156-215.77 Exam Details

  • Exam Code
    :156-215.77
  • Exam Name
    :Check Point Certified Security Administrator
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :358 Q&As
  • Last Updated
    :Dec 13, 2024

CheckPoint 156-215.77 Online Questions & Answers

  • Question 181:

    Which of the following statements accurately describes the command upgrade_export?

    A. upgrade_export stores network-configuration data, objects, global properties, and the database revisions prior to upgrading the Security Management Server.
    B. Used primarily when upgrading the Security Management Server, upgrade_export stores all object databases and the /conf directories for importing to a newer Security Gateway version.
    C. upgrade_export is used when upgrading the Security Gateway, and allows certain files to be included or excluded before exporting.
    D. This command is no longer supported in GAiA.

  • Question 182:

    Which command displays the installed Security Gateway version?

    A. fw printver
    B. fw ver
    C. fw stat
    D. cpstat -gw

  • Question 183:

    Which R77 feature or command allows Security Administrators to revert to earlier Security Policy versions without changing object configurations?

    A. upgrade_export/upgrade_import
    B. fwm dbexport/fwm dbimport
    C. Database Revision Control
    D. Policy Package management

  • Question 184:

    You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.

    A. You checked the cache password on desktop option in Global Properties.
    B. Another rule that accepts HTTP without authentication exists in the Rule Base.
    C. You have forgotten to place the User Authentication Rule before the Stealth Rule.
    D. Users must use the SecuRemote Client, to use the User Authentication Rule.

  • Question 185:

    Which of the following describes the default behavior of an R77 Security Gateway?

    A. Traffic not explicitly permitted is dropped.
    B. Traffic is filtered using controlled port scanning.
    C. All traffic is expressly permitted via explicit rules.
    D. IP protocol types listed as secure are allowed by default, i.e. ICMP, TCP, UDP sessions are inspected.

  • Question 186:

    Jennifer McHanry is CEO of ACME. She recently bought her own personal iPad. She wants use her iPad to access the internal Finance Web server. Because the iPad is not a member of the Active Directory domain, she cannot identify

    seamlessly with AD Query. However, she can enter her AD credentials in the Captive Portal and then get the same access as on her office computer. Her access to resources is based on rules in the R77 Firewall Rule Base.

    To make this scenario work, the IT administrator must:

    1) Enable Identity Awareness on a gateway and select Captive Portal as one of the Identity Sources.

    2) In the Portal Settings window in the User Access section, make sure that Name and password login is selected.

    3) Create a new rule in the Firewall Rule Base to let Jennifer McHanry access network destinations. Select accept as the Action.

    Ms. McHanry tries to access the resource but is unable. What should she do?

    A. Have the security administrator select the Action field of the Firewall Rule "Redirect HTTP connections to an authentication (captive) portal?
    B. Have the security administrator reboot the firewall
    C. Have the security administrator select Any for the Machines tab in the appropriate Access Role
    D. Install the Identity Awareness agent on her iPad

  • Question 187:

    You want to implement Static Destination NAT in order to provide external, Internet users access to an internal Web Server that has a reserved (RFC 1918) IP address. You have an unused valid IP address on the network between your Security Gateway and ISP router. You control the router that sits between the firewall external interface and the Internet.

    What is an alternative configuration if proxy ARP cannot be used on your Security Gateway?

    A. Publish a proxy ARP entry on the ISP router instead of the firewall for the valid IP address.
    B. Place a static ARP entry on the ISP router for the valid IP address to the firewall's external address.
    C. Publish a proxy ARP entry on the internal Web server instead of the firewall for the valid IP address.
    D. Place a static host route on the firewall for the valid IP address to the internal Web server.

  • Question 188:

    Which utility allows you to configure the DHCP service on GAiA from the command line?

    A. ifconfig
    B. sysconfig
    C. cpconfig
    D. dhcp_cfg

  • Question 189:

    What type of traffic can be re-directed to the Captive Portal?

    A. SMTP
    B. HTTP
    C. All of the above
    D. FTP

  • Question 190:

    The User Directory Software Blade is used to integrate which of the following with Security Gateway R77?

    A. RADIUS server
    B. Account Management Client server
    C. UserAuthority server
    D. LDAP server

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-215.77 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.