156-115.77 Exam Questions
310 real 156-115.77 exam questions with expert-verified answers and explanations. Page 1 of 7.
- Question #1
The user tried to connect in SmartDashboard and did not work. You started a FWM debug and receive the logs below: What is the error cause?
- Question #2
When troubleshooting and trying to understand which chain is causing a problem on the Security Gateway, you should use the command:
- Question #3
Which process should you debug when SmartDashboard authentication is rejected?
- Question #4
A fwm debug provides the following output. What prevents the customer from logging into SmartDashboard?
- Question #5
When performing a fwm debug, to which directory are the logs written?
- Question #6
You are attempting to establish an FTP session between your computer and a remote server, but it is not being completed successfully. You think the issue may be due to IPS. Viewing...
- Question #7
The fw tab -t ___________ command displays the NAT table.
- Question #8
While troubleshooting a DHCP relay issue, you run a fw ctl zdebug drop and see the following output: ;[cpu_1];[fw_0];fw_log_drop: Packet proto=17 10.216.14.108:67 > 172.31.2.1:67 d...
- Question #9
You need to completely reboot the Operating System after making which of the following changes on the Security Gateway? (i.e. the command cprestart is not sufficient.) 1. Adding a...
- Question #10
The Security Gateway is installed on SecurePlatform R77. The default port for the Web User Interface is ____________.
- Question #11
You have configured SNX on the Security Gateway. The client connects to the Security Gateway and the user enters the authentication credentials. What must happen after authenticati...
- Question #12
Your primary Security Gateway runs on SecurePlatform. What is the easiest way to back up your Security Gateway R77 configuration, including routing and network configuration files?
- Question #13
Where in a fw monitor output would you see destination address translation occur in cases of inbound automatic static NAT?
- Question #14
Which flag in the fw monitor command is used to print the position of the kernel chain?
- Question #15
Server A is subject to automatically static NAT and also resides on a network which is subject to automatic Hide NAT. With regards to address translation what will happen when Serv...
- Question #16
In your SecurePlatform configuration you need to set up a manual static NAT entry. After creating the proper NAT rule what step needs to be completed?
- Question #17
How do you set up Port Address Translation?
- Question #18
You have set up a manual NAT rule, however fw monitor shows you that the device still uses the automatic Hide NAT rule. How should you correct this?
- Question #19
Since R76 GAiA, what is the method for configuring proxy ARP entries for manual NAT rules?
- Question #20
Tom has a Web server for which he has created a manual NAT rule. The rule is not working. He tries to initiate a connection from the external network to a DMZ server using the publ...
- Question #21
Tom is troubleshooting NAT issues using fw monitor and Wireshark. He tries to initiate a connection from the external network to a DMZ server using the public IP which the firewall...
- Question #22
Which FW-1 kernel flags should be used to properly debug and troubleshoot NAT issues?
- Question #23
Which file should be edited to modify ClusterXL VIP Hide NAT rules, and where?
- Question #24
When viewing a NAT Table, What represents the second hexadecimal number of the 6-tuple:
- Question #25
By default, the size of the fwx_alloc table is:
- Question #26
Given the screen configuration shown, the failure's probable cause is:
- Question #27
Ann wants to hide FTP traffic behind the virtual IP of her cluster. Where is the relevant file table.def located to make this modification?
- Question #28
While troubleshooting a connectivity issue with an internal web server, you know that packets are getting to the upstream router, but when you run a tcpdump on the external interfa...
- Question #29
In a production environment, your gateway is configured to apply a Hide NAT for all internal traffic destined to the Internet. However, you are setting up a VPN tunnel with a remot...
- Question #30
The "Hide internal networks behind the Gateway's external IP" option is selected. What defines what traffic will be NATted?
- Question #31
With the default ClusterXL settings what will be the state of an active gateway upon using the command ClusterXL_admin up?
- Question #32
Which command should you use to stop kernel module debugging (excluding SecureXL)?
- Question #33
Which command should you run to debug the VPN-1 kernel module?
- Question #34
Which command can be used to see all active modules on the Security Gateway:
- Question #35
In some situations, switches may not play nicely with a Check Point Cluster and it is necessary to change from multicast to broadcast. What command should you invoke to correct the...
- Question #36
Which of the following commands shows the high watermark threshold for triggering the cluster under load mechanism in R77?
- Question #37
What mechanism solves asymmetric routing issues in a load sharing cluster?
- Question #38
When you have edited the local.arp configuration, to support a manual NAT, what must be done to ensure proxy arps for both manual and automatic NAT rules function?
- Question #39
Which command clears all the connection table entries on a Security Gateway?
- Question #40
How can you see a dropped connection and the cause from the kernel?
- Question #41
After creating and pushing out a new policy, Joe finds that an old connection is still being allowed that should have been closed after his changes. He wants to delete the connecti...
- Question #42
Using the default values in R77 how many kernel instances will there be on a 16-core gateway?
- Question #43
When viewing connections using the command fw tab -t connections, all entries are displayed with a 6-tuple key, the elements of the 6-tuple include the following EXCEPT:
- Question #44
Each connection allowed by a Security Gateway, will have a real entry and some symbolic link entries in the connections state table. The symbolic link entries point back to the rea...
- Question #45
Extended Cluster Anti-Spoofing checks what value to determine if a packet with the source IP of a gateway in the cluster is being spoofed?
- Question #46
How do you clear the connections table?
- Question #47
In order to prevent outgoing NTP traffic from being hidden behind a Cluster IP you should?
- Question #48
Of the following answer choices, which best describes a possible effect of expanding the connections table?
- Question #49
Adam wants to find idle connections on his gateway. Which command would be best suited for viewing the connections table?
- Question #50
From the output of the following cphaprob -i list, what is the most likely cause of the clustering issue? Cluster B> cphaprob -i list Built-in Devices: Device Name: Interface Activ...