156-315.81.20 Study Guide Brilliant 156-315.81.20 Exam Dumps PDF [Q256-Q280]

Share

156-315.81.20 Study Guide Brilliant 156-315.81.20 Exam Dumps PDF

View 156-315.81.20 Exam Question Dumps With Latest Demo

NEW QUESTION # 256
Fill in the blank: The R81 utility fw monitor is used to troubleshoot ______________________.

  • A. Phase two key negotiations
  • B. User data base corruption
  • C. LDAP conflicts
  • D. Traffic issues

Answer: D


NEW QUESTION # 257
What could NOT be a reason for synchronization issues in a Management HA environment?

  • A. Servers are in Collision Mode. Two servers, both in active state cannot be synchronized either automatically or manually.
  • B. Accidentally, you have configured unique IP addresses per Management Server which invalidates the CA Certificate
  • C. The products installed on the servers do not match: one device is a Standalone Server while the other is only a Security Management server
  • D. There is a network connectivity failure between the servers

Answer: C


NEW QUESTION # 258
What solution is multi-queue intended to provide?

  • A. Improve the efficiency of CoreXL Kernel Instances
  • B. Reduce the performance of network interfaces
  • C. Improve the efficiency of traffic handling by SecureXL SNDs
  • D. Reduce the confusion for traffic capturing in FW Monitor

Answer: A


NEW QUESTION # 259
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU.
After installation, is the administrator required to perform any additional tasks?

  • A. Run cprestart from dish
  • B. After upgrading the hardware, increase the number of kernel instances using cpconfig
  • C. Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores.
  • D. Hyperthreading must be enabled in the bios to use CoreXL

Answer: B


NEW QUESTION # 260
What order should be used when upgrading a Management High Availability Cluster?

  • A. Secondary Management, then Primary Management
  • B. Standby Management, then Active Management
  • C. Primary Management, then Secondary Management
  • D. Active Management, then Standby Management

Answer: B


NEW QUESTION # 261
You want to verify if your management server is ready to upgrade to R81.20.
What tool could you use in this process?

  • A. pre_upgrade_verifier
  • B. upgrade_tools verify
  • C. migrate export
  • D. migrate import

Answer: A


NEW QUESTION # 262
By default, which port does the WebUI listen on?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D


NEW QUESTION # 263
You want to allow your Mobile Access Users to connect to an internal file share. Adding the Mobile Application 'File Share' to your Access Control Policy in the SmartConsole didn't work. You will be only allowed to select Services for the 'Service & Application' column.
How to fix it?

  • A. The Mobile Access Policy Source under Gateway properties Is set to Legacy Policy and not to Unified Access Policy.
  • B. The Mobile Access Blade is not enabled under Gateway properties.
  • C. The Mobile Access Blade is not enabled for the Access Control Layer of the policy.
  • D. A Quantum Spark Appliance is selected as Installation Target for the policy packet.

Answer: A


NEW QUESTION # 264
What Is the difference between Updatable Objects and Dynamic Objects

  • A. Dynamic Objects are maintained automatically by the Threat Cloud. For Dynamic Objects there rs no need to install policy for the changes to take effect. Updatable Objects are created and maintained locally.
  • B. Dynamic Objects ate maintained automatically by the Threat Cloud. Updatable Objects are created and maintained locally. In both cases there is no need to install policy for the changes to take effect.
  • C. Updatable Objects is a Threat Cloud Service. The provided Objects are updated automatically. Dynamic Objects are created and maintained locally For Dynamic Objects there is no need to install policy for the changes to take effect.
  • D. Updatable Objects is a Threat Cloud Service. The provided Objects are updated automatically. Dynamic Objects are created and maintained locally In both cases there is no need to install policy for the changes to take effect.

Answer: C


NEW QUESTION # 265
On the following picture an administrator configures Identity Awareness:

After clicking "Next" the above configuration is supported by:

  • A. Obligatory usage of Captive Portal.
  • B. Based on Active Directory integration which allows the Security Gateway to correlate Active Directory users and machines to IP addresses in a method that is completely transparent to the user.
  • C. Kerberos SSO which will be working for Active Directory integration
  • D. The ports 443 or 80 what will be used by Browser-Based and configured Authentication.

Answer: B


NEW QUESTION # 266
Bob is asked by Alice to disable the SecureXL mechanism temporary tor further diagnostic by their
Check Point partner.
Which of the following Check Point Command is true:

  • A. fwaccel suspend
  • B. fwaccel templates
  • C. fwaccel standby
  • D. fwaccel off

Answer: D


NEW QUESTION # 267
When requiring certificates for mobile devices, make sure the authentication method is set to one of the following, Username and Password, RADIUS or ________.

  • A. Complexity
  • B. TacAcs
  • C. SecurID
  • D. SecureID

Answer: C


NEW QUESTION # 268
What destination versions are supported for a Multi-Version Cluster Upgrade?

  • A. R70 and Later
  • B. R76 and later
  • C. R81.20 and Later
  • D. R81.40 and later

Answer: C


NEW QUESTION # 269
Which of the following technologies extracts detailed information from packets and stores that information in state tables?

  • A. INSPECT Engine
  • B. Packet Filtering
  • C. Stateful Inspection
  • D. Application Layer Firewall

Answer: A


NEW QUESTION # 270
SecureXL improves non-encrypted firewall traffic throughput and encrypted VPN traffic throughput.

  • A. This statement is false because encrypted traffic cannot be inspected.
  • B. This statement is true because SecureXL does improve all traffic.
  • C. This statement is true because SecureXL does improve this traffic.
  • D. This statement is false because SecureXL does not improve this traffic but CoreXL does.

Answer: C


NEW QUESTION # 271
Can Check Point and Third-party Gateways establish a certificate-based Site-to-Site VPN tunnel?

  • A. Yes, but they need to have a mutually trusted certificate authority
  • B. No, they cannot share certificate authorities
  • C. No, Certificate based VPNs are only possible between Check Point devices
  • D. Yes, but they have to have a pre-shared secret key

Answer: A


NEW QUESTION # 272
What are the steps to configure the HTTPS Inspection Policy?

  • A. Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
  • B. Go to Manage&Settings > Blades > HTTPS Inspection > Policy
  • C. Go to Application&url filtering blade > Https Inspection > Policy
  • D. Go to Application&url filtering blade > Advanced > Https Inspection > Policy

Answer: A


NEW QUESTION # 273
Which SmartEvent component is responsible to collect the logs from different Log Servers?

  • A. SmartEvent Database
  • B. SmartEvent Collector
  • C. SmartEvent Server
  • D. SmartEvent Correlation Unit

Answer: D


NEW QUESTION # 274
During inspection of your Threat Prevention logs you find four different computers having one event each with a Critical Severity.
Which of those hosts should you try to remediate first?

  • A. Host having a Critical event found by IPS
  • B. Host having a Critical event found by Antivirus
  • C. Host having a Critical event found by Threat Emulation
  • D. Host having a Critical event found by Anti-Bot

Answer: D


NEW QUESTION # 275
How can you switch the active log file?

  • A. Run fw logswitch on the Management Server
  • B. Run fwm logswitch on the gateway
  • C. Run fw logswitch on the gateway
  • D. Run fwm logswitch on the Management Server

Answer: A


NEW QUESTION # 276
Which is NOT an example of a Check Point API?

  • A. Threat Prevention API
  • B. Management API
  • C. Gateway API
  • D. OPSEC SDK

Answer: C


NEW QUESTION # 277
Which Check Point daemon monitors the other daemons?

  • A. fwm
  • B. cpd
  • C. fwssd
  • D. cpwd

Answer: D


NEW QUESTION # 278
In the Firewall chain mode FFF refers to:

  • A. Stateless Packets
  • B. All Packets
  • C. No Match
  • D. Stateful Packets

Answer: B


NEW QUESTION # 279
Gaia has two default user accounts that cannot be deleted.
What are those user accounts?

  • A. Expert and Clish
  • B. Admin and Monitor
  • C. Control and Monitor
  • D. Admin and Default

Answer: B


NEW QUESTION # 280
......

Free 156-315.81.20 Test Questions Real Practice Test Questions: https://examsforall.lead2passexam.com/CheckPoint/valid-156-315.81.20-exam-dumps.html