156-215.81.20 Exam Details

  • Exam Code
    :156-215.81.20
  • Exam Name
    :Check Point Certified Security Administrator - R81.20 (CCSA)
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :677 Q&As
  • Last Updated
    :May 26, 2026

CheckPoint 156-215.81.20 Online Questions & Answers

  • Question 571:

    Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?

    A. All Site-to-Site VPN Communities
    B. Accept all encrypted traffic
    C. All Connections (Clear or Encrypted)
    D. Specific VPN Communities

  • Question 572:

    What is the purpose of the Stealth Rule?

    A. To reduce the amount of logs for performance issues.
    B. To reduce the number of rules in the database.
    C. To prevent users from directly connecting to a Security Gateway.
    D. To make the gateway visible to the Internet.

  • Question 573:

    Which type of Check Point license is tied to the IP address of a specific Security Gateway and cannot be transferred to a gateway that has a different IP address?

    A. Central
    B. Corporate
    C. Formal
    D. Local

  • Question 574:

    What will be the effect of running the following command on the Security Management Server?

    A. Remove the installed Security Policy.
    B. Remove the local ACL lists.
    C. No effect.
    D. Reset SIC on all gateways.

  • Question 575:

    What is the main objective when using Application Control?

    A. To see what users are doing.
    B. Ensure security and privacy of information.
    C. To filter out specific content.
    D. To assist the firewall blade with handling traffic.

  • Question 576:

    Which of the following Windows Security Events will NOT map a username to an IP address in Identity Awareness?

    A. Kerberos Ticket Renewed
    B. Kerberos Ticket Requested
    C. Account Logon
    D. Kerberos Ticket Timed Out

  • Question 577:

    What must a Security Administrator do to comply with a management requirement to log all traffic accepted through the perimeter Security Gateway?

    A. In Global Properties > Reporting Tools check the box Enable tracking all rules (including rules marked as None in the Track column). Send these logs to a secondary log server for a complete logging history. Use your normal log server for standard logging for troubleshooting.
    B. Install the View Implicit Rules package using SmartUpdate.
    C. Define two log servers on the R77 Gateway object. Lof Implied Rules on the first log server. Enable Log Rule Base on the second log server. Use SmartReporter to merge the two log server records into the same database for HIPPA log audits.
    D. Check the Log Implied Rules Globally box on the R77 Gateway object.

  • Question 578:

    Which key is created during Phase 2 of a site-to-site VPN?

    A. Pre-shared secret
    B. Diffie-Hellman Public Key
    C. Symmetrical IPSec key
    D. Diffie-Hellman Private Key

  • Question 579:

    After a new Log Server is added to the environment and the SIC trust has been established with the SMS what will the gateways do?

    A. Gateways will send new firewall logs to the new Log Server as soon as the SIC trust is set up between the SMS and the new Log Server.
    B. Logs are not automatically forwarded to a new Log Server. SmartConsole must be used to manually configure each gateway to send its logs to the server.
    C. The firewalls will detect the new Log Server after the next policy install and redirect the new logs to the new Log Server.
    D. The gateways can only send logs to an SMS and cannot send logs to a Log Server. Log Servers are proprietary log archive servers.

  • Question 580:

    A Check Point Software license consists of two components, the Software Blade and the Software Container. There are ______________ types of Software Containers: ______________.

    A. Three; Security Management, Security Gateway, and Endpoint Security
    B. Three; Security Gateway, Endpoint Security, and Gateway Management
    C. Two; Security Management and Endpoint Security
    D. Two; Endpoint Security and Security Gateway

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-215.81.20 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.