Exam Details

  • Exam Code
    :156-315.77
  • Exam Name
    :Check Point Certified Security Expert
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :60 Q&As
  • Last Updated
    :Dec 13, 2024

CheckPoint Checkpoint Certifications 156-315.77 Questions & Answers

  • Question 241:

    Your customer wishes to useSmart WorkflowSoftware Blade, but he also wishes to install a policy during an emergency without an approval. Is it possible?

    A. Yes, it is possible but the administrator must receive special administrator permission,

    B. e., Can install in emergency. You can use the new GUI to set the administration security setting.

    C. Yes, it is possible, but this feature must be configured in the Global Properties. The administrator must provide a special password and the reason for this emergency installation.

    D. Yes, it is possible, but this feature must be configured in Global Properties and the administrator must provide a special password.

    E. No, if a customer uses theSmart WorkflowSoftware Blade, a policy must be approved.

  • Question 242:

    Which of the following does IPSec use during IPSec key negotiation?

    A. IPSec SA

    B. RSA Exchange

    C. ISAKMP SA

    D. Diffie-Hellman exchange

  • Question 243:

    Your current stands alone VPN-1 NG with Application Intelligence (Al) R55 installation is running on SecurePlatform. You plan to implement VPN-1 NGX in a distributed environment, where the existing machine will be the VPN-1 Pro Gateway. An additional machine will serve as the SmartCenter Server. The new machine runs on a Windows Server 2003. You need to upgrade the NG with Al R55 SmartCenter Server configuration to VPN-1 NGX.

    How do you upgrade to VPN-1 NGX?

    A. Insert the NGX CD in the existing NGwithAI R55 SecurePlatform machine, and answer yes to backup the configuration. Copy the backup file to the Windows Server 2003. Continue the upgrade process. Reboot after upgrade is finished. After SecurePlatform NGX reboots, run sysconfig, select VPN-1 Pro Gateway, and finish the sysconfig process. Reboot again. Use the NGX CD to install the primary SmartCenter on the Windows Server 2003. Import the backup file.

    B. Run the backup command in the existing SecurePlatform machine, to create a backup file. Copy the file to the Windows Server 2003. Uninstall all Check Point products on SecurePlatform by running rpm CPsuitE. R55 command. Reboot. Install new VPN-1 NGX on the existing SecurePlatform machine. Run sysconfig, select VPN-1 Pro Gateway, and reboot. Use VPN-1 NGX CD to install primary SmartCenter Server on the Windows Server 2003. Import the backup file.

    C. Copy the $FWDIR\conf and $FWDIR\lib files from the existing SecurePlatform machine. Create a tar.gzfile, and copy it to the Windows Server 2003. Use VPN-1 NGX CD on the existing SecurePlatform machine to do a new installation. Reboot. Run sysconfig and select VPN-1 Pro Gateway. Reboot. Use the NGX CD to install the primary SmartCenter Server on the Windows Server 2003. On the Windows Server 2003, run upgradeimport command to import $FWDIR\conf and $FWDIR\lib from the SecurePlatform machine.

    D. Run backup command on the existing SecurePlatform machine to create a backup file. Copy the file to the Windows Server 2003. Uninstall the primary SmartCenter Server package from NG with Al R55 SecurePlatform using sysconfig. Reboot. Install the NGX primary SmartCenter Server and import the backup file. Open the NGX SmartUpdate, and select "upgrade all packages" on the NG with Al R55 Security Gateway.

  • Question 244:

    Which of the following is supported with Office Mode?

    A. Secure mote

    B. Secure Client

    C. SSL Network Extender

    D. Connect Mode

  • Question 245:

    You are using SmartUpdate to fetch data and perform a remote upgrade of an NGX Security Gateway. Which of the following statements is FALSE?

    A. If SmartDashboard is open during package upload and upgrade, the upgrade will fail.

    B. A remote installation can be performed without the SVN Foundation package installed on a remote NG with Application Intelligence Security Gateway

    C. SmartUpdate can query the SmartCenter Server and VPN-1 Gateway for product information

    D. SmartUpdate can query license information running locally on the VPN-1 Gateway

  • Question 246:

    Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the following requirements: Portability: Standard Key management: Automatic, external PKI Session keys: Changed at configured times during a connection's lifetime Key length: No less than 128-bit Data integrity: Secure against inversion andbruteforce attacks What is the most appropriate setting Yoav should choose?

    A. IKE VPNs: AES encryption for IKE Phase 1, and DES encryption for Phase 2; SHA1 hash

    B. IKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for Phase 2; AES hash

    C. IKE VPNs: CAST encryption for IKE Phase 1, and SHA1 encryption for Phase 2; DES hash

    D. IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash

    E. IKE VPNs: DES encryption for IKE Phase 1, and 3DES encryption for Phase 2; MD5 hash

  • Question 247:

    Damon enables an SMTP resource for content protection. He notices that mail seems to slow down on occasion, sometimes being delivered late. Which of the following might improve throughput performance?

    A. Configuring the SMTP resource to bypass the CVP resource

    B. Increasing the Maximum number of mail messages in the Gateway's spool directory

    C. Configuring the Content Vector Protocol (CVP) resource to forward the mail to the internal SMTP server, without waiting for a response from the Security Gateway

    D. Configuring the CVP resource to return the mail to the Gateway

    E. Configuring the SMTP resource to only allow mail with Damon's company's domain name in the header

  • Question 248:

    You must set up SIP with a proxy for your network. IP phones are in the 172.16.100.0 network. The Registrar and proxy are installed on host 172.16.100.100. To allow handover enforcement for outbound calls from SIP-net to network Net_B on the Internet, you have defined the following objects: Network object: SIP-net: 172.16.100.0/24 SIP-gateway: 172.16.100.100 VoIP Domain object: VolP_domain_A 1.Endpoint domain: SIP-net 2.VoIP gateway installed at: SIP-gateway host object How would you configure the rule?

    A. SIP- G ateway/N et_B/s i p_a ny/a c c e pt

    B. VolP_domain_A/Net_B/sip/accept

    C. SIP-Gateway/Net_B/sip/accept

    D. VolP_domain_A/Net_B/sip_any, and sip/accept

    E. VolP_Gateway_MJet_B/sip_any/accept

  • Question 249:

    Identify the correct step performed by SmartUpdate to upgrade a remote Security Gateway.

    A. After selecting "Packages > Distribute..." and choosing the target gateway, the selected package is copied from the Package Repository on the SmartCenter to the Security Gateway but the installation IS NOT performed.

    B. After selecting "Packages > Distribute..." and choosing the target gateway, the SmartUpdate wizard walks the Administrator through a Distributed Installation.

    C. After selecting "Packages > Distribute..." and choosing the target gateway, the selected package is copied from the Package Repository on the SmartCenter to the Security Gateway and the installation IS performed.

    D. After selecting "Packages > Distribute..." and choosing the target gateway, the selected package is copied from the CDROM of the SmartUpdate PC directly to the Security Gateway and the installation IS performed.

  • Question 250:

    When you add a resource service to a rule, which ONE of the following actions occur?

    A. VPN-1 Secure Client users attempting to connect to the object defined in the Destination column of the rule will receive a new Desktop Policy from the resource.

    B. All packets that match the resource in the rule will be dropped.

    C. All packets matching the resource service rule are analyzed or authenticated, based on the resource properties.

    D. Users attempting to connect to the destination of the rule will be required to authenticate.

    E. All packets matching that rule are either encrypted or decrypted by the defined resource.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-315.77 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.