156-215.81.20 Exam Details

  • Exam Code
    :156-215.81.20
  • Exam Name
    :Check Point Certified Security Administrator - R81.20 (CCSA)
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :677 Q&As
  • Last Updated
    :May 26, 2026

CheckPoint 156-215.81.20 Online Questions & Answers

  • Question 451:

    Which of these statements describes the Check Point ThreatCloud?

    A. Blocks or limits usage of web applications
    B. Prevents or controls access to web sites based on category
    C. Prevents Cloud vulnerability exploits
    D. A worldwide collaborative security network

  • Question 452:

    Which command can you use to enable or disable multi-queue per interface?

    A. cpmq set
    B. Cpmqueue set
    C. Cpmq config
    D. Set cpmq enable

  • Question 453:

    There are two R77.30 Security Gateways in the Firewall Cluster. They are named FW_A and FW_B. The cluster is configured to work as HA (High availability) with default cluster configuration. FW_A is configured to have higher priority than FW_B. FW_A was active and processing the traffic in the morning. FW_B was standby. Around 1100 am, its interfaces went down and this caused a failover. FW_B became active. After an hour, FW_A's interface issues were resolved and it became operational. When it re-joins the cluster, will it become active automatically?

    A. No, since "maintain current active cluster member" option on the cluster object properties is enabled by default
    B. No, since "maintain current active cluster member" option is enabled by default on the Global Properties
    C. Yes, since "Switch to higher priority cluster member" option on the cluster object properties is enabled by default
    D. Yes, since "Switch to higher priority cluster member" option is enabled by default on the Global Properties

  • Question 454:

    You have configured SNX on the Security Gateway. The client connects to the Security Gateway and the user enters the authentication credentials. What must happen after authentication that allows the client to connect to the Security Gateway's VPN domain?

    A. SNX modifies the routing table to forward VPN traffic to the Security Gateway.
    B. An office mode address must be obtained by the client.
    C. The SNX client application must be installed on the client.
    D. Active-X must be allowed on the client.

  • Question 455:

    Vanessa is attempting to log into the Gaia Web Portal. She is able to login successfully. Then she tries the same username and password for SmartConsole but gets the message in the screenshot image below. She has checked that the IP address of the Server is correct and the username and password she used to login into Gaia is also correct.

    What is the most likely reason?

    A. Check Point R80 SmartConsole authentication is more secure than in previous versions and Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.
    B. Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.
    C. SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.
    D. Authentication failed because Vanessa's username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.

  • Question 456:

    Which of the following is NOT an alert option?

    A. SNMP
    B. High alert
    C. Mail
    D. User defined alert

  • Question 457:

    An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security Management Server. While configuring the VPN community to specify the pre-shared secret the administrator found that the check box to enable pre-shared secret is shared and cannot be enabled. Why does it not allow him to specify the pre-shared secret?

    A. IPsec VPN blade should be enabled on both Security Gateway.
    B. Pre-shared can only be used while creating a VPN between a third party vendor and Check Point Security Gateway.
    C. Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS.
    D. The Security Gateways are pre-R75.40.

  • Question 458:

    Fill in the blank: The tool _______ generates a R80 Security Gateway configuration report.

    A. infoCP
    B. infoview
    C. cpinfo
    D. fw cpinfo

  • Question 459:

    Web Control Layer has been set up using the settings in the following dialogue:

    Consider the following policy and select the BEST answer.

    A. Traffic that does not match any rule in the subpolicy is dropped.
    B. All employees can access only Youtube and Vimeo.
    C. Access to Youtube and Vimeo is allowed only once a day.
    D. Anyone from internal network can access the internet, expect the traffic defined in drop rules 5.2, 5.5 and 5.6.

  • Question 460:

    Which command is used to add users to or from existing roles?

    A. Add rba user roles
    B. Add rba user
    C. Add user roles
    D. Add user

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-215.81.20 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.