156-215.77 Exam - Check Point Certified Security Administrator – GAiA

certleader.com

Q1. - (Topic 3) 

You are trying to save a custom log query in R77 SmartView Tracker, but getting the following error: 

Could not save <query-name> (Error: Database is Read Only) 

Which of the following is a likely explanation for this? 

A. You do not have OS write permissions on the local SmartView Tracker PC in order to save the custom query locally. 

B. You do not have the explicit right to save a custom query in your administrator permission profile under SmartConsole customization. 

C. Another administrator is currently connected to the Security Management Server with read/write permissions which impacts your ability to save custom log queries to the Security Management Server. 

D. You have read-only rights to the Security Management Server database. 

Answer:

Q2. - (Topic 3) 

Identity Awareness is implemented to manage access to protected resources based on a user’s _____________. 

A. Application requirement 

B. Computer MAC address 

C. Identity 

D. Time of connection 

Answer:

Q3. - (Topic 2) 

How do you use SmartView Monitor to compile traffic statistics for your company's Internet Web activity during production hours? 

A. View total packets passed through the Security Gateway. 

B. Configure a Suspicious Activity Rule which triggers an alert when HTTP traffic passes through the Gateway. 

C. Use Traffic settings and SmartView Monitor to generate a graph showing the total HTTP traffic for the day. 

D. Select Tunnels view, and generate a report on the statistics. 

Answer:

Q4. - (Topic 3) 

What is the difference between Standard and Specific Sign On methods? 

A. Standard Sign On allows the user to be automatically authorized for all services that the rule allows. Specific Sign On requires that the user re-authenticate for each service and each host to which he is trying to connect. 

B. Standard Sign On allows the user to be automatically authorized for all services that the rule allows. Specific Sign On requires that the user re-authenticate for each service specifically defined in the window Specific Action Properties. 

C. Standard Sign On requires the user to re-authenticate for each service and each host to which he is trying to connect. Specific Sign On allows the user to sign on only to a specific IP address. 

D. Standard Sign On allows the user to be automatically authorized for all services that the rule allows, but re-authenticate for each host to which he is trying to connect. Specific Sign On requires that the user re-authenticate for each service. 

Answer:

Q5. - (Topic 3) 

Where do you verify that UserDirectory is enabled? 

A. Verify that Security Gateway > General Properties > Authentication > Use UserDirectory (LDAP) for Security Gateways is checked 

B. Verify that Global Properties > Authentication > Use UserDirectory (LDAP) for Security Gateways is checked 

C. Verify that Security Gateway > General Properties > UserDirectory (LDAP) > Use UserDirectory (LDAP) for Security Gateways is checked 

D. Verify that Global Properties > UserDirectory (LDAP) > Use UserDirectory (LDAP) for Security Gateways is checked 

Answer:

Q6. - (Topic 3) 

You are running the license_upgrade tool on your SecurePlatform Gateway. Which of the following can you NOT do with the upgrade tool? 

A. Perform the actual license-upgrade process 

B. View the status of currently installed licenses 

C. Simulate the license-upgrade process 

D. View the licenses in the SmartUpdate License Repository 

Answer:

Q7. - (Topic 3) 

Charles requests a Website while using a computer not in the net_singapore network. 

What is TRUE about his location restriction? 

A. As location restrictions add up, he would be allowed from net_singapore and net_sydney. 

B. It depends on how the User Auth object is configured; whether User Properties or Source Restriction takes precedence. 

C. Source setting in User Properties always takes precedence. 

D. Source setting in Source column always takes precedence. 

Answer:

Q8. - (Topic 1) 

Which of the following statements accurately describes the command upgrade_export? 

A. Used primarily when upgrading the Security Management Server, upgrade_export stores all object databases and the /conf directories for importing to a newer Security Gateway version. 

B. upgrade_export stores network-configuration data, objects, global properties, and the database revisions prior to upgrading the Security Management Server. 

C. This command is no longer supported in GAiA. 

D. upgrade_export is used when upgrading the Security Gateway, and allows certain files to be included or excluded before exporting. 

Answer:

Q9. - (Topic 2) 

Which of the following is a viable consideration when determining Rule Base order? 

A. Adding SAM rules at the top of the Rule Base 

B. Placing frequently accessed rules before less frequently accessed rules 

C. Grouping rules by date of creation 

D. Grouping IPS rules with dynamic drop rules 

Answer:

Q10. - (Topic 2) 

By default, when you click File > Switch Active File in SmartView Tracker, the Security Management Server: 

A. Purges the current log file, and prompts you for the new log's mode. 

B. Purges the current log file, and starts a new log file. 

C. Saves the current log file, names the log file by date and time, and starts a new log file. 

D. Prompts you to enter a filename, and then saves the log file. 

Answer: