156-215.81 Exam Questions
690 real 156-215.81 exam questions with expert-verified answers and explanations. Page 14 of 14.
- Question #653
What are the three main components of Check Point security management architecture?
- Question #654
The default shell of the Gaia CLI is cli.sh. How do you change from the cli.sh shell to the advanced shell to run Linux commands?
- Question #655
Check Point licenses come in two forms. What are those forms?
- Question #656
In SmartEvent, a correlation unit (CU) is used to do what?
- Question #657
What are the two elements of address translation rules?
- Question #658
Identity Awareness lets an administrator easily configure network access and auditing based on three items.
- Question #659
Which Check Point software Wade provides visibility of users, groups and machines while also providing access control through identity-based policies?
- Question #660
For Automatic Hide NAT rules created by the administrator what is a TRUE statement?
- Question #661
What is the user ID of a user that have all the privileges of a root user?
- Question #662
Which command shows the installed licenses in Expert mode?
- Question #663
What are two basic rules Check Point recommends for building an effective security policy?
- Question #664
When a gateway requires user information for authentication, what order does it query servers for user information?
- Question #665
SmartConsole provides a consolidated solution for everything that is necessary for the security of an organization, such as the following:
- Question #666
Which of the following is NOT a type of Endpoint Identity Agent?
- Question #667
An administrator wishes to use Application objects in a rule in their policy but there are no Application objects listed as options to add when clicking the"+" to add new items to...
- Question #668
Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?
- Question #669
Where can alerts be viewed?
- Question #670
A layer can support different combinations of blades, what are the supported blades?
- Question #671
What technologies are used to deny or permit network traffic?
- Question #672
If an administrator wants to restrict access to a network resource only allowing certain users to access it, and only when they are on a specific network, what is the best way to a...
- Question #673VPN
Which of the following statements about Site-to-Site VPN Domain-based is NOT true?
Site-to-Site VPNdomain-based VPNVPN domainsroute-based VPN - Question #674VPN
You had setup the VPN Community NPN-Stores' with 3 gateways. There are some issues with one remote gateway(1.1.1.1) and an your local gateway. What will be the best log filter to s...
IKE Phase 2Quick ModeVPN logslog filtering - Question #675VPN
Aggressive Mode in IKEv1 uses how many packages for negotiation?
IKEv1Aggressive ModeIKE negotiationpacket exchange - Question #676Security Policy Management
What are the software components used by Autonomous Threat Prevention Profiles in R8I.20 and higher?
Autonomous Threat Preventionsecurity bladesthreat prevention profilesR81.20 - Question #677Security Gateway Troubleshooting
Which command shows detailed information about VPN tunnels?
VPN tunnelsvpn tu commandCLI diagnosticstunnel listing - Question #678VPN
What are valid authentication methods for mutual authenticating the VPN gateways?
VPN authenticationpre-shared secretPKI certificatesIKE - Question #679Deployment
Which of the following is a valid deployment option?
deployment optionsstandalone deploymentarchitecture modes - Question #680Check Point Technology Overview
Check Point licenses come in two forms. What are those forms?
licensingcentral licenselocal licenseCheck Point licenses - Question #681VPN
Which encryption algorithm is the least secured?
encryption algorithmsDESAEScipher strength - Question #682VPN
What is required for a certificate-based VPN tunnel between two gateways with separate management systems?
certificate-based VPNPKImutual CA trustinter-gateway VPN - Question #683VPN
You want to set up a VPN tunnel to a external gateway. You had to make sure that the IKE P2 SA will only be established between two subnets and not all subnets defined in the defau...
VPN CommunityIKE Phase 2VPN domainsubnet restriction - Question #684Check Point Technology Overview
In the Check Point three-tiered architecture, which of the following is NOT a function of the Security Management Server?
three-tier architectureSecurity Management ServerSMS functionsadmin workstation - Question #685User Management and Authentication
Fill in the blank: The_____is used to obtain identification and security information about network users.
User DirectoryLDAPuser identificationidentity source - Question #686Security Policy Management
Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?
Threat Extractionfile sanitizationcontent disarmsecurity blades - Question #687Policy Management
Fill in the blank: A(n)_____rule is created by an administrator and configured to allow or block traffic based on specified criteria.
explicit rulesfirewall policyrule typesaccess control - Question #688User Management and Authentication
Which Check Point supported authentication scheme typically requires a user to possess a token?
SecurIDtoken authenticationauthentication schemestwo-factor - Question #689Check Point Technology Overview
Which of the following is true about Stateful Inspection?
Stateful Inspectionpacket inspectionconnection trackingINSPECT engine - Question #690Monitoring and Reporting
Which option in tracking allows you to see the amount of data passed in the connection?
Accountingtraffic trackingconnection datalogging options - Question #691Deployment and Configuration
Bob and Joe both have Administrator Roles on their Gaia Platform. Bob logs in on the WebUI and then Joe logs in through CLI. Choose what BEST describes the following scenario, wher...
Gaia platformadmin accessWebUI vs CLIconcurrent sessions - Question #692User Management and Authentication
Fill in the blank: An identity server uses a______________to trust a Terminal Server Identity Agent.
Terminal ServerIdentity Agentshared secretidentity awareness