156-315.81.20 Exam Details

  • Exam Code
    :156-315.81.20
  • Exam Name
    :Check Point Certified Security Expert - R81.20
  • Certification
    :Checkpoint Certifications
  • Vendor
    :CheckPoint
  • Total Questions
    :641 Q&As
  • Last Updated
    :May 26, 2026

CheckPoint 156-315.81.20 Online Questions & Answers

  • Question 391:

    During the Check Point Stateful Inspection Process, for packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are:

    A. Dropped without sending a negative acknowledgment
    B. Dropped without logs and without sending a negative acknowledgment
    C. Dropped with negative acknowledgment
    D. Dropped with logs and without sending a negative acknowledgment

  • Question 392:

    In CoreXL, the Firewall kernel is replicated multiple times. Each replicated copy or instance can perform the following:

    A. The Firewall kernel only touches the packet if the connection is accelerated
    B. The Firewall kernel is replicated only with new connections and deletes itself once the connection times out
    C. The Firewall can run the same policy on all cores
    D. The Firewall can run different policies per core

  • Question 393:

    GAiA Software update packages can be imported and installed offline in situation where:

    A. Security Gateway with GAiA does NOT have SFTP access to Internet
    B. Security Gateway with GAiA does NOT have access to Internet.
    C. Security Gateway with GAiA does NOT have SSH access to Internet.
    D. The desired CPUSE package is ONLY available in the Check Point CLOUD.

  • Question 394:

    Pamela is Cyber Security Engineer working for Global Instance Firm with large scale deployment of Check Point Enterprise Appliances using GAiA/R81.20. Company's Developer Team is having random access issue to newly deployed Application Server in DMZ's Application Server Farm Tier and blames DMZ Security Gateway as root cause. The ticket has been created and issue is at Pamela's desk for an investigation. Pamela decides to use Check Point's Packet Analyzer Tool-fw monitor to iron out the issue during approved Maintenance window.

    What do you recommend as the best suggestion for Pamela to make sure she successfully captures entire traffic in context of Firewall and problematic traffic?

    A. Pamela should check SecureXL status on DMZ Security gateway and if it's turned ON. She should turn OFF SecureXL before using fw monitor to avoid misleading traffic captures.
    B. Pamela should check SecureXL status on DMZ Security Gateway and if it's turned OFF. She should turn ON SecureXL before using fw monitor to avoid misleading traffic captures.
    C. Pamela should use tcpdump over fw monitor tool as tcpdump works at OS-level and captures entire traffic.
    D. Pamela should use snoop over fw monitor tool as snoop works at NIC driver level and captures entire traffic.

  • Question 395:

    Which CLI command will reset the IPS pattern matcher statistics?

    A. ips reset pmstat
    B. ips pstats reset
    C. ips pmstats refresh
    D. ips pmstats reset

  • Question 396:

    In which VPN community is a satellite VPN gateway not allowed to create a VPN tunnel with another satellite VPN gateway?

    A. Pentagon
    B. Combined
    C. Meshed
    D. Star

  • Question 397:

    What is the base level encryption key used by Capsule Docs?

    A. RSA 2048
    B. RSA 1024
    C. SHA-256
    D. AES

  • Question 398:

    What statement best describes the Proxy ARP feature for Manual NAT in R81.20?

    A. Automatic proxy ARP configuration can be enabled
    B. Translate Destination on Client Side should be configured
    C. fw ctl proxy should be configured
    D. local.arp file must always be configured

  • Question 399:

    What could NOT be a reason for synchronization issues in a Management HA environment?

    A. Servers are in Collision Mode. Two servers, both in active state cannot be synchronized either automatically or manually.
    B. Accidentally, you have configured unique IP addresses per Management Server which invalidates the CA Certificate
    C. There is a network connectivity failure between the servers
    D. The products installed on the servers do not match: one device is a Standalone Server while the other is only a Security Management server.

  • Question 400:

    Please choose the path to monitor the compliance status of the Check Point R81.20 based management.

    A. Gateways & Servers --> Compliance View
    B. Compliance blade not available under R81.20
    C. Logs & Monitor --> New Tab --> Open compliance View
    D. Security & Policies --> New Tab --> Compliance View

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-315.81.20 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.