156-215.75 Exam Questions
526 real 156-215.75 exam questions with expert-verified answers and explanations. Page 3 of 11.
- Question #101
You intend to upgrade a Check Point Gateway from R65 to R75. Prior to upgrading, you want to backup the Gateway should there be any problems with the upgrade. Which of the followin...
- Question #102System Administration
Your network is experiencing connectivity problems and you want to verify if routing problems are present. You need to disable the firewall process but still allow routing to pass...
IPSOipsofwdroutingfirewall process disable - Question #103
Where can you find the Check Point's SNMP MIB file?
- Question #104
You want to generate a cpinfo file via CLI on a system running SecurePlatform. This will take about 40 minutes since the log files are also needed. What action do you need to take...
- Question #105
Many companies have defined more than one administrator. To increase security, only one administrator should be able to install a Rule Base on a specific Firewall. How do you confi...
- Question #106
What is the officially accepted diagnostic tool for IP appliance support?
- Question #107
You are the Security Administrator for MegaCorp. A Check Point firewall is installed and in use on a SecurePlatform. You have trouble configuring the speed and duplex settings of y...
- Question #108
Which command enables IP forwarding on IPSO?
- Question #109
How many inspection capture points are shown in fw monitor?
- Question #110
Looking at an fw monitor capture in Wireshark, the initiating packet in Hide NAT translates on________.
- Question #111
You want to create an ASCII formatted output file of the fw monitor command. What is the correct Check Point 156-215.75 Exam syntax to accomplish this task?
- Question #112
When you run the fw monitor -e "accept;" command, what type of traffic is captured?
- Question #113
The Get Address button, found on the Host Node Object / General Properties page, will retrieve what?
- Question #114
You have just been hired as the Security Administrator for the Insure-It-All insurance company. Your manager gives you the following requirements for controlling DNS traffic: Requi...
- Question #115
When you change an implicit rule's order from last to first in global properties, how do you make the change take effect?
- Question #116
You create implicit and explicit rules for the following network. The group object internal-networks includes networks 10.10.10.0 and 10.10.20.0. Assume Accept ICMP requests is ena...
- Question #117
How does the Get Address button, found on the Host Node Object > General Properties page retrieve the address?
- Question #118
Anti-Spoofing is typically set up on which object type?
- Question #119
Spoofing is a method of:
- Question #120
Certificates for Security Gateways are created during a simple initialization from______.
- Question #121
Which of the below is most correct process to reset SIC from SmartDashboard?
- Question #122
You installed Security Management Server on a computer using SecurePlatform in the MegaCorp home office. You use IP address 10.1.1.1. You also installed the Security Gateway on a s...
- Question #123
Although SIC was already established and running, Joe reset SIC between the Security Management Server and a remote Gateway. He set a new activation key on the Gateway's side with...
- Question #124
You want to reset SIC between smberlin and sgosaka. In SmartDashboard, you choose sgosaka, Communication, Reset. On sgosaka, you start cpconfig, choose Secure Internal Communicatio...
- Question #125
Which rule should be the Cleanup Rule in the Rule Base?
- Question #126
What are the two basic rules which should be used by all Security Administrators? Check Point 156-215.75 Exam
- Question #127
Which item below in a Security Policy would be enforced first?
- Question #128
When you hide a rule in a Rule Base, how can you then disable the rule?
- Question #129
A Stealth rule is used to:
- Question #130Security Policy Management
A Clean-up rule is used to:
cleanup ruleimplicit droploggingrule base - Question #131
A ____________ rule is designed to log and drop all other communication that does not match another rule.
- Question #132
Which statement is TRUE about implicit rules?
- Question #133
You have included the Cleanup Rule in your Rule Base. Where in the Rule Base should the Accept ICMP Requests implied rule have no effect?
- Question #134
All of the following are Security Gateway control connections defined by default implied rules, EXCEPT:
- Question #135
In a distributed management environment, the administrator has removed all default check boxes from the Policy / Global Properties / Firewall tab. In order for the Security Gateway...
- Question #136
Examine the following Security Policy. What, if any, changes could be made to accommodate Rule 4?
- Question #137
A Security Policy has several database versions. What configuration remains the same no matter which version is used?
- Question #138
Check Point 156-215.75 Exam You are working with multiple Security Gateways that enforce an extensive number of rules. To simplify Security administration, which one of the followi...
- Question #139
You are working with multiple Security Gateways that enforce a common set of rules. To minimize the number of policy packages, which one of the following would you choose to do?
- Question #140
Which rules are not applied on a first-match basis?
- Question #141
Installing a policy usually has no impact on currently existing connections. Which statement is TRUE?
- Question #142
Several Security Policies can be used for different installation targets. The firewall protecting Human Resources' servers should have a unique Policy Package. These rules may only...
- Question #143
Which of these security policy changes optimize Security Gateway performance?
- Question #144
Your perimeter Security Gateway's external IP is 200.200.200.3. Your network diagram shows: Required: Allow only network 192.168.10.0 and 192.168.20.0 to go out to the Internet, us...
- Question #145
Because of a pre-existing design constraints, you set up manual NAT rules for your HTTP server. However, your FTP server and SMTP server are both using automatic NAT rules. All tra...
- Question #146
You enable Hide NAT on the network object, 10.1.1.0 behind the Security Gateway's external interface. You browse to from host, 10.1.1.10 successfully. You enable a log on the rule...
- Question #147
Which of the following statements BEST describes Check Point's Hide Network Address Translation method?
- Question #148
Which Check Point address translation method allows an administrator to use fewer ISP-assigned IP addresses than the number of internal hosts requiring Internet connectivity?
- Question #149
NAT can NOT be configured on which of the following objects?
- Question #150
NAT can be implemented on which of the following lists of objects?