156-115.80 Exam Questions
189 real 156-115.80 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1Network Management and Monitoring
Tom has been tasked to install Check Point R80 in a distributed deployment. Before Tom installs the systems this way, how many machines will he need if he does NOT include a SmartC...
Check Point R80distributed deploymentSmartConsoleinstallation requirements - Question #2Network Security Fundamentals
In order to test ClusterXL failovers which command would you use on one of the ClusterXL nodes to initiate a failover?
ClusterXLfailoverhigh availabilitycluster admin command - Question #3Network Management and Monitoring
Which of the following is NOT a valid "fwaccel" parameter?
fwaccelSecureXLCLI parametersCheck Point commands - Question #4Network Management and Monitoring
Which of the following is not one of the relational database domains that stores the management configuration?
management database domainsCheck Pointglobal domainsystem domain - Question #5Network Management and Monitoring
What file extension should be used with fw monitor to allow the output file to be imported and read in Wireshark?
fw monitorpacket captureWiresharkfile extension - Question #6Network Management and Monitoring
Where will the usermode core files located?
core dump filesfile pathusermode debuggingCheck Point filesystem - Question #7Network Management and Monitoring
How often will a gateway with Performance Pack running by default automatically review and distribute interface affinity between cores?
Performance Packinterface affinityCoreXLautomatic review interval - Question #9Network Management and Monitoring
You verified that Performance Pack is disabled and need to distribute the affinity interfaces. What command would you run to use static affinity to balance the interfaces between t...
static affinitySND coresPerformance Packfw ctl affinity - Question #10Network Management and Monitoring
Which command would you use to check CoreXL instances for IPv6 traffic?
CoreXLIPv6 trafficmultik statfw ctl - Question #11Troubleshooting and Optimization
What must be done for the "fw monitor" command to capture packets through the firewall kernel?
fw monitorSecureXLpacket capturekernel module - Question #13Troubleshooting and Optimization
What is the default and maximum number of entries in the ARP Cache Table in a Check Point appliance?
ARP cacheappliance defaultstable limits - Question #14Troubleshooting and Optimization
Which kernel debug flag should you use to troubleshoot NAT connections?
kernel debugNAT troubleshootingfw ctl debugconnection tracking - Question #15Core R80 Architecture and Management
You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?
policy packagessecurity gateway managementSmartConsolerule administration - Question #16Troubleshooting and Optimization
Which type of SecureXL templates is enabled by default on Security Gateways?
SecureXL templatesaccelerationdefault settings - Question #17Troubleshooting and Optimization
Which one of following commands should you run to display HTTPS packet content together with kernel debug?
HTTPS inspectionkernel debugdecrypted datafw ctl set - Question #18Core R80 Architecture and Management
You issued the command "set ipv6-state on" in order to enable IPv6 protocol on a Security Gateway. The command was executed successfully. After reboot you notice that IPv6 protocol...
IPv6 configurationpersistent settingsGaia OSSecurity Gateway - Question #19Core R80 Architecture and Management
Where does the translation occur with Hide NAT?
Hide NATsource translationNAT mechanicsserver-side translation - Question #21Troubleshooting and Optimization
Which is the correct "fw monitor" syntax for creating a capture file for loading it into WireShark?
fw monitorWireSharkpacket capturecapture file syntax - Question #22Advanced Threat Prevention (SandBlast)
How many layers are incorporated in IPS detection and what are they called?
IPS detection layersPSLProtocol ParsersContext Management - Question #23Troubleshooting and Optimization
What is the command to check the current status of hyper-threading?
hyper-threadingsmt_statusCoreXLsystem status - Question #24Advanced Threat Prevention (SandBlast)
What occurs when Bypass Under Load activated?
Bypass Under LoadIPS bypassthreat preventionperformance mode - Question #25Troubleshooting and Optimization
Having a look at the output of the "fwaccel conns" command, the F flag is the indicator for a packet ______________.
fwaccelSecureXLconnection flagsfirewall kernel - Question #26Advanced VPN Solutions
Of how many packets consists Main Mode in Phase 1?
IKE Main ModePhase 1VPN negotiationpacket exchange - Question #27Advanced VPN Solutions
What does the command "vpn shell tunnels delete all ike" do?
vpn shellIKE SASA managementVPN commands - Question #28Core R80 Architecture and Management
When enabling hyper-threading on a Security Gateway, the administrator needs to make sure there is enough _______________ to support additional CoreXL Firewall instances.
hyper-threadingCoreXLmemory requirementsfirewall instances - Question #29Troubleshooting and Optimization
You run "cat/proc/smt_status" on your security gateway and the output shows `Soft Disable'. How is your system configured in reference to hyper-threading?
hyper-threadingsmt_statusBIOScpconfig - Question #30Core R80 Architecture and Management
Which command is used to enable IPv6 on Security Gateway?
IPv6Security GatewayGaia OSnetwork configuration - Question #31Advanced VPN Solutions
What is the correct command to turn off an IKE debug?
IKE debugvpn debugVPN troubleshooting - Question #32Troubleshooting and Optimization
What process(es) should be checked if there is high I/O and you suspect it may be related to the Antivirus Software Blade?
Antivirus bladeprocess monitoringI/O performancedlpu rad - Question #33Troubleshooting and Optimization
Which of the following is NOT a special consideration while running fw monitor on production firewall?
fw monitorSecureXL accelerationpacket captureproduction firewall - Question #34Core R80 Architecture and Management
In R80 spoofing is defined as a method of:
IP spoofinganti-spoofingpacket filteringunauthorized IP - Question #35Troubleshooting and Optimization
Which of the following inputs is suitable for debugging HTTPS inspection issues?
HTTPS inspectionTLS debugfw ctl debugcptls - Question #36Core R80 Architecture and Management
Which of the connections cannot be accelerated with SecureXL?
SecureXLNAT accelerationconnection templatesperformance - Question #37Core R80 Architecture and Management
Which of the following ports are used for SIC?
SICsecure internal communicationport numbersmanagement connectivity - Question #38Troubleshooting and Optimization
Joey's implementing a new R80.10 firewall cluster into the network. During the implementation he notices that the cluster object is in error state in SmartConsole. He tries to figu...
ClusterXLHA state machinecluster debugversion compatibility - Question #40Troubleshooting and Optimization
What is the name of the table that an administrator would review to investigate a port exhaustion error when using Hide NAT?
Hide NATport exhaustionfwx_allocNAT table - Question #41Troubleshooting and Optimization
After determining that the IPS Blade is causing high resource utilization in the gateway, which would be an appropriate strategy to improve IPS performance?
IPS performanceCoreXLresource utilizationblade optimization - Question #42Core R80 Architecture and Management
Which process is responsible for the generation of certificates?
cpca processcertificate generationPKIinternal CA - Question #43Core R80 Architecture and Management
Which one of the following does not belong to an initial status of a critical device?
critical devicesClusterXL statuspnoteHA initialization - Question #44Core R80 Architecture and Management
Fill in the blank: The R80 feature _________________ permits blocking specific IP addresses for a specified time period.
Suspicious Activity MonitoringSAMIP blockingdynamic blocking - Question #45Core R80 Architecture and Management
The Security Gateway is installed on GAiA R80. The default port for the Web User Interface is _____________.
Gaia web portalmanagement portsport 443Web UI - Question #46Advanced VPN Solutions
What is enabled by the command "vpn debug mon"?
vpn debug monIKE monitorVPN debuggingvpnd - Question #47Troubleshooting and Optimization
Fill in the blank: The R80 utility fw monitor is used to troubleshoot ___________________.
fw monitortraffic troubleshootingpacket inspectiondebug utility - Question #48Troubleshooting and Optimization
Which daemon would you debug if you have issues acquiring identities via identity sharing and identities with other gateways?
pdpd daemonidentity sharingIdentity Awarenessidentity debug - Question #49Troubleshooting and Optimization
What is the difference between disabling SecureXL by running "fwaccel off" and disabling it via cpconfig?
SecureXLfwaccelcpconfigreboot persistence - Question #51Troubleshooting and Optimization
Which IPS command debug tool can you use for troubleshooting IPS traffic?
IPS debugips debug commandtraffic inspectionIPS troubleshooting - Question #52Troubleshooting and Optimization
Which of the following would NOT be a flag when debugging a unified policy?
unified policy debugdebug flagspolicy compilationfw ctl debug - Question #53Core R80 Architecture and Management
What is the shorthand reference for a classification object?
classification objectsSmartConsole terminologyR80 object model - Question #55Advanced Threat Prevention (SandBlast)
Where do Protocol parsers register themselves for IPS?
IPS architectureprotocol parsersPassive Streaming Librarythreat prevention - Question #56Troubleshooting and Optimization
Which command is used to write a kernel debug to a file?
kernel debugfw ctl kdebugdebug outputtroubleshooting commands