156-315.81 Exam - Check Point Certified Security Expert R81

certleader.com

Tested of 156-315.81 training materials and exams for CheckPoint certification for IT learners, Real Success Guaranteed with Updated 156-315.81 pdf dumps vce Materials. 100% PASS Check Point Certified Security Expert R81 exam Today!

Also have 156-315.81 free dumps questions for you:

NEW QUESTION 1

You are investigating issues with to gateway cluster members are not able to establish the first initial cluster
synchronization. What service is used by the FWD daemon to do a Full Synchronization?

  • A. TCP port 443
  • B. TCP port 257
  • C. TCP port 256
  • D. UDP port 8116

Answer: C

NEW QUESTION 2

What is the valid range for Virtual Router Identifier (VRID) value in a Virtual Routing Redundancy Protocol (VRRP) configuration?

  • A. 1-254
  • B. 1-255
  • C. 0-254
  • D. 0 – 255

Answer: B

NEW QUESTION 3

Using Threat Emulation technologies, what is the best way to block .exe and .bat file types?

  • A. enable DLP and select.exe and .bat file type
  • B. enable .exe & .bat protection in IPS Policy
  • C. create FW rule for particular protocol
  • D. tecli advanced attributes set prohibited_file_types exe.bat

Answer: A

NEW QUESTION 4

What cloud-based SandBlast Mobile application is used to register new devices and users?

  • A. Check Point Protect Application
  • B. Management Dashboard
  • C. Behavior Risk Engine
  • D. Check Point Gateway

Answer: D

NEW QUESTION 5

Which command is used to add users to or from existing roles?

  • A. Add rba user <User Name> roles <List>
  • B. Add rba user <User Name>
  • C. Add user <User Name> roles <List>
  • D. Add user <User Name>

Answer: A

NEW QUESTION 6

John detected high load on sync interface. Which is most recommended solution?

  • A. For FTP connections – do not sync
  • B. Add a second interface to handle sync traffic
  • C. For short connections like http service – do not sync
  • D. For short connections like icmp service – delay sync for 2 seconds

Answer: A

NEW QUESTION 7

Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.

  • A. Symmetric routing
  • B. Failovers
  • C. Asymmetric routing
  • D. Anti-Spoofing

Answer: C

NEW QUESTION 8

Which of the following is NOT a type of Endpoint Identity Agent?

  • A. Terminal
  • B. Light
  • C. Full
  • D. Custom

Answer: A

NEW QUESTION 9

What is the minimum number of CPU cores required to enable CoreXL?

  • A. 1
  • B. 6
  • C. 2
  • D. 4

Answer: C

Explanation:
Default number of CoreXL IPv4 FW instances:
Note: The real number of CoreXL FW instances depends on the current CoreXL license. Number of
CPU cores Default number of CoreXL IPv4
FW instances Default number of Secure Network Distributors (SNDs)
1 1
Note: CoreXL is disabled 0 Note: CoreXL is disabled
2 2 2
4 3 1
6 - 20 [Number of CPU cores] - 2 2
More than 20 (1) [Number of CPU cores] - 4 4

NEW QUESTION 10

Identify the API that is not supported by Check Point currently.

  • A. R81 Management API
  • B. Identity Awareness Web Services API
  • C. Open REST API
  • D. OPSEC SDK

Answer: C

NEW QUESTION 11

Which one of the following is true about Capsule Connect?

  • A. It is a full layer 3 VPN client
  • B. It offers full enterprise mobility management
  • C. It is supported only on iOS phones and Windows PCs
  • D. It does not support all VPN authentication methods

Answer: A

NEW QUESTION 12

SandBlast agent extends 0 day prevention to what part of the network?

  • A. Web Browsers and user devices
  • B. DMZ server
  • C. Cloud
  • D. Email servers

Answer: A

NEW QUESTION 13

What is required for a site-to-site VPN tunnel that does not use certificates?

  • A. Pre-Shared Secret
  • B. RSA Token
  • C. Unique Passwords
  • D. SecurelD

Answer: A

NEW QUESTION 14

After trust has been established between the Check Point components, what is TRUE about name and IP-address changes?

  • A. Security Gateway IP-address cannot be changed without re-establishing the trust.
  • B. The Security Gateway name cannot be changed in command line without re-establishing trust.
  • C. The Security Management Server name cannot be changed in SmartConsole without re-establishing trust.
  • D. The Security Management Server IP-address cannot be changed without re-establishing the trust.

Answer: A

NEW QUESTION 15

Which command is used to set the CCP protocol to Multicast?

  • A. cphaprob set_ccp multicast
  • B. cphaconf set_ccp multicast
  • C. cphaconf set_ccp no_broadcast
  • D. cphaprob set_ccp no_broadcast

Answer: B

NEW QUESTION 16

Fill in the blank: Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or ______.

  • A. On all satellite gateway to satellite gateway tunnels
  • B. On specific tunnels for specific gateways
  • C. On specific tunnels in the community
  • D. On specific satellite gateway to central gateway tunnels

Answer: C

NEW QUESTION 17

If SecureXL is disabled which path is used to process traffic?

  • A. Passive path
  • B. Medium path
  • C. Firewall path
  • D. Accelerated path

Answer: C

NEW QUESTION 18
......

100% Valid and Newest Version 156-315.81 Questions & Answers shared by Surepassexam, Get Full Dumps HERE: https://www.surepassexam.com/156-315.81-exam-dumps.html (New 617 Q&As)