156-315.77 Exam Details

  • Exam Code
    :156-315.77
  • Exam Name
    :Check Point Certified Security Expert
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :735 Q&As
  • Last Updated
    :Dec 13, 2024

CheckPoint 156-315.77 Online Questions & Answers

  • Question 471:

    Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the following requirements: Portability: Standard Key management: Automatic, external PKI Session keys: Changed at configured times during a connection's lifetime Key length: No less than 128-bit Data integrity: Secure against inversion andbruteforce attacks What is the most appropriate setting Yoav should choose?

    A. IKE VPNs: AES encryption for IKE Phase 1, and DES encryption for Phase 2; SHA1 hash
    B. IKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for Phase 2; AES hash
    C. IKE VPNs: CAST encryption for IKE Phase 1, and SHA1 encryption for Phase 2; DES hash
    D. IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash
    E. IKE VPNs: DES encryption for IKE Phase 1, and 3DES encryption for Phase 2; MD5 hash

  • Question 472:

    One profile in SmartProvisioning can update:

    A. Potentially hundreds and thousands of gateways.
    B. Only Clustered Gateways.
    C. Specific gateways.
    D. Profiles are not used for updating, just reporting.

  • Question 473:

    Which of the following can NOT approve a change in aSmart Workflowsession?

    A. FirewallAdministrators
    B. FirewallManagers
    C. Provider-1Super users
    D. CustomerSuper users

  • Question 474:

    What is the default port number for standard TCP connections with the LDAP server?

    A. 398
    B. 636
    C. 389
    D. 363

  • Question 475:

    Your online bookstore has customers connecting to a variety of Web servers to place or change orders and check order status. You ran penetration tests through the Security Gateway to determine if the Web servers were protected from a recent series of cross-site scripting attacks. The penetration testing indicated the Web servers were still vulnerable. You have checked every box in the Web Intelligence tab, and installed the Security Policy. What else might you do to reduce the vulnerability?

    A. Configure the Security Gateway protecting the Web servers as a Web server.
    B. Check the Products / Web Server box on the host node objects representing your Web servers.
    C. Add Port (TCP 443) as an additional port on the Web Server tab for the host node.
    D. The penetration software you are using is malfunctioning and is reporting a false- positive.

  • Question 476:

    You want to create an IKE VPN between two VPN-1 NGX Security Gateways, to protect two networks. The network behind one Gateway is 10.15.0.0/16, and network 192.168.9.0/24 is behind the peer's Gateway. Which type of address translation should you use, to ensure the two networks access each other through the VPN tunnel?

    A. Manual NAT
    B. Static NAT
    C. Hide NAT
    D. None
    E. Hide NAT

  • Question 477:

    Which of the following commands do you run on the AD server to identify the DN name before configuring LDAP integration with the Security Gateway?

    A. query ldap -name administrator
    B. dsquery user -name administrator
    C. ldapquery -name administrator
    D. cpquery -name administrator

  • Question 478:

    What physical machine must have access to the UserCenter public IP when checking for new packages with SmartUpdate?

    A. VPN-1 Security Gateway getting the new upgrade package
    B. SmartUpdate installed SmartCenter Server PC
    C. SmartUpdate Repository SQL database Server
    D. SmartUpdate GUI PC

  • Question 479:

    What is a task of theSmart EventServer?

    A. Assign a severity level to an event.
    B. Display the received events.
    C. Analyze each IPS log entry as it enters the Log server.
    D. Forward what is known as an event to theSmart EventServer.

  • Question 480:

    Which load-balancing method below is NOT valid?

    A. Domain
    B. They are all valid
    C. Round Trip
    D. Random

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-315.77 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.