible.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
What is the lowest possible version a Security Gateway may be running in order to use it as an LSM enabled Gateway?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 51
Single choice
Which of the following services will cause SecureXL templates to be disabled?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 52
Single choice
Which of the following is NOT TRUE regarding HTTPS traffic being passed through a DLP gateway?
-
A
You must edit the $FWDIR/conf/fwauthd.conf file in order for HTTPS traffic to be passed to your Web Proxy through a DLP gateway.
-
B
HTTPS traffic is not scanned by DLP
-
C
Only one proxy can be configured for DLP
-
D
You must configure the DLP gateway to allow HTTP/HTTPS traffic through the proxy if you have a web proxy between the DLP gateway and the internet.
Reveal answer details
Close answer details
Question 53
Single choice
If Jack was concerned about the number of log entries he would receive in the SmartReporter system, which policy would he need to modify?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 54
Single choice
Your company has the requirement that SmartEvent reports should show a detailed and accurate view of network activity but also performance should be guaranteed. Which actions should be taken to achieve that? (i) Use same hard driver for database directory, log files and temporary directory (ii) Use Consolidation Rules (iii) Limit logging to blocked traffic only (iv) Using Multiple Database Tables
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 55
Single choice
You have a production implementation of Management High Availability, at version VPN-1 NG with Application Intelligence R55. You must upgrade your two SmartCenter Servers to VPN-1 NGX. What is the correct procedure?
-
A
1. Synchronize the two SmartCenter Servers. 2. Upgrade the secondary SmartCenter Server. 3. Upgrade the primary SmartCenter Server. 4. Configure both SmartCenter Server host objects version to VPN-1 NGX. 5. Synchronize the Servers again.
-
B
1. Synchronize the two SmartCenter Servers. 2. Perform an advanced upgrade on the primary SmartCenter Server. 3. Upgrade the secondary SmartCenter Server. 4. Configure both SmartCenter Server host objects to version VPN-1 NGX. 5. Synchronize the Servers again.
-
C
1. Perform an advanced upgrade on the primary SmartCenter Server. 2. Configure the primary SmartCenter Server host object to version VPN-1 NGX. 3. Synchronize the primary with the secondary SmartCenter Server. 4. Upgrade the secondary SmartCenter Server. 5. Configure the secondary SmartCenter Server host object to version VPN-1 NGX. 6. Synchronize the Servers again.
-
D
1. Synchronize the two SmartCenter Servers. 2. Perform an advanced upgrade on the primary SmartCenter Server. 3. Configure the primary SmartCenter Server host object to version VPN-1 NGX. 4. Synchronize the two Servers again. 5. Upgrade the secondary SmartCenter Server. 6. Configure the secondary SmartCenter Server host object to version VPN-1 NGX. 7. Synchronize the Servers again.
Reveal answer details
Close answer details
Question 56
Single choice
Frank is concerned with performance and wants to configure the affinities settings. His gateway does not have the Performance Pack running. What would Frank need to perform in order configure those settings?
-
A
Edit $FWDIR/conf/fwaffinity.conf and change the settings.
-
B
Edit affinity.conf and change the settings.
-
C
Run fw affinity and change the settings.
-
D
Run sim affinity and change the settings.
Reveal answer details
Close answer details
Question 57
Single choice
Your VPN Community includes three Security Gateways. Each Gateway has its own internal network defined as a VPN Domain. You must test the VPN-1 NGX routE. based VPN feature, without stopping the VPN. What is the correct order of steps?
-
A
1. Add a new interface on each Gateway. 2. Remove the newly added network from the current VPN Domain for each Gateway. 3. Create VTIs on each Gateway, to point to the other two peers 4. Enable advanced routing on all three Gateways.
-
B
1. Add a new interface on each Gateway. 2. Remove the newly added network from the current VPN Domain in each gateway object. 3. Create VPN Tunnel Interfaces (VTI) on each gateway object, to point to the other two peers. 4. Add static routes on three Gateways, to route the new network to each peer's VTI interface.
-
C
1. Add a new interface on each Gateway. 2. Add the newly added network into the existing VPN Domain for each Gateway. 3. Create VTIs on each gateway object, to point to the other two peers. 4. Enable advanced routing on all three Gateways.
-
D
1. Add a new interface on each Gateway. 2. Add the newly added network into the existing VPN Domain for each gateway object. 3. Create VTIs on each gateway object, to point to the other two peers. 4. Add static routes on three Gateways, to route the new networks to each peer's VTI interface.
Reveal answer details
Close answer details
Question 58
Multiple choice
Public keys and digital certificates provide which of the following? Select three.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 59
Single choice
Which of the following statements is FALSE about the DLP Software Blade and Active Directory (AD) or LDAP?
-
A
When a user authenticates in the DLP Portal to view all his unhandled incidents, the portal authenticates the user using only AD/LDAP.
-
B
Check Point UserCheck client authentication is based on AD.
-
C
For SMTP traffic, each recipient e-mail address is translated using AD/LDAP to a user name and group that is checked vs. the destination column of the DLP rule base.
-
D
For SMTP traffic, the sender e-mail address is translated using AD/LDAP to a user name and group that is checked vs. the source column of the DLP rule base.
Reveal answer details
Close answer details
Question 60
Single choice
Where is the encryption domain for a SmartLSM Security Gateway configured in R71?
-
A
Inside the SmartLSM Security Gateway object in the SmartDashboard GUI
-
B
Inside the SmartLSM Security Gateway profile in the SmartProvisioning GUI
-
C
Inside the SmartLSM Security Gateway object in the SmartProvisioning GUI
-
D
Inside the SmartLSM Security Gateway profile in the SmartDashboard GUI
Reveal answer details
Close answer details
Question 61
Single choice
John is the MultiCorp Security Administrator. If he suggests a change in the firewall configuration, he must submit his proposal to David, a security manager. One day David is out of the office and john submits his proposal to peter. Surprisingly, Peter is not able to approve the proposal because the system does not permit him to do so?   Both David and Peter have accounts as administrators in the Security Management server and both have the Read/Write ALL permission. What is the reason for this difference?
-
A
There were some Hardware/Software issues at Security Management server on the first day.
-
B
Peter was no logged on to system for a longer time
-
C
The attribute Manage Administrator was not assigned to Peter
-
D
The specific SmartWorkflow read/Write permission were assigned to David only.
Reveal answer details
Close answer details
Question 62
Single choice
When you add a resource service to a rule, which ONE of the following actions occur?
-
A
VPN-1 Secure Client users attempting to connect to the object defined in the Destination column of the rule will receive a new Desktop Policy from the resource.
-
B
All packets that match the resource in the rule will be dropped.
-
C
All packets matching the resource service rule are analyzed or authenticated, based on the resource properties.
-
D
Users attempting to connect to the destination of the rule will be required to authenticate.
-
E
All packets matching that rule are either encrypted or decrypted by the defined resource.
Reveal answer details
Close answer details
Question 63
Single choice
In Company XYZ, the DLP Administrator defined a new Keywords Data Type that contains a list of secret project names; i.e., Ayalon, Yarkon, Yarden. The threshold is set to At least 2 keywords or phrases. Based on this information, which of the following scenarios will be a match to the Rule Base?
-
A
A PDF file that contains the following text Yarkon1 can be the code name for the new product. Yardens list of protected sites
-
B
An MS Excel file that contains the following text Mort resources for Yarkon project.. Are you certain this is about Yarden?
-
C
A word file that contains the following text will match: Ayalon ayalon AYALON
-
D
A password protected MS Excel file that contains the following text Ayalon Yarkon Yarden
Reveal answer details
Close answer details
Question 64
Single choice
Which component receives events and assigns severity levels to the events; invokes any defined automatic reactions, and adds the events to the Events Data Base?
-
A
SmartEvent Analysis DataServer
-
B
-
C
SmartEvent Correlation Unit
-
D
Reveal answer details
Close answer details
Question 65
Single choice
To force clients to use Integrity Secure Workspace when accessing sensitive applications, the Administrator can configure Connectra:
-
A
-
B
To implement Integrity Clientless Security
-
C
To force the user to re-authenticate at login
-
D
Without a special setting. Secure Workspace is automatically configured.
Reveal answer details
Close answer details
Question 66
Single choice
In a particular IPS protection in R71 in the Logging Settings, what does the Capture Packets option do?
-
A
This is not a valid selection in R71
-
B
Attaches a packet capture of the traffic that matches this particular protection to each log that the protection generates.
-
C
Starts a packet capture at the time of policy install to capture all of the traffic until this protection is hit.
-
D
Collects all of the logs for packets that have matched this protection within the last 30 days
Reveal answer details
Close answer details
Question 67
Single choice
In R71, My Organization e-mail addresses or domains are used for:
-
A
Scanning e-mails only if its sender e-mail address is part of this definition, by default.
-
B
Defining the e-mail address of the SMTP relay server.
-
C
FTP traffic sent from a user where his e-mail is part of this definition scanned by DLP, by default.
-
D
HTTP traffic sent from a user where his e-mail is part of this definition scanned by DLP, by default.
Reveal answer details
Close answer details
Question 68
Single choice
Using the Backup Target functionality in SmartProvisioning, what targets are available? i) FTP ii) TFTP iii) SFTP iv) SCP v) Locally
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 69
Single choice
How can you disable SecureXL via the command line (it does not need to survive a reboot)?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 70
Single choice
User definitions are stored in ________________ .
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 71
Single choice
Which OPSEC server is used to prevent users from accessing certain Web sites?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 72
Single choice
-
A
displays the received events
-
B
adds events to the events database
-
C
invokes defined automatic reactions
-
D
analyzes each IPS log entry as it enters the Log server
Reveal answer details
Close answer details
Question 73
Single choice
Which of the following is NOT a ClusterXL mode?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 74
Single choice
When synchronizing clusters, which of the following statements is NOT true?
-
A
The state of connections using resources is maintained by a Security Server, so these connections cannot be synchronized.
-
B
In the case of a failover, accounting information on the failed member may be lost despite a properly working synchronization.
-
C
Only cluster members running on the same OS platform can be synchronized.
-
D
Client Authentication or Session Authentication connections through a cluster member will be lost if the cluster member fails.
Reveal answer details
Close answer details
DRAG DROP Match the remote-access VPN connection mode features with their descriptions. 
Reveal answer details
Close answer details
Question 76
Single choice
In ClusterXL, which of the following are defined by default as a critical device?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 77
Single choice
Assume an intruder has compromised your current IKE Phase 1 and Phase 2 keys. Which of the following options will end the intruder's access, after the next Phase 2 exchange occurs?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 78
Single choice
To change the default port of the Management Portal:
-
A
Edit the masters. conf file on the Portal server.
-
B
Modify the file cp_httpd_admin .conf.
-
C
Run sysconfig and change the management interface.
-
D
Reveal answer details
Close answer details
Question 79
Single choice
Using the output below, why is the QoS rule not limiting the internal users to 2000 Bps of GNUtella traffic?
-
A
Rule Guarantee needs to be changed to Rule Limit
-
B
Rule Weight needs to be changed to 10
-
C
The Source and Destination columns need to be reversed
-
D
Encrypted traffic needs to be added to the Action field
Reveal answer details
Close answer details
Question 80
Single choice
When Load Sharing Multicast mode is defined in a ClusterXL cluster object, how are packets being handled by cluster members?
-
A
All members receive all packets. The Security Management Server decides which member will process the packets. Other members delete the packets from memory.
-
B
All cluster members process all packets and members synchronize with each other.
-
C
All members receive all packets. All members run an algorithm which determines which member processes packets further and which members delete the packet from memory.
-
D
Only one member at a time is active. The active cluster member processes all packets.
Reveal answer details
Close answer details
Question 81
Single choice
Identity Agent is a lightweight endpoint agent that authenticates securely with Single Sign-On (SSO). Which of the following is NOT a recommended use for this method?
-
A
When accuracy in detecting identity is crucial
-
B
Identity based enforcement for non-AD users (non-Windows and guest users)
-
C
Protecting highly sensitive servers
-
D
Leveraging identity for Data Center protection
Reveal answer details
Close answer details
Question 82
Single choice
Which of the following components contains the Events Data Base?
-
A
-
B
-
C
SmartEvent Correlation Unit
-
D
Reveal answer details
Close answer details
Question 83
Single choice
-
A
analyzes each IPS log entry as it enters the Log server.
-
B
displays the received events.
-
C
forwards what is known as an event to the SmartEvent Server.
-
D
assigns a severity level to an event.
Reveal answer details
Close answer details
Question 84
Single choice
What could be a reason why synchronization between primary and secondary Security Management Servers does not occur?
-
A
You did not activate synchronization within Global Properties.
-
B
You are using different time zones.
-
C
You have installed both Security Management Servers on different server systems (e. g. one machine on HP hardware and the other one on DELL).
-
D
If the set of installed products differ from each other, the Security Management Servers do not synchronize the database to each other.
Reveal answer details
Close answer details
Question 85
Single choice
You are trying to configure Directional VPN Rule Match in the Rule Base. But the Match column does not have the option to see the Directional Match. You see the following window. What must you enable to see the Directional Match?
-
A
VPN Directional Match on the Gateway object's VPN tab
-
B
Advanced Routing on each Security Gateway
-
C
VPN Directional Match on the VPN advanced window, in Global Properties
-
D
directional_match(true) in the objects_5_0.C file on Security Management Server
Reveal answer details
Close answer details
Question 86
Single choice
Which of the following log files contains verbose information regarding the negotiation process and other encryption failures?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 87
Single choice
The SmartProvisioning management concept is based on:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 88
Single choice
What command will allow you to disable sync on a cluster firewall member?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 89
Single choice
What is the SmartEvent Analyzer's function?
-
A
Assign severity levels to events.
-
B
Analyze log entries, looking for Event Policy patterns.
-
C
Display received threats and tune the Events Policy.
-
D
Generate a threat analysis report from the Analyzer database.
Reveal answer details
Close answer details
Question 90
Single choice
Which changes are tracked by SmartWorkflow?
-
A
SmartDashboard, SmartView Tracker and SmartView Monitor logins and logouts
-
B
Security Policies and the Rule Base, Network Objects, Network Services, VPN Communities.
-
C
Users, Administrators, Groups and VPN Communities
-
D
Security Policies and the Rule Base, Network Objects, Network Services, Resources, Users, Administrators, Groups, VPN Communities and Servers and OPSEC Applications.
Reveal answer details
Close answer details
Question 91
Single choice
Assuming all connections that are allocated bandwidth in your Check Point QoS Rule Base are open, what would be the corresponding bandwidth percentage of the Kazaa Rule in the following example? 
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 92
Single choice
What is the router command to save your OSPF configuration?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 93
Single choice
Check Point support has asked Tony for a firewall capture of accepted packets. What would be the correct syntax to create a capture file to a filename called monitor.out?
-
A
Run fw monitor -e "accept;" -f monitor.out
-
B
Run fw monitor -e "accept;" -c monitor.out
-
C
Run fw monitor -e "accept;" -o monitor.out
-
D
Run fw monitor -e "accept;" -m monitor.out
Reveal answer details
Close answer details
Question 94
Single choice
Check Point recommends deploying SSL VPN:
-
A
In parallel to the firewall
-
B
-
C
In front of the firewall with a LAN connection
-
D
On the Primary cluster member
Reveal answer details
Close answer details
Question 95
Single choice
How would you set the debug buffer size to 1024?
-
A
-
B
-
C
Run fw ctl debug -buf 1024
-
D
Run fw ctl set int print_cons 1024
Reveal answer details
Close answer details
|