156-115.77 Exam Details

  • Exam Code
    :156-115.77
  • Exam Name
    :Check Point Certified Security Master
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :295 Q&As
  • Last Updated
    :Dec 09, 2024

CheckPoint 156-115.77 Online Questions & Answers

  • Question 221:

    Where can you configure Wire mode?

    A. In the gateway object in "Stateful Inspection"
    B. In the VPN community in "Advanced Settings"
    C. In cpconfig
    D. In Global Properties

  • Question 222:

    The file ike.elg is a log file used to log IKE negotiations during VPN tunnel establishment. Where is this file located?

    A. /opt/CPshrd-R77/log
    B. /opt/CPsuite-R77/fw1/log
    C. /var/log/opt/CPsuite-R77/fg1/log
    D. /opt/CPsuite-R77/fg1/log

  • Question 223:

    The "Hide internal networks behind the Gateway's external IP" option is selected. What defines what traffic will be NATted?

    A. The Firewall policy of the gateway
    B. The network objects configured for the network
    C. The VPN encryption domain of the gateway object
    D. The topology configuration of the gateway object

  • Question 224:

    Under which scenario would you most likely consider the use of Multi-Queue?

    A. When IPS is heavily used.
    B. When most of the traffic is accelerated.
    C. When most of the processing is done in CoreXL.
    D. When trying to increase session rate.

  • Question 225:

    Running the command fw ctl pstat l would return what information?

    A. Additional hmem details
    B. General Security Gateway statistics
    C. Additional kmem details
    D. Additional smem details

  • Question 226:

    True or False: Software blades perform their inspection primarily through the kernel chain modules.

    A. False. Software blades do not pass through the chain modules.
    B. True. Many software blades have their own dedicated kernel chain module for inspection.
    C. True. All software blades are inspected by the IP Options chain module.
    D. True. Most software blades are inspected by the TCP streaming or Passive Streaming chain module.

  • Question 227:

    Where in a fw monitor output would you see source address translation occur in cases of automatic Hide NAT?

    A. Between the "I" and "o"
    B. Hide NAT does not adjust the source IP
    C. Between the "o" and "O"
    D. Between the "i" and "I"

  • Question 228:

    Which directory below contains the URL Filtering engine update info? Here you can also go to see the status of the URL Filtering and Application Control updates.

    A. $FWDIR/urlf/update
    B. $FWDIR/appi/update
    C. $FWDIR/appi/urlf
    D. $FWDIR/update/appi

  • Question 229:

    How can an administrator stay up-to-date on the status of their VPN Tunnels?

    A. Tracking settings can be configured on the Tunnel Management screen of the Community Properties screen for all VPN tunnels.
    B. Make a change in /proc/net/tun.
    C. Run vpn tu and select the option Live Monitoring.
    D. In Smartview Tracker.

  • Question 230:

    Which of the following CANNOT be used as a source/destination for an IPS network exception?

    A. Network Group
    B. Identity Awareness Access Role
    C. Any
    D. IP Address

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-115.77 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.