Pass the Checkpoint CCSE R81 156-315.81 Questions and answers with CertsForce

Viewing page 7 out of 13 pages
Viewing questions 91-105 out of questions
Questions # 91:

Which upgrade method you should use upgrading from R80.40 to R81.20 to avoid any downtime?

Options:

A.

Zero Downtime Upgrade (ZDU)


B.

Connectivity Upgrade (CU)


C.

Minimal Effort Upgrade (ME)


D.

Multi-Version Cluster Upgrade (MVC)


Expert Solution
Questions # 92:

Which of the following is NOT a method used by identity Awareness for acquiring identity?

Options:

A.

Remote Access


B.

Active Directory Query


C.

Cloud IdP (Identity Provider)


D.

RADIUS


Expert Solution
Questions # 93:

What are scenarios supported by the Central Deployment in SmartConsole?

Options:

A.

Installation of Jumbo Hotfix on a ClusterXL environment in High Availability Mode


B.

Upgrading a Dedicated SmartEvent Server


C.

Upgrading a Dedicated Log Server to R81


D.

Upgrading a Standalone environment


Expert Solution
Questions # 94:

By default, which port does the WebUI listen on?

Options:

A.

80


B.

4434


C.

443


D.

8080


Expert Solution
Questions # 95:

What is true of the API server on R81.20?

Options:

A.

By default the API-server is activated and does not have hardware requirements.


B.

By default the API-server is not active and should be activated from the WebUI.


C.

By default the API server is active on management and stand-alone servers with 16GB of RAM (or more).


D.

By default, the API server is active on management servers with 4 GB of RAM (or more) and on stand-alone servers with 8GB of RAM (or more).


Expert Solution
Questions # 96:

What will be the effect of running the following command on the Security Management Server?

Question # 96

Options:

A.

Remove the installed Security Policy.


B.

Remove the local ACL lists.


C.

No effect.


D.

Reset SIC on all gateways.


Expert Solution
Questions # 97:

Fill in the blank: The R81 SmartConsole, SmartEvent GUI client, and _______ consolidate billions of logs and shows then as prioritized security events.

Options:

A.

SmartMonitor


B.

SmartView Web Application


C.

SmartReporter


D.

SmartTracker


Expert Solution
Questions # 98:

Which statement is most correct regarding about “CoreXL Dynamic Dispatcher”?

Options:

A.

The CoreXL FW instanxces assignment mechanism is based on Source MAC addresses, Destination MAC addresses


B.

The CoreXL FW instances assignment mechanism is based on the utilization of CPU cores


C.

The CoreXL FW instances assignment mechanism is based on IP Protocol type


D.

The CoreXl FW instances assignment mechanism is based on Source IP addresses, Destination IP addresses, and the IP ‘Protocol’ type


Expert Solution
Questions # 99:

You notice that your firewall is under a DDoS attack and would like to enable the Penalty Box feature, which command you use?

Options:

A.

sim erdos –e 1


B.

sim erdos – m 1


C.

sim erdos –v 1


D.

sim erdos –x 1


Expert Solution
Questions # 100:

Fill in the blank. Once a certificate is revoked from the Security Gateway by the Security Management Server, the certificate information is ________ .

Options:

A.

Sent to the Internal Certificate Authority.


B.

Sent to the Security Administrator.


C.

Stored on the Security Management Server.


D.

Stored on the Certificate Revocation List.


Expert Solution
Questions # 101:

Which of the following Windows Security Events will not map a username to an IP address in Identity Awareness?

Options:

A.

Kerberos Ticket Renewed


B.

Kerberos Ticket Requested


C.

Account Logon


D.

Kerberos Ticket Timed Out


Expert Solution
Questions # 102:

When using CPSTAT, what is the default port used by the AMON server?

Options:

A.

18191


B.

18192


C.

18194


D.

18190


Expert Solution
Questions # 103:

During the Check Point Stateful Inspection Process, for packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are:

Options:

A.

Dropped without sending a negative acknowledgment


B.

Dropped without logs and without sending a negative acknowledgment


C.

Dropped with negative acknowledgment


D.

Dropped with logs and without sending a negative acknowledgment


Expert Solution
Questions # 104:

What must you do first if “fwm sic_reset” could not be completed?

Options:

A.

Cpstop then find keyword “certificate” in objects_5_0.C and delete the section


B.

Reinitialize SIC on the security gateway then run “fw unloadlocal”


C.

Reset SIC from Smart Dashboard


D.

Change internal CA via cpconfig


Expert Solution
Questions # 105:

What are the types of Software Containers?

Options:

A.

Three; security management, Security Gateway, and endpoint security


B.

Three; Security Gateway, endpoint security, and gateway management


C.

Two; security management and endpoint security


D.

Two; endpoint security and Security Gateway


Expert Solution
Viewing page 7 out of 13 pages
Viewing questions 91-105 out of questions