Skip to main content

156-215.81 Online Practice Questions

Check Point Certified Security Administrator - R81 (CCSA)

400 questions available · Page 1 of 40

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

An administrator wishes to use Application objects in a rule in their policy but there are no Application objects listed as options to add when clicking the"+" to add new items to the "Services & Applications" column of a rule.

What should be done to fix this?

  1. A

    The administrator should drag-and-drop the needed Application objects from the Object Explorer into the new rule

  2. B

    The "Application Control" blade should be enabled on a gateway

  3. C

    "Applications & URL Filtering" should first be enabled on the policy layer where the rule is being created.

  4. D

    The administrator should first create some applications to add to the rule.

Show answer and explanation

Correct answer: C

Explanation

To use Application objects in a rule, the "Applications & URL Filtering" blade should be enabled on the policy layer where the rule is being created. Enabling the "Application Control" blade on a gateway is not enough.
References:
Check Point R81 Security Management Administration Guide, page 102.

Question 2 Single choice

Fill in the blank: Service blades must be attached to a ______________.

  1. A

    Security Gateway

  2. B

    Management container

  3. C

    Management server

  4. D

    Security Gateway container

Show answer and explanation

Correct answer: A

Explanation

Service blades must be attached to a Security Gateway. A Security Gateway is a device that enforces security policies on traffic that passes through it. A service blade is a software module that provides a specific security function, such as firewall, VPN, IPS, etc. A Security Gateway can have one or more service blades attached to it, depending on the license and hardware capabilities. The other options are incorrect. A management container is a virtualized environment that hosts a Security Management Server or a Log Server. A management server is a device that manages security policies and distributes them to Security Gateways. A Security Gateway container is not a valid term in Check Point terminology.
References:
[Check Point R81 Security Management Administration Guide], [Check Point R81 CloudGuard
Administration Guide]

Question 3 Single choice

Which GUI tool can be used to view and apply Check Point licenses?

  1. A

    cpconfig

  2. B

    Management Command Line

  3. C

    SmartConsole

  4. D

    SmartUpdate

Show answer and explanation

Correct answer: D

Explanation

The GUI tool that can be used to view and apply Check Point licenses is SmartUpdate. SmartUpdate is a centralized tool that allows you to manage licenses, software packages, and hotfixes for multiple gateways and clusters. cpconfig, Management Command Line, and SmartConsole are not tools for license management.
References:
Check Point R81 SmartUpdate Administration Guide, | Udemy

Question 4 Single choice

What are the two types of NAT supported by the Security Gateway?

  1. A

    Destination and Hide

  2. B

    Hide and Static

  3. C

    Static and Source

  4. D

    Source and Destination

Show answer and explanation

Correct answer: B

Explanation

The two types of NAT supported by the Security Gateway are hide NAT and static NAT. Hide NAT translates many source IP addresses into one IP address, usually the external interface of the gateway.
Static NAT translates one source IP address into another IP address, usually a public IP address. The other options are not valid types of NAT.
References:
Network Address Translation (NAT),

Question 5 Single choice

Why is a Central License the preferred and recommended method of licensing?

  1. A

    Central Licensing is actually not supported with Gaia.

  2. B

    Central Licensing is the only option when deploying Gaia

  3. C

    Central Licensing ties to the IP address of a gateway and can be changed to any gateway if needed.

  4. D

    Central Licensing ties to the IP address of the management server and is not dependent on the IP of any gateway in the event it changes.

Show answer and explanation

Correct answer: D

Explanation

Central License is the preferred and recommended method of licensing because it ties to the IP address of the management server and is not dependent on the IP of any gateway in the event it changes. Central License allows administrators to manage licenses for all Security Gateways from one central location. If the IP address of a gateway changes, the license remains valid as long as it is connected to the same management server. Central Licensing is supported with Gaia and is not the only option when deploying Gaia. Central Licensing does not tie to the IP address of a gateway and can not be changed to any gateway if needed.

References:
1: Rugged Appliances
2: SmartUpdate
3: Check Point Software Deployment Options : [Anti-Virus] : [Check Point Software Blades] : [Central
License]

Question 6 Single choice

Fill in the blank: The_____is used to obtain identification and security information about network users.

  1. A

    User index

  2. B

    UserCheck

  3. C

    User Directory

  4. D

    User server

Show answer and explanation

Correct answer: C

Explanation

The User Directory is used to obtain identification and security information about network users. It can be integrated with external user databases such as LDAP, RADIUS, or TACACS+.
References:
Certified Security Administrator (CCSA) R81.20 Course Overview, page 9.

Question 7 Single choice

In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?

  1. A

    SND is a feature to accelerate multiple SSL VPN connections

  2. B

    SND is an alternative to IPSec Main Mode, using only 3 packets

  3. C

    SND is used to distribute packets among Firewall instances

  4. D

    SND is a feature of fw monitor to capture accelerated packets

Show answer and explanation

Correct answer: C

Explanation

The Secure Network Distributor (SND) is a feature of the Security Gateway that is used to distribute packets among Firewall instances . It improves the performance and scalability of the Firewall by utilizing multiple CPU cores. The other options are not related to SND.
References:
[Check Point Security Gateway Architecture and Packet Flow], [Free Check Point CCSA Sample Questions and Study Guide]

Question 8 Single choice

Which of the following is the most secure means of authentication?

  1. A

    Password

  2. B

    Certificate

  3. C

    Token

  4. D

    Pre-shared secret

Show answer and explanation

Correct answer: B

Explanation

Certificate is the most secure means of authentication among the given options. A certificate is a digital document that contains information about the identity of a user or a device, and is signed by a trusted authority. A certificate can be used to prove the identity of a user or a device without revealing any sensitive information, such as passwords or tokens. Password, token, and pre-shared secret are less secure means of authentication because they can be easily compromised, stolen, or guessed by attackers.
References:
Secure User Authentication Methods - freeCodeCamp.org, What is the Most Secure
Authentication Method for Your Organization ...

Question 9 Single choice

You want to store the GAiA configuration in a file for later reference.

What command should you use?

  1. A

    write mem <filename>

  2. B

    show config -f <filename>

  3. C

    save config -o <filename>

  4. D

    save configuration <filename>

Show answer and explanation

Correct answer: D

Explanation

The correct answer is D because the command save configuration <filename> stores the Gaia configuration in a file for later reference. The other commands are not valid in Gaia Clish.
References:
Gaia R81.10 Administration Guide

Question 10 Single choice

A SAM rule Is implemented to provide what function or benefit?

  1. A

    Allow security audits.

  2. B

    Handle traffic as defined in the policy.

  3. C

    Monitor sequence activity.

  4. D

    Block suspicious activity.

Show answer and explanation

Correct answer: D

Explanation

A SAM (Suspicious Activity Monitoring) rule is implemented to provide the function or benefit of blocking suspicious activity. A SAM rule is a rule that defines an action to be taken by the firewall when it detects a suspicious activity, such as an attack, a scan, or a policy violation. The action can be blocking, dropping, rejecting, or logging the traffic that triggered the suspicious activity. A SAM rule can be created manually or automatically by other security features, such as IPS, Anti-Bot, or SmartEvent.
References:
[SAM Rules], [Suspicious Activity Rules]