156-215.81 Exam Questions
690 real 156-215.81 exam questions with expert-verified answers and explanations. Page 6 of 14.
- Question #251
Which R77 GUI would you use to see number of packets accepted since the last policy install?
- Question #252
Which of the following firewall modes DOES NOT allow for Identity Awareness to be deployed?
- Question #253
What is the Manual Client Authentication TELNET port?
- Question #254
Jennifer McHanry is CEO of ACME. She recently bought her own personal iPad. She wants use her iPad to access the internal Finance Web server. Because the iPad is not a member of th...
- Question #255
How many packets does the IKE exchange use for Phase 1 Main Mode?
- Question #256
What is also referred to as Dynamic NAT?
- Question #257
A client has created a new Gateway object that will be managed at a remote location. When the client attempts to install the Security Policy to the new Gateway object, the object d...
- Question #258
Which of the following is NOT a valid option when configuring access for Captive Portal?
- Question #259
As you review this Security Policy, what changes could you make to accommodate Rule 4?
- Question #260
What happens when you run the command: fw sam -J src [Source IP Address]?
- Question #261
VPN gateways must authenticate to each other prior to exchanging information. What are the two types of credentials used for authentication?
- Question #262
According to Check Point Best Practice, when adding a non-managed Check Point Gateway to a Check Point security solution what object SHOULD be added? A(n):
- Question #263
You are about to integrate RSA SecurID users into the Check Point infrastructure. What kind of users are to be defined via SmartDashboard?
- Question #264
Where does the security administrator activate Identity Awareness within SmartDashboard?
- Question #265
While in SmartView Tracker, Brady has noticed some very odd network traffic that he thinks could be an intrusion. He decides to block the traffic for 60 minutes, but cannot remembe...
- Question #266
You are about to test some rule and object changes suggested in an R77 news group. Which backup solution should you use to ensure the easiest restoration of your Security Policy to...
- Question #267
You are using SmartView Tracker to troubleshoot NAT entries. Which column do you check to view the NAT'd source port if you are using Source NAT?
- Question #268
What happens if the identity of a user is known?
- Question #269
Your company enforces a strict change control policy. Which of the following would be MOST effective for quickly dropping an attacker's specific active connection?
- Question #270
What port is used for communication to the User Center with SmartUpdate?
- Question #271
How do you configure an alert in SmartView Monitor?
- Question #272
Where would an administrator enable Implied Rules logging?
- Question #273
Which of these attributes would be critical for a site-to-site VPN?
- Question #274
You have just installed your Gateway and want to analyze the packet size distribution of your traffic with SmartView Monitor. Unfortunately, you get the message: "There are no mach...
- Question #275
You believe Phase 2 negotiations are failing while you are attempting to configure a site-to-site VPN with one of your firm's business partners. Which SmartConsole application shou...
- Question #276
Which of the following uses the same key to decrypt as it does to encrypt?
- Question #277
How do you configure the Security Policy to provide uses access to the Captive Portal through an external (Internet) interface?
- Question #278
The technical-support department has a requirement to access an intranet server. When configuring a User Authentication rule to achieve this, which of the following should you reme...
- Question #279
As a Security Administrator, you must refresh the Client Authentication authorized time-out every time a new user connection is authorized. How do you do this? Enable the Refreshab...
- Question #280
When using GAiA, it might be necessary to temporarily change the MAC address of the interface eth 0 to 00:0C:29:12:34:56. After restarting the network the old MAC address should be...
- Question #281
John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to designated IP addresses to minimize malware infection and unauthorized access r...
- Question #282
Review the rules. Assume domain UDP is enabled in the implied rules. What happens when a user from the internal network tries to browse to the internet using HTTP? The user:
- Question #283
Which component functions as the Internal Certificate Authority for R77?
- Question #284
Check Point APIs allow system engineers and developers to make changes to their organization's security policy with CLI tools and Web Services for all of the following except:
- Question #285
In what way are SSL VPN and IPSec VPN different?
- Question #286
Which command can you use to enable or disable multi-queue per interface?
- Question #287
Which limitation of CoreXL is overcome by using (mitigated by) Multi-Queue?
- Question #288
To fully enable Dynamic Dispatcher on a Security Gateway:
- Question #289
What are types of Check Point APIs available currently as part of R80.10 code?
- Question #290
What is the purpose of Priority Delta in VRRP?
- Question #291
The Firewall kernel is replicated multiple times, therefore:
- Question #292
There are 4 ways to use the Management API for creating host object with R80 Management API. Which one is NOT correct?
- Question #293
Which the following type of authentication on Mobile Access can NOT be used as the first authentication method?
- Question #294
Which command can you use to verify the number of active concurrent connections?
- Question #295
Which remote Access Solution is clientless?
- Question #296
What component of R80 Management is used for indexing?
- Question #297
Which NAT rules are prioritized first?
- Question #298
What is the difference between an event and a log?
- Question #299
The system administrator of a company is trying to find out why acceleration is not working for the traffic. The traffic is allowed according to the rule base and checked for virus...
- Question #300
During the Check Point Stateful Inspection Process, for packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are: