Pass CheckPoint 156-215.80 With PassTorrent Exam Dumps - Updated on Oct-2022
Fully Updated 156-215.80 Dumps - 100% Same Q&A In Your Real Exam
Check Point CCSA Exam Certification Details:
| Exam Code | 156-215.80 |
| Sample Questions | Check Point CCSA Sample Questions |
| Duration | 90 mins |
| Books / Training | CCSM Training |
| Exam Name | Check Point Certified Security Administrator (CCSA) R80 |
| Schedule Exam | Pearson VUE |
| Passing Score | 70% |
| Number of Questions | 90 |
NEW QUESTION 117
ABC Corp., and have recently returned from a training course on Check Point's new advanced R80 management platform. You are presenting an in-house R80 Management to the other administrators in ABC Corp.
How will you describe the new "Publish" button in R80 Management Console?
- A. The Publish button makes any changes an administrator has made in their management session visible to all other administrator sessions and saves it to the Database.
- B. The Publish button makes any changes an administrator has made in their management session visible to the new Unified Policy session and saves it to the Database.
- C. The Publish button takes any changes an administrator has made in their management session, publishes a copy to the Check Point of R80, and then saves it to the R80 database.
- D. The Publish button takes any changes an administrator has made in their management session and publishes a copy to the Check Point Cloud of R80 and but does not save it to the R80
Answer: A
Explanation:
Explanation
To make your changes available to other administrators, and to save the database before installing a policy, you must publish the session. When you publish a session, a new database version is created.
References:
NEW QUESTION 118
Choose the Best place to find a Security Management Server backup file named backup_fw, on a Check Point
Appliance.
- A. /var/log/Cpbackup/backups/backup/backup_fw.tar
- B. /var/log/Cpbackup/backups/backups/backup_fw.tar
- C. /var/log/Cpbackup/backups/backup_fw.tgz
- D. /var/log/Cpbackup/backups/backup/backup_fw.tgs
Answer: C
Explanation:
Explanation
Gaia's Backup feature allows backing up the configuration of the Gaia OS and of the Security Management
server database, or restoring a previously saved configuration.
The configuration is saved to a .tgz file in the following directory:
Gaia OS Version
Hardware
Local Directory
R75.40 - R77.20
Check Point appliances
/var/log/CPbackup/backups/
Open Server
/var/CPbackup/backups/
R77.30
Check Point appliances
/var/log/CPbackup/backups/
Open Server
NEW QUESTION 119
What does it mean if Deyra sees the gateway status:
Choose the BEST answer.
- A. Security Gateway's MGNT NIC card is disconnected.
- B. SmartCenter Server cannot reach this Security Gateway
- C. VPN software blade is reporting a malfunction
- D. There is a blade reporting a problem
Answer: D
Explanation:
Explanation
NEW QUESTION 120
When an encrypted packet is decrypted, where does this happen?
- A. Security policy
- B. Inbound chain
- C. Outbound chain
- D. Decryption is not supported
Answer: A
NEW QUESTION 121
Which of the following is NOT a method used by Identity Awareness for acquiring identity?
- A. RADIUS
- B. Active Directory Query
- C. Remote Access
- D. Certificates
Answer: D
Explanation:
Explanation/Reference:
Reference: https://www.checkpoint.com/products/identity-awareness-software-blade/
NEW QUESTION 122
What are the three deployment considerations for a secure network?
- A. Remote, Standalone, and Distributed
- B. Standalone, Distributed, and Bridge Mode
- C. Bridge Mode, Remote, and Standalone
- D. Distributed, Bridge Mode, and Remote
Answer: D
NEW QUESTION 123
John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to
HR servers to designated IP addresses to minimize malware infection and unauthorized access risks. Thus, the gateway policy permits access only from John's desktop which is assigned a static IP address 10.0.0.19.
John received a laptop and wants to access the HR Web Server from anywhere in the organization. The IT department gave the laptop a static IP address, but that limits him to operating it only from his desk. The current Rule Base contains a rule that lets John Adams access the HR Web Server from his desktop with a static IP (10.0.0.19). He wants to move around the organization and continue to have access to the HR Web Server.
To make this scenario work, the IT administrator:
1) Enables Identity Awareness on a gateway, selects AD Query as one of the Identity
Sources installs the policy.
2) Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web Server from any machine and from any location.
3) Changes from static IP address to DHCP for the client PC.
What should John request when he cannot access the web server from his laptop?
- A. John should lock and unlock his computer
- B. Investigate this as a network connectivity issue
- C. The access should be changed to authenticate the user instead of the PC
- D. John should install the Identity Awareness Agent
Answer: C
NEW QUESTION 124
What will be the effect of running the following command on the Security Management Server?
- A. No effect.
- B. Remove the local ACL lists.
- C. Remove the installed Security Policy.
- D. Reset SIC on all gateways.
Answer: C
Explanation:
Explanation
This command uninstall actual security policy (already installed)
NEW QUESTION 125
You have just installed your Gateway and want to analyze the packet size distribution of your traffic with SmartView Monitor.
Unfortunately, you get the message:
"There are no machines that contain Firewall Blade and SmartView Monitor".
What should you do to analyze the packet size distribution of your traffic? Give the BEST answer.
- A. Enable Monitoring on your Security Management Server.
- B. Purchase the SmartView Monitor license for your Security Management Server.
- C. Purchase the SmartView Monitor license for your Security Gateway.
- D. Enable Monitoring on your Security Gateway.
Answer: D
NEW QUESTION 126
Fill in the blank: In Security Gateways R75 and above, SIC uses ______________ for encryption.
- A. DES
- B. 3DES
- C. AES-128
- D. AES-256
Answer: C
Explanation:
Explanation
References:
NEW QUESTION 127
Which of the following is NOT an authentication scheme used for accounts created through SmartConsole?
- A. RADIUS
- B. Check Point password
- C. Security questions
- D. SecurID
Answer: C
Explanation:
Authentication Schemes:
- Check Point Password
- Operating System Password
- RADIUS
- SecurID
- TACAS
- Undefined If a user with an undefined authentication scheme is matched to a Security Rule with some form of authentication, access is always denied.
NEW QUESTION 128
Can a Check Point gateway translate both source IP address and destination IP address in a given packet?
- A. Yes.
- B. Yes, but only when using Manual NAT.
- C. No.
- D. Yes, but only when using Automatic NAT.
Answer: A
NEW QUESTION 129
Which remote Access Solution is clientless?
- A. Mobile Access Portal
- B. SecuRemote
- C. Checkpoint Mobile
- D. Endpoint Security Suite
Answer: A
Explanation:
Explanation/Reference:
Reference: https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_WebAdmin/92708.htm
NEW QUESTION 130
An internal router is sending UDP keep-alive packets that are being encapsulated with GRE and sent through your R77 Security Gateway to a partner site. A rule for GRE traffic is configured for ACCEPT/LOG.
Although the keep-alive packets are being sent every minute, a search through the SmartView Tracker logs for GRE traffic only shows one entry for the whole day (early in the morning after a Policy install).
Your partner site indicates they are successfully receiving the GRE encapsulated keep-alive packets on the 1-minute interval.
If GRE encapsulation is turned off on the router, SmartView Tracker shows a log entry for the UDP keep- alive packet every minute.
Which of the following is the BEST explanation for this behavior?
- A. The Log Server is failing to log GRE traffic properly because it is VPN traffic. Disable all VPN configuration to the partner site to enable proper logging.
- B. The log unification process is using a LUUID (Log Unification Unique Identification) that has become corrupt. Because it is encrypted, the R77 Security Gateway cannot distinguish between GRE sessions.
This is a known issue with GRE. Use IPSEC instead of the non-standard GRE protocol for encapsulation. - C. The Log Server log unification process unifies all log entries from the Security Gateway on a specific connection into only one log entry in the SmartView Tracker. GRE traffic has a 10 minute session timeout, thus each keep-alive packet is considered part of the original logged connection at the beginning of the day.
- D. The setting Log does not capture this level of detail for GRE. Set the rule tracking action to Audit since certain types of traffic can only be tracked this way.
Answer: C
NEW QUESTION 131
You are unable to login to SmartDashboard. You log into the management server and run #cpwd_admin list with the following output:
What reason could possibly BEST explain why you are unable to connect to SmartDashboard?
- A. SVR is down
- B. CPSM is down
- C. CDP is down
- D. FWM is down
Answer: D
Explanation:
Explanation/Reference:
The correct answer would be FWM (is the process making available communication between SmartConsole applications and Security Management Server.). STATE is T (Terminate = Down) Explanation :
Symptoms
SmartDashboard fails to connect to the Security Management server.
1. Verify if the FWM process is running. To do this, run the command:
[Expert@HostName:0]# ps -aux | grep fwm
2. If the FWM process is not running, then try force-starting the process with the following command:
[Expert@HostName:0]# cpwd_admin start -name FWM -path "$FWDIR/bin/fwm" -command "fwm" Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk97638
https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk12120
NEW QUESTION 132
Which option would allow you to make a backup copy of the OS and Check Point configuration, without stopping Check Point processes?
- A. All options stop Check Point processes
- B. snapshot
- C. backup
- D. migrate export
Answer: B
Explanation:
Explanation/Reference:
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk106127
NEW QUESTION 133
On the following picture an administrator configures Identity Awareness:
After clicking "Next" the above configuration is supported by:
- A. Obligatory usage of Captive Portal
- B. The ports 443 or 80 what will be used by Browser-Based and configured Authentication
- C. Based on Active Directory integration which allows the Security Gateway to correlate Active Directory users and machines to IP addresses in a method that is completely transparent to the user
- D. Kerberos SSO which will be working for Active Directory integration
Answer: C
Explanation:
To enable Identity Awareness:
The Identity Awareness Configuration wizard opens.
NEW QUESTION 134
You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.
- A. You checked the cache password on desktop option in Global Properties.
- B. You have forgotten to place the User Authentication Rule before the Stealth Rule.
- C. Users must use the SecuRemote Client, to use the User Authentication Rule.
- D. Another rule that accepts HTTP without authentication exists in the Rule Base.
Answer: D
NEW QUESTION 135
Which icon indicates in the WebUI that read/write access is enabled?
- A. Book
- B. Padlock
- C. Pencil
- D. Eyeglasses
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 136
CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You suspect that the problem might be the Threat Prevention settings.
The following Threat Prevention Profile has been created.
How could you tune the profile in order to lower the CPU load still maintaining security at good level?
- A. Set High Confidence to Low and Low Confidence to Inactive.
- B. Set the Performance Impact to Medium or lower.
- C. Set the Performance Impact to Very Low Confidence to Prevent.
- D. The problem is not with the Threat Prevention Profile. Consider adding more memory to the appliance.
Answer: B
NEW QUESTION 137
Where can you trigger a failover of the cluster members?
1. Log in to Security Gateway CLI and run command clusterXL_admin down.
2. In SmartView Monitor right-click the Security Gateway member and select Cluster member stop.
3. Log into Security Gateway CLI and run command cphaprob down.
- A. 1 and 2
- B. 1 and 3
- C. 2 and 3
- D. 1, 2, and 3
Answer: A
Explanation:
Explanation
How to Initiate Failover
NEW QUESTION 138
In ____________ NAT, the ____________ is translated.
- A. Hide; source
- B. Static; source
- C. Simple; source
- D. Hide; destination
Answer: A
NEW QUESTION 139
There are two R77.30 Security Gateways in the Firewall Cluster. They are named FW_A and FW_B. The cluster is configured to work as HA (High availability) with default cluster configuration. FW_A is configured to have higher priority than FW_B. FW_A was active and processing the traffic in the morning. FW_B was standby. Around 1100 am, its interfaces went down and this caused a failover.
FW_B became active. After an hour, FW_A's interface issues were resolved and it became operational.
When it re-joins the cluster, will it become active automatically?
- A. No, since "maintain current active cluster member" option is enabled by default on the Global Properties
- B. Yes, since "Switch to higher priority cluster member" option is enabled by default on the Global Properties
- C. Yes, since "Switch to higher priority cluster member" option on the cluster object properties is enabled by default
- D. No, since "maintain current active cluster member" option on the cluster object properties is enabled by default
Answer: D
Explanation:
What Happens When a Security Gateway Recovers?
In a Load Sharing configuration, when the failed Security Gateway in a cluster recovers, all connections are redistributed among all active members. High Availability and Load Sharing in ClusterXL ClusterXL Administration Guide R77 Versions | 31 In a High Availability configuration, when the failed Security Gateway in a cluster recovers, the recovery method depends on the configured cluster setting. The options are:
* Maintain Current Active Security Gateway means that if one member passes on control to a lower priority member, control will be returned to the higher priority member only if the lower priority member fails. This mode is recommended if all members are equally capable of processing traffic, in order to minimize the number of failover events.
* Switch to Higher Priority Security Gateway means that if the lower priority member has control and the higher priority member is restored, then control will be returned to the higher priority member. This mode is recommended if one member is better equipped for handling connections, so it will be the default Security Gateway.
NEW QUESTION 140
......
How to study the 156-215.80 Exam
PassTorrent expert team recommends you to prepare some notes on these topics along with it don't forget to practice Check Point Certified Security Administrator (CCSA R80) 156-215.80 Exam exam dumps which been written by our expert team, Both these will help you a lot to clear this exam with good marks.
Latest 156-215.80 Exam Dumps - Valid and Updated Dumps: https://freepdf.passtorrent.com/156-215.80-latest-torrent.html