nerdexam
Check_Point

156-215.80 · Question #231

MegaCorp's security infrastructure separates Security Gateways geographically. You must request a central license for one remote Security Gateway. How do you apply the license?

The correct answer is B. Using your Security Management Server's IP address, and attaching the license to the remote. This question tests understanding of how Check Point central (repository) licenses are obtained and applied to remote Security Gateways managed by a central Security Management Server.

Deployment and Configuration

Question

MegaCorp's security infrastructure separates Security Gateways geographically. You must request a central license for one remote Security Gateway. How do you apply the license?

Options

  • AUsing the remote Gateway's IP address, and attaching the license to the remote Gateway via
  • BUsing your Security Management Server's IP address, and attaching the license to the remote
  • CUsing the remote Gateway's IP address, and applying the license locally with command cplic put.
  • DUsing each of the Gateway's IP addresses, and applying the licenses on the Security

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    71% (22)
  • C
    3% (1)
  • D
    16% (5)

Why each option

This question tests understanding of how Check Point central (repository) licenses are obtained and applied to remote Security Gateways managed by a central Security Management Server.

AUsing the remote Gateway's IP address, and attaching the license to the remote Gateway via

Using the remote gateway's IP address with attachment via SmartUpdate describes the workflow for a local license, not a central license, which must reference the SMS IP.

BUsing your Security Management Server's IP address, and attaching the license to the remoteCorrect

In Check Point's centralized licensing model, a central license is anchored to the IP address of the Security Management Server (SMS), not the remote gateway. The license is purchased and generated using the SMS IP, stored in the central license repository, and then attached to the target remote gateway via SmartUpdate or SmartConsole - allowing the gateway to receive its entitlement without requiring a local license file applied directly on that machine.

CUsing the remote Gateway's IP address, and applying the license locally with command cplic put.

Applying a license locally on the remote gateway using 'cplic put' is the procedure for a local license; central licenses are managed and pushed from the SMS, not applied directly on the gateway.

DUsing each of the Gateway's IP addresses, and applying the licenses on the Security

Central licensing does not require each individual gateway's IP address as the license anchor - a single central license is tied to the SMS IP and distributed from there to multiple gateways.

Concept tested: Check Point centralized licensing for remote Security Gateways

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Licensing-Overview.htm

Topics

#central licensing#SmartUpdate#remote gateway#license management

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice