156-215.13 Exam Details

  • Exam Code
    :156-215.13
  • Exam Name
    :Check Point Certified Security Administrator - GAiA
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :361 Q&As
  • Last Updated
    :Dec 15, 2021

CheckPoint 156-215.13 Online Questions & Answers

  • Question 261:

    The Captive Portal tool:

    A. Allows access to users already identified.
    B. Acquires identities from unidentified users.
    C. Is deployed from the Identity Awareness page in the Global Properties settings.
    D. Is only used for guest user authentication.

  • Question 262:

    You want to establish a VPN, using certificates. Your VPN will exchange certificates with an external partner. Which of the following activities should you do first?

    A. Manually import your partner's Access Control List.
    B. Manually import your partner's Certificate Revocation List.
    C. Create a new logical-server object to represent your partner's CA.
    D. Exchange exported CA keys and use them to create a new server object to represent your partner's Certificate Authority (CA).

  • Question 263:

    Your boss wants you to closely monitor an employee suspected of transferring company secrets to the competition. The IT department discovered the suspect installed a WinSCP client in order to use encrypted communication. Which of the following methods is BEST to accomplish this task?

    A. Use SmartView Tracker to follow his actions by filtering log entries that feature the WinSCP destination port. Then, export the corresponding entries to a separate log file for documentation.
    B. Watch his IP in SmartView Monitor by setting an alert action to any packet that matches your Rule Base and his IP address for inbound and outbound traffic.
    C. Send the suspect an email with a keylogging Trojan attached, to get direct information about his wrongdoings.
    D. Use SmartDashboard to add a rule in the firewall Rule Base that matches his IP address, and those of potential targets and suspicious protocols. Apply the alert action or customized messaging.

  • Question 264:

    You receive a notification that long-lasting Telnet connections to a mainframe are dropped after an hour of inactivity. Reviewing SmartView Tracker shows the packet is dropped with the error:

    Unknown established connection

    How do you resolve this problem without causing other security issues? Choose the BEST answer.

    A. Increase the service-based session timeout of the default Telnet service to 24-hours.
    B. Increase the TCP session timeout under Global Properties > Stateful Inspection.
    C. Create a new TCP service object on port 23 called Telnet-mainframe. Define a service-based session timeout of 24-hours. Use this new object only in the rule that allows the Telnet connections to the mainframe.
    D. Ask the mainframe users to reconnect every time this error occurs.

  • Question 265:

    Which command would provide the most comprehensive diagnostic information to Check Point Technical Support?

    A. cpstat - date.cpstat.txt
    B. fw cpinfo
    C. cpinfo -o date.cpinfo.txt
    D. diag

  • Question 266:

    The London Security Gateway Administrator has just installed the Security Gateway and Management Server. He has not changed any default settings. As he tries to configure the Gateway, he is unable to connect. Which troubleshooting suggestion will NOT help him?

    A. Check if some intermediate network device has a wrong routing table entry, VLAN assignment, duplex-mismatch, or trunk issue.
    B. Verify that the Rule Base explicitly allows management connections.
    C. Test the IP address assignment and routing settings of the Security Management Server, Gateway, and console client.
    D. Verify the SIC initialization.

  • Question 267:

    How can you most quickly reset Secure Internal Communications (SIC) between a Security Management Server and Security Gateway?

    A. From the Security Management Server's command line, type fw putkey -p .
    B. Run the command fwm sic_reset to reinitialize the Security Management Server Internal Certificate Authority (ICA). Then retype the activation key on the Security Gateway from SmartDashboard.
    C. Use SmartUpdate to retype the Security Gateway activation key. This will automatically sync SIC to both the Security Management Server and Gateway.
    D. From cpconfig on the Gateway, choose the Secure Internal Communication option and retype the activation key. Next, retype the same key in the Gateway object in SmartDashboard and reinitialize Secure Internal Communications (SIC).

  • Question 268:

    You cannot use SmartDashboard's User Directory features to connect to the LDAP server.

    What should you investigate?

    1) Verify you have read-only permissions as administrator for the operating system.

    2) Verify there are no restrictions blocking SmartDashboard's User Manager from connecting to the LDAP server.

    3) Check that the login Distinguished Name configured has root permission (or at least write permission Administrative access) in the LDAP Server's access control configuration.

    A. 2 and 3
    B. 1 and 3
    C. 1 and 2
    D. 1, 2, and 3

  • Question 269:

    In a distributed management environment, the administrator has removed the default check from Accept Control Connections under the Policy > Global Properties > FireWall tab. In order for the Security Management Server to install a policy to the Firewall, an explicit rule must be created to allow the server to communicate to the Security Gateway on port .

    A. 259
    B. 256
    C. 80
    D. 900

  • Question 270:

    How is wear on the flash storage device mitigated on diskless appliance platforms?

    A. The external PCMCIA-based flash extension has the swap file mapped to it, allowing easy replacement.
    B. A RAM drive reduces the swap file thrashing which causes fast wear on the device.
    C. Issue FW-1 bases its package structure on the Security Management Server, dynamically loading when the firewall is booted.
    D. PRAM flash devices are used, eliminating the longevity.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-215.13 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.