156-115.77 Exam Questions
310 real 156-115.77 exam questions with expert-verified answers and explanations. Page 6 of 7.
- Question #251
Which of the following BEST describes the command fw ctl chain function?
- Question #252
The command _____________ shows which firewall chain modules are active on a gateway.
- Question #253
Compare these two images to establish which blade/feature was disabled on the firewall.
- Question #254
The command fw ctl kdebug <params> is used to:
- Question #255
What command would give you a summary of all the tables available to the firewall kernel?
- Question #256
What flag option(s) must be used to dump the complete table in friendly format, assuming there are more than one hundred connections in the table?
- Question #257
Which directory below contains the URL Filtering engine update info? Here you can also go to see the status of the URL Filtering and Application Control updates.
- Question #258
For URL Filtering in the Cloud in R75 and above, what table is used to contain the URL Filtering cache values?
- Question #259
You are troubleshooting a Security Gateway, attempting to determine which chain is causing a problem. What command would you use to show all the chains through which traffic passed...
- Question #260
In Check Point, Domain-based VPN's take precedence over route-based VPN. If implementing a route-based VPN, what is one configuration step you must make on the gateway object takin...
- Question #261
What utility would you use to configure route-based VPNs?
- Question #262
Where do you configure the file user.def to change the encryption domain of the Security Gateway?
- Question #263
Henry is attempting to verify VPN connectivity between two hosts, x and y. Of the following commands, which could be BEST used to verify connectivity of this VPN?
- Question #264
Which technology is not supported with route-based VPNs?
- Question #265
Which feature is not supported with unnumbered VTI?
- Question #266
In the gateway object, under topology you select the "Get All Members Interfaces with Topology" option and your newly configured unnumbered VTIs are not populated. Why is this info...
- Question #267
What operating systems support unnumbered VTIs?
- Question #268
You would like to configure unnumbered VTIs and your environment uses load sharing clustering. Would this clustering technology be supported by your unnumbered VTI's?
- Question #269
You are configuring dynamic routing on Secure Platform, as the administrator you run the command pro enable and reboot. You are confident that your configuration has been done corr...
- Question #270
What is the prefix name for the interface when creating an unnumbered VTI in GAIA?
- Question #271
Your customer receives an alert from their network operation center, they are seeing ARP and Ping scans of their network originating from the firewall. What could be the reason for...
- Question #272
Your cluster member is showing a state of "Ready". Which of the following is NOT a reason one would expect for this behaviour?
- Question #273
Which of the following is NOT a cphaprob status?
- Question #274
What would be a reason for changing the "Magic MAC"?
- Question #275
What are the kernel parameters that control "Magic MACs"?
- Question #276
How many sync interfaces are supported on Check Point R77 GAiA?
- Question #277
Which is NOT a valid upgrade method in an R77 GAiA ClusterXL deployment?
- Question #278
What would be a reason to use the command cphaosu stat?
- Question #279
You run the commands: fw ctl debug 0 fw ctl debug -buf 32000 Which of the following commands would be best to troubleshoot a clustering issue?
- Question #280
You run the command fw tab -t connections -s on both members in the cluster. Both members report differing values for "vals" and "peaks". Which may NOT be a reason for this differe...
- Question #281
Your customer reports that the time on the standby cluster member is not correct. After failing over and making it active, the time is now correct. NTP has been configured on both...
- Question #282
Your customer has an R77 Multi-domain Management Server managing a mix of firewalls of R70 and R77 versions. A change was made to the file $FWDIR/lib/tables.def on one of the domai...
- Question #283
What is the function of the setting "no_hide_services_ports" in the tables.def files?
- Question #284
Which command will you run to list established VPN tunnels?
- Question #285
You are in VPN troubleshooting with a Partner and you suspect a mismatch configuration in Diffie- Hellman (DH) group to Phase1. After starting a vpn debug, in which packet would yo...
- Question #286
True or False: Software blades perform their inspection primarily through the kernel chain modules.
- Question #287
When using the command fw monitor, what command ensures the capture is accurate?
- Question #288
You are running a debugging session and you have set the debug environment to TDERROR_ALL_ALL=5 using the command export TDERROR_ALL_ALL=5. How do you return the debug value to def...
- Question #289
What command would you use to view which debugs are set in your current working environment?
- Question #290
What causes the SIP Early NAT chain module to appear in the chain?
- Question #291
When you perform an install database, the status window is filled with large amounts of text. What could be the cause?
- Question #292
When finished running a debug on the Management Server using the command fw debug fwm on how do you turn this debug off?
- Question #293
Which commands will properly set the debug level to maximum and then run a policy install in debug mode for the policy Standard on gateway A-GW from an R77 GAiA Management Server?
- Question #294
Which of the following items is NOT part of the columns of the chain modules?
- Question #295
John is a Security Administrator of a Check Point platform. He has a mis-configuration issue that points to the Rule Base. To obtain information about the issue, John runs the comm...
- Question #296
You are trying to troubleshoot a NAT issue on your network, and you use a kernel debug to verify a connection is correctly translated to its NAT address. What flags should you use...
- Question #297
Since switching your network to ISP redundancy you find that your outgoing static NAT connections are failing. You use the command _________ to debug the issue.
- Question #298
Remote VPN clients can initiate connections with internal hosts, but internal hosts are unable to initiate connections with the remote VPN clients, even though the policy is config...
- Question #299
Where in a fw monitor output would you see source address translation occur in cases of automatic Hide NAT?
- Question #300
You run cpconfig to reset SIC on the Security Gateway. After the SIC reset operation is complete, the policy that will be installed is the: