156-315.71 Exam Questions
484 real 156-315.71 exam questions with expert-verified answers and explanations. Page 3 of 10.
- Question #101
Which Security Servers can perform Content Security tasks, but CANNOT perform authentication tasks?
- Question #102
The following diagram illustrates how a VPN-1 SecureClient user tries to establish a VPN with hosts in the external_net and internal_net from the Internet. How is the Security Gate...
- Question #103
You want VPN traffic to match packets from internal interfaces. You also want the traffic to exit the Security Gateway, bound for all sitE. to-site VPN Communities, including Remot...
- Question #104
A cluster contains two members, with external interfaces 172.28.108.1 and 172.28.108.2. The internal interfaces are 10.4.8.1 and 10.4.8.2. The external cluster's IP address is 172....
- Question #105
How can you completely tear down a specific VPN tunnel in an intranet IKE VPN deployment?
- Question #106
How can you prevent delay-sensitive applications, such as video and voice traffic, from being dropped due to long queue using Check Point QoS solution?
- Question #107
You are preparing to deploy a VPN-1 Pro Gateway for VPN-1 NGX. You have five systems to choose from for the new Gateway, and you must conform to the following requirements: Operati...
- Question #108
In a Management High Availability (HA) configuration, you can configure synchronization to occur automatically, when: 1. The Security Policy is installed. 2. The Security Policy is...
- Question #109
Stephanie wants to reduce the encryption overhead and improve performance for her mesh VPN Community. The Advanced VPN Properties screen below displays adjusted page settings:What...
- Question #110
Check Point 156-315.71 Exam Steve tries to configure Directional VPN Rule Match in the Rule Base. But the Match column does not have the option to see the Directional Match. Steve...
- Question #111
Jerry is concerned that a denial-oF. service (DoS) attack may affect his VPN Communities. He decides to implement IKE DoS protection. Jerry needs to minimize the performance impact...
- Question #112
Where can a Security Administrator adjust the unit of measurement (bps, Kbps or Bps), for Check Point QoS bandwidth?
- Question #113
You are configuring the VoIP Domain object for an H.323 environment, protected by VPN-1 NGX. Which VoIP Domain object type can you use?
- Question #114
Problems sometimes occur when distributing IPSec packets to a few machines in a Load Sharing Multicast mode cluster, even though the machines have the same source and destination I...
- Question #115
Rachel is the Security Administrator for a university. The university's FTP servers have old hardware and software. Certain FTP commands cause the FTP servers to malfunction. Upgra...
- Question #116
Jacob is using a mesh VPN Community to create a sitE. to-site VPN. The VPN properties in this mesh Community display in this graphic:Which of the following statements is TRUE?
- Question #117
You want to establish a VPN, using Certificates. Your VPN will exchange Certificates with an external partner. Which of the following activities should you do first?
- Question #118
You are reviewing SmartView Tracker entries, and see a Connection Rejection on a Check Point QoS rule. What causes the Connection Rejection?
- Question #119
Wayne configures an HTTP Security Server to work with the content vectoring protocol to screen forbidden sites. He has created a URI resource object using CVP with the following se...
- Question #120
You have two Nokia Appliances: one IP530 and one IP380. Both Appliances have IPSO 3.9 and VPN-1 Pro NGX installed in a distributed deployment. Can they be members of a gateway clus...
- Question #121
You want to block corporatE. internal-net and localnet from accessing Web sites containing inappropriate content. You are using WebTrends for URL filtering. You have disabled VPN-1...
- Question #122
VPN-1 NGX includes a resource mechanism for working with the Common Internet File System (CIFS). However, this service only provides a limited level of actions for CIFS security. W...
- Question #123
Your organization has many VPN-1 Edge gateways at various branch offices, to allow VPN-1 Secure Client users to access company resources. For security reasons, your organization's...
- Question #124
Robert has configured a Common Internet File System (CIFS) resource to allow access to the public partition of his company's file server, on \\erisco\goldenapple\files\public. Robe...
- Question #125
You want to create an IKE VPN between two VPN-1 NGX Security Gateways, to protect two networks. The network behind one Gateway is 10.15.0.0/16, and network 192.168.9.0/24 is behind...
- Question #126
Which is the BEST configuration option to protect internal users from malicious Java code, without stripping Java scripts?
- Question #127
Your VPN Community includes three Security Gateways. Each Gateway has its own internal network defined as a VPN Domain. You must test the VPN-1 NGX routE. based VPN feature, withou...
- Question #128
Which Security Server can perform authentication tasks, but CANNOT perform content security Check Point 156-315.71 Exam tasks?
- Question #129
You are running a VPN-1 NG with Application Intelligence R54 SecurePlatform VPN-1 Pro Gateway. The Gateway also serves as a Policy Server. When you run patch add cd from the NGX CD...
- Question #130
Which type of service should a Security Administrator use in a Rule Base to control access to specific shared partitions on target machines?
- Question #131
Assume an intruder has compromised your current IKE Phase 1 and Phase 2 keys. Which of the following options will end the intruder's access, after the next Phase 2 exchange occurs?
- Question #132
How would you configure a rule in a Security Policy to allow SIP traffic from end point Net_Ato end Check Point 156-315.71 Exam point Net_B, through an NGX Security Gateway?
- Question #133
After you add new interfaces to a cluster, how can you check if the new interfaces and the associated virtual IP address are recognized by ClusterXL?
- Question #134
Barak is a Security Administrator for an organization that has two sites using prE. shared secrets in its VPN. The two sites are Oslo and London. Barak has just been informed that...
- Question #135
You have an internal FTP server, and you allow downloading, but not uploading. Assume Network Address Translation is set up correctly, and you want to add an inbound rule with: Sou...
- Question #136
Damon enables an SMTP resource for content protection. He notices that mail seems to slow down on occasion, sometimes being delivered late. Which of the following might improve thr...
- Question #137
You are preparing computers for a new ClusterXL deployment. For your cluster, you plan to use three machines with the following configurations: Are these machines correctly configu...
- Question #138
What is the consequence of clearing the "Log VoIP Connection" box in Global Properties?
- Question #139
VPN-1 NGX includes a resource mechanism for working with the Common Internet File System (CIFS). However, this service only provides a limited level of actions for CIFS security. W...
- Question #140
Your company has two headquarters, one in London, one in New York. Each headquarters includes several branch offices. The branch offices only need to communicate with the headquart...
- Question #141
You are preparing to configure your VoIP Domain Gatekeeper object. Which two other objects should you have created first?
- Question #142
Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the follo...
- Question #143
Which of the following commands shows full synchronization status?
- Question #144
In a distributed VPN-1 Pro NGX environment, where is the Internal Certificate Authority (ICA) installed?
- Question #145
You must set up SIP with a proxy for your network. IP phones are in the 172.16.100.0 network. The Registrar and proxy are installed on host 172.16.100.100. To allow handover enforc...
- Question #146
What is the behavior of ClusterXL in a High Availability environment?
- Question #147
Which Check Point QoS feature marks the Type of Service (ToS) byte in the IP header?
- Question #148
You plan to incorporate OPSEC servers, such as Websense and Trend Micro, to do content filtering. Which segment is the BEST location for these OPSEC servers, when you consider Secu...
- Question #149
The following rule contains an FTP resource object in the Service field: Source: local_net Destination: Any Service: FTP-resource object Action: Accept Check Point 156-315.71 Exam...
- Question #150
VPN-1 NGX supports VoIP traffic in all of the following environments, EXCEPT which environment?