156-215.71 Exam Questions
574 real 156-215.71 exam questions with expert-verified answers and explanations. Page 7 of 12.
- Question #303
In a distributed management environment, the administrator has removed all default check boxes from the Policy > Global Properties > Firewall tab. In order for the Security Gateway...
- Question #304
You need to plan the company's new security system. The company needs a very high level of security and also high performance and high throughput for their applications. You need t...
- Question #305
Once installed, the R71 kernel resides directly below which layer of the OSI model? Note: Application is the top and Physical is the bottom of the IP stack.
- Question #306
How can you reset the password of the Security Administrator that was created during initial installation of the Security Management Server on SecurePlatform?
- Question #307
The Administrator of the London Security Gateway has just installed the Security Gateway and Management Server. He has not changed any default settings. As he tries to configure th...
- Question #308
When restoring R71 using the upgrade_ import command, which of the following items is NOT restored?
- Question #309
Which operating systems are supported by a Check Point Security Gateway on an open server?
- Question #310
Your network is experiencing connectivity problems and you want to verify if routing problems are present. You need to disable the firewall process but still allow routing to pass...
- Question #311
ALL of the following options are provided by the SecurePlatform sysconfig utility, EXCEPT:
- Question #312
Your company is running Security Management Server R71 on SecurePlatform, which has been migrated through each version starting from Check Point 4.1. How do you add a new administr...
- Question #313
The command fw fetch causes the:
- Question #314
Which of the following provides confidentiality services for data and messages in a Check Point VPN?
- Question #315
Of the following VPN Community options, which is most likely to provide a balance between IKE compatibility to VPN-capable devices (Check Point and non-Check Point) and preserving...
- Question #316
You wish to configure an IKE VPN between two R71 Security Gateways, to protect two networks. The network behind one Gateway is 10.15.0.0/16, and network 192.168.9.0/24 is behind th...
- Question #317
Your manager requires you to setup a VPN to a new business partner site. The administrator from the partner site gives you his VPN settings and you notice that he setup AES 128 for...
- Question #318
For VPN routing to succeed, what must be configured?
- Question #319
If Henry wanted to configure Perfect Forward Secrecy for his VPN tunnel, in which phase would he be configuring this?
- Question #320
You enable Automatic Static NAT on an internal host node object with a private IP address of 10.10.10.5, which is NATed into 216.216.216.5. (You use the default settings in Global...
- Question #321
Which command allows verification of the Security Policy name and install date on a Security Gateway?
- Question #322
Which answers are TRUE? Automatic Static NAT CANNOT be used when: (i) NAT decision is based on the destination port. (ii) Source and Destination IP both have to be translated. (iii...
- Question #323
When translation occurs using automatic Hide NAT, what also happens?
- Question #324
Which of the following statements BEST describes Check Point's Hide Network Address Translation method?
- Question #325
Which R71 feature or command allows Security Administrators to revert to earlier versions of the Security Policy without changing object configurations?
- Question #326
A Hide NAT rule has been created which includes a source address group often (10) networks and three (3) other group objects (containing 4, 5, and 6 host objects respectively). Ass...
- Question #327
A client has created a new Gateway object that will be managed at a remote location. When the client attempts to install the Security Policy to the new Gateway object, the object d...
- Question #328
You have configured a remote site Gateway that supports your boss's access from his home office using a DSL dialup connection. Everything worked fine yesterday, but today all conne...
- Question #329
A host on the Internet initiates traffic to the Static NAT IP of your Web server behind the Security Gateway. With the default settings in place for NAT, the initiating packet will...
- Question #330
When you use the Global Properties' default settings on R71, which type of traffic will be dropped if no explicit rule allows the traffic?
- Question #331
A Stealth rule is used to:
- Question #332
SmartView Tracker logs the following Security Administrator activities, EXCEPT:
- Question #333
You are working with three other Security Administrators. Which SmartConsole component can be used to monitor changes to rules or object properties made by the other administrators...
- Question #334
Which SmartView Tracker mode allows you to read the SMTP e-mail body sent from the Chief Executive Officer (CEO) of a company?
- Question #335
One of your remote Security Gateway's suddenly stops sending logs, and you cannot install the Security Policy on the Gateway. All other remote Security Gateways are logging normall...
- Question #336
Where can an administrator specify the notification action to be taken by the firewall in the event that available disk space drops below 15%?
- Question #337
Which R71 component displays the number of packets accepted, rejected, and dropped on a specific Security Gateway, in real time?
- Question #338
For which protocol is anti-virus not available?
- Question #339
For remote user authentication, which authentication scheme is NOT supported?
- Question #340
What happens to evaluation licenses during the license-upgrade process?
- Question #341
Which of the following statements about service contracts, i.e., Certificate, software subscription, or support contract, is FALSE? Check Point 156-215.71 Exam
- Question #342
All R71 Security Servers can perform authentication with the exception of one. Which of the Security Servers cannot perform authentication?
- Question #343
What is the difference between Standard and Specific Sign On methods?
- Question #344
Which column in the Rule Base is used to define authentication parameters?
- Question #345
Check Point 156-215.71 Exam Identify the ports to which the Client Authentication daemon listens by default.
- Question #346
If a Security Gateway enforces three protections, LDAP Injection, Malicious Code Protector, and Header Rejection, which Check Point license is required in SmartUpdate?
- Question #347
R71's INSPECT Engine inserts itself into the kernel between which two layers of the OSI model?
- Question #348
Your R71 primary Security Management Server is installed on SecurePlatform. You plan to schedule the Security Management Server to run fw logswitch automatically every 48 hours. Ho...
- Question #349
Which command is used to uninstall the Security Policy directly from the Security Gateway? Check Point 156-215.71 Exam
- Question #350
Which of these attributes would be critical for a site-to-site VPN?
- Question #351
What statement is true regarding Visitor Mode?
- Question #352
How does the Get Address button, found on the Host Node Object > General Properties page retrieve the address?