156-915.80 Exam - Check Point Certified Security Expert Update - R80

certleader.com

P.S. Pinpoint 156-915.80 Q&A are available on Google Drive, GET MORE: https://drive.google.com/open?id=1kHtvfzv89_QPh4A3_cAnuAFq9mDuP3yP


New Check Point 156-915.80 Exam Dumps Collection (Question 6 - Question 15)

Question No: 6

Use the table to match the BEST Management High Availability synchronication-status descriptions for your Security Management Server (SMS).

Exhibit:

A. A-5, B-3, C-1, D-2

B. A-3, B-1, C-4, D-2

C. A-3, B-5, C-2, D-4

D. A-3, B-1, C-5, D-4

Answer: D


Question No: 7

You want VPN traffic to match packets from internal interfaces. You also want the traffic to exit the Security Gateway bound for all site-to-site VPN Communities, including Remote Access Communities. How should you configure the VPN match rule?

A. internal_clear > All_communities

B. Internal_clear > External_Clear

C. Communities > Communities

D. internal_clear > All_GwToGw

Answer: A


Question No: 8

You are investigating issues with two gateway cluster members that are not able to establish the first initial cluster synchronization. What service is used by the FWD daemon to do a Full Synchronization?

A. TCP port 443

B. TCP port 257

C. TCP port 256

D. UDP port 8116

Answer: C

Explanation:

Synchronization works in two modes:

Full sync transfers all Security Gateway kernel table information from one cluster member to another. It is handled by the fwd daemon using an encrypted TCP connection.

Delta sync transfers changes in the kernel tables between cluster members. Delta sync is handled by the Security Gateway kernel using UDP multicast or broadcast on port 8116.

Full sync is used for initial transfers of state information, for many thousands of connections. If a cluster member is brought up after being down, it will perform full sync. After all members are synchronized, only

updates are transferred via delta sync. Delta sync is quicker than full sync.


Question No: 9

MegaCorp is using SmartCenter Server with several gateways. Their requirements result in a heavy log load. Would it be feasible to add the SmartEvent Correlation Unit and SmartEvent Server to their SmartCenter Server?

A. No. SmartCenter SIC will interfere with the function of SmartEvent.

B. No. If SmartCenter is already under stress, the use of a separate server for SmartEvent is recommended.

C. No, SmartEvent and Smartcenter cannot be installed on the same machine at the same time.

D. Yes. SmartEvent must be installed on your SmartCenter Server.

Answer: B


Question No: 10

You are troubleshooting a HTTP connection problem. You've started fw monitor -o http.pcap. When you open http.pcap with Wireshark there is only one line. What is the most likely reason?

A. fw monitor was restricted to the wrong interface.

B. Like SmartView Tracker only the first packet of a connection will be captured by fw monitor.

C. By default only SYN pakets are captured.

D. Acceleration was turned on and therefore fw monitor sees only SYN.

Answer: D


Question No: 11

Paul has just joined the MegaCorp security administration team. Natalie, the administrator, creates a new administrator account for Paul in SmartDashboard and installs the policy. When Paul tries to login it fails. How can Natalie verify whether Paulu2021s IP address is predefined on the security management server?

A. Login to Smart Dashboard, access Properties of the SMS, and verify whether Paulu2021s IP address is listed.

B. Type cpconfig on the Management Server and select the option u201cGUI client Listu201d to see if Paulu2021s IP address is listed.

C. Login in to Smart Dashboard, access Global Properties, and select Security Management, to verify whether Paulu2021s IP address is listed.

D. Access the WEBUI on the Security Gateway, and verify whether Paulu2021s IP address is listed as a GUI client.

Answer: B


Question No: 12

Fill in the blank. The command that typically generates the firewall application, operating system, and hardware specific drivers is .

Answer:

snapshot


Question No: 13

SmartEvent does NOT use which of the following procedures to identify events?

A. Matching a log against each event definition

B. Create an event candidate

C. Matching a log against local exclusions

D. Matching a log against global exclusions

Answer: C

Explanation:

Events are detected by the SmartEvent Correlation Unit. The Correlation Unit task is to scan logs for criteria that match an Event Definition. SmartEvent uses these procedures to identify events:

Matching a Log Against Global Exclusions

Matching a Log Against Each Event Definition

Creating an Event Candidate

When a Candidate Becomes an Event


Question No: 14

You are running a R80 Security Gateway on GAiA. In case of a hardware failure, you have a server with the exact same hardware and firewall version installed. What back up method could be used to quickly put the secondary firewall into production?

A. manual backup

B. upgrade_export

C. backup

D. snapshot

Answer: D


Question No: 15

An internal host initiates a session to the Google.com website and is set for Hide NAT behind the Security Gateway. The initiating traffic is an example of .

A. client side NAT

B. source NAT

C. destination NAT

D. None of these

Answer: B


P.S. Easily pass 156-915.80 Exam with Surepassexam Pinpoint Dumps & pdf vce, Try Free: https://www.surepassexam.com/156-915.80-exam-dumps.html ( New Questions)