156-315.71 Exam Questions
484 real 156-315.71 exam questions with expert-verified answers and explanations. Page 5 of 10.
- Question #202
The following configuration is for VPN-1 NGX 65. :Is this configuration correct for Management High Availability (HA)? Check Point 156-315.71 Exam
- Question #203
When distributing IPSec packets to gateways in a Load Sharing Multicast mode cluster, which valid Load Sharing method will consider VPN information?
- Question #204
Which encryption scheme provides in-place encryption?
- Question #205
Which of the following can be said about numbered VPN Tunnel Interfaces (VTIs)?
- Question #206
What is the command to upgrade an NG with Application Intelligence R55 SmartCenter running on SecurePlatform to VPN-1 NGX R65?
- Question #207
What can be said about RSA algorithms? Select all that apply.
- Question #208
By default Check Point High Availability components send updates about their state every:
- Question #209
What is the most typical type of configuration for VPNs with several externally managed Gateways?
- Question #210
A VPN Tunnel Interface (VTI) is defined on SecurePlatform Pro as: Check Point 156-315.71 Exam vpn shell interface add numbered 10.10.0.1 10.10.0.2 Helsinki.cp What do you know abou...
- Question #211
You study the Advanced Properties exhibit carefully. What settings can you change to reduce the encryption overhead and improve performance for your mesh VPN Community?
- Question #217
Which of the following commands can be used to bind a NIC to a single processor when using a Performance Pack on SecurePlatform? Check Point 156-315.71 Exam
- Question #218
What is the maximum number of cores supported by CoreXL?
- Question #219
Which of the following is NOT a restriction for connection template generation?
- Question #220
Due to some recent performance issues, you are asked to add additional processors to your firewall. If you already have CoreXL enabled, how are you able to increase Kernel instance...
- Question #221
From the following Rule Base, for which rules will the connection templates be generated in SecureXL? Check Point 156-315.71 Exam
- Question #222
In which ClusterXL Load Sharing mode, does the pivot machine get chosen automatically by ClusterXL?
- Question #223
Which Check Point QoS feature allows a Security Administrator to define special classes of service for delay-sensitive applications?
- Question #224
What is the router command to save your OSPF configuration?
- Question #225
At what router prompt would you save your OSPF configuration? Check Point 156-315.71 Exam
- Question #226
Which of the following operating systems support numbered VTI's?
- Question #227
Which statement is TRUE for route-based VPNs?
- Question #228
Which of the following is TRUE concerning unnumbered VPN Tunnel Interfaces (VTIs)?
- Question #229
Which of the following is a supported Sticky Decision function of Sticky Connections for Load Sharing?
- Question #230
What is the reason for the following error? (See Graphic)
- Question #231
A customer calls saying that a load-sharing cluster shows drops with the error First packet is not SYN. Complete the following sentence. I will recommend:
- Question #232
By default, a standby Security Management Server is automatically synchronized by an active Security Management Server, when:
- Question #233
You have a High Availability ClusterXL configuration. Machines are not synchronized. What happens to connections on failover?
- Question #234
You are preparing computers for a new ClusterXL deployment. For your cluster, you plan to use three machines with the following configurations: Cluster Member 1: OS: SecurePlatform...
- Question #235
Which of the following commands will stop acceleration on a Security Gateway running on SecurePlatform?
- Question #236
Which of the following is TRUE concerning numbered VPN Tunnel Interfaces (VTIs)?
- Question #237
Which operating system(s) support(s) unnumbered VPN Tunnel Interfaces (VTIs) for route-based VPNs?
- Question #238
After Travis added new processing cores on his server, CoreXL did not use them. What would be the most plausible reason why? Travis did not:
- Question #239
Check Point New Mode HA is a(n)__________solution.
- Question #240
Included in the client's network are some switches, which rely on IGMP snooping. You must find a solution to work with these switches. Which of the following answers does NOT lead...
- Question #241
You have two IP Appliances: one IP565 and one IP395. Both appliances have IPSO 6.2 and R71 installed in a distributed deployment. Can they be members of a Gateway Cluster?
- Question #242
What could be a reason why synchronization between primary and secondary Security Management Servers does not occur?
- Question #243
Which of the following items can be provisioned via a Profile through SmartProvisioning?
- Question #244
What does it mean when a Security Gateway is labeled Untrusted in the SmartProvisioning Status view?
- Question #245
Using the Backup Target functionality in SmartProvisioning, what targets are available?
- Question #246
The We-Make-Widgets company has purchased twenty UTM-1 Edge appliances for their remote offices. Kim decides the best way to manage those appliances is to use SmartProvisioning and...
- Question #247
SmartProvisioning can provision the Operating System and network settings on which of the following?
- Question #248
Check Point 156-315.71 Exam Which of the following services will cause SecureXL templates to be disabled?
- Question #249
Which of the following load-balancing methods is not valid?
- Question #250
The relay mail server configured under Email Notifications is used by the DLP Gateway to: (Choose the BEST answer.)
- Question #251
For a dedicated DLP Gateway that runs in inline bridge mode, why is it important to properly define the topology?
- Question #252
Which protocol is not supported for DLP?
- Question #253
What happens when an Administrator activates the DLP Portal for Self Incident Handling and enters its fully qualified domain name (DNS name)?
- Question #254
You just upgraded to R71 and are using the IPS Software Blade. You want to enable all critical protections while keeping the rate of false positive very low. How can you achieve th...
- Question #255
You enable Sweep Scan Protection and Host port scan in IPS to determine if a large amount of traffic from a specific internal IP address is a network attack, or a user's system is...
- Question #256
You need to verify the effectiveness of your IPS configuration for your Web server farm. You have a colleague run penetration tests to confirm that the Web servers are secure again...