100% Pass Top-selling 156-215.80 Exams - New 2021 CheckPoint Pratice Exam
CCSA R80 Dumps 156-215.80 Exam for Full Questions - Exam Study Guide
NEW QUESTION 135
Match the following commands to their correct function. Each command has one function only listed.
- A. C1>F2; C2>F1; C3>F6; C4>F4
- B. C1>F2; C2>F4; C3>F1; C4>F5
- C. C1>F6; C2>F4; C3>F2; C4>F5
- D. C1>F4; C2>F6; C3>F3; C4>F5
Answer: C
NEW QUESTION 136
VPN gateways must authenticate to each other prior to exchanging information.
What are the two types of credentials used for authentication?
- A. Certificates and IPsec
- B. Certificates and pre-shared secret
- C. IPsec and VPN Domains
- D. 3DES and MD5
Answer: B
NEW QUESTION 137
Identify the API that is not supported by Check Point currently.
- A. Open REST API
- B. OPSEC SDK
- C. R80 Management API-
- D. Identity Awareness Web Services API
Answer: A
Explanation:
Explanation/Reference: http://dl3.checkpoint.com/paid/29/29532b9eec50d0a947719ae631f640d0/ CP_R80_CheckPoint_API_ReferenceGuide.pdf?
HashKey=1517091458_be29bd4732d8d22283df32ccaaffc482&xtn=.pdf
NEW QUESTION 138
A Cleanup rule:
- A. drops packets without logging connections that would otherwise be accepted and logged by default.
- B. drops packets without logging connections that would otherwise be dropped and logged by default.
- C. logs connections that would otherwise be dropped without logging by default.
- D. logs connections that would otherwise be accepted without logging by default.
Answer: C
NEW QUESTION 139
Web Control Layer has been set up using the settings in the following dialogue:
Consider the following policy and select the BEST answer.
- A. Anyone from internal network can access the internet, expect the traffic defined in drop rules 5.2, 5.5 and 5.6.
- B. All employees can access only Youtube and Vimeo.
- C. Access to Youtube and Vimeo is allowed only once a day.
- D. Traffic that does not match any rule in the subpolicy is dropped.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Policy Layers and Sub-Policies
R80 introduces the concept of layers and sub-policies, allowing you to segment your policy according to your network segments or business units/functions. In addition, you can also assign granular privileges by layer or sub-policy to distribute workload and tasks to the most qualified administrators With layers, the rule base is organized into a set of security rules. These set of rules or layers, are
inspected in the order in which they are defined, allowing control over the rule base flow and the security functionalities that take precedence. If an "accept" action is performed across a layer, the inspection will continue to the next layer. For example, a compliance layer can be created to overlay across a cross-section of rules.
Sub-policies are sets of rules that are created for a specific network segment, branch office or business
unit, so if a rule is matched, inspection will continue through this subset of rules before it moves on to the next rule.
Sub-policies and layers can be managed by specific administrators, according to their permissions
profiles. This facilitates task delegation and workload distribution.
Reference: https://community.checkpoint.com/docs/DOC-1065
NEW QUESTION 140
Fill in the blank: A _______ is used by a VPN gateway to send traffic as if it were a physical interface.
- A. VPN community
- B. VPN interface
- C. VPN router
- D. VPN Tunnel Interface
Answer: D
Explanation:
Explanation
Route Based VPN
VPN traffic is routed according to the routing settings (static or dynamic) of the Security Gateway operating
system. The Security Gateway uses a VTI (VPN Tunnel Interface) to send the VPN traffic as if it were a
physical interface. The VTIs of Security Gateways in a VPN community connect and can support dynamic
routing protocols.
NEW QUESTION 141
Which product correlates logs and detects security threats, providing a centralized display of potential attack
patterns from all network devices?
- A. SmartUpdate
- B. SmartDashboard
- C. SmartEvent
- D. SmartView Monitor
Answer: C
Explanation:
Explanation
SmartEvent correlates logs from all Check Point enforcement points, including end-points, to identify
suspicious activity from the clutter. Rapid data analysis and custom event logs immediately alert
administrators to anomalous behavior such as someone attempting to use the same credential in multiple
geographies simultaneously.
NEW QUESTION 142
Packages and licenses are loaded from all of theses sources EXCEPT
- A. UserUpdate
- B. User Center
- C. Download Center Web site
- D. Check Point DVD
Answer: A
Explanation:
Packages and licenses are loaded into these repositories from severalsources:
NEW QUESTION 143
What key is used to save the current CPView page in a filename format cpview_"cpview process ID".
cap"number of captures"?
- A. S
- B. W
- C. Space bar
- D. C
Answer: D
Explanation:
Explanation/Reference:
Reference: https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_SecurityManagement_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/ WebAdminGuides/EN/CP_R80.20_SecurityManagement_AdminGuide/204685
NEW QUESTION 144
Fill in the blank: When tunnel test packets no longer invoke a response, SmartView Monitor displays _____________ for the given VPN tunnel.
- A. Down
- B. No Response
- C. Inactive
- D. Failed
Answer: A
NEW QUESTION 145
Which Threat Prevention Software Blade provides comprehensive against malicious and unwanted network traffic, focusing on application and server vulnerabilities?
- A. IPS
- B. Anti-Spam
- C. Anti-bot
- D. Anti-Virus
Answer: A
Explanation:
The IPS Software Blade provides a complete Intrusion Prevention System security solution, providing comprehensive network protection against malicious and unwanted network traffic, including:
NEW QUESTION 146
You are the administrator for Alpha Corp. You have logged into your R80 Management server. You are making some changes in the Rule Base and notice that rule No.6 has a pencil icon next to it.
What does this mean?
- A. The rule No.6 has been marked for editing in your Management session.
- B. The rule No.6 has been marked for deletion in your Management session.
- C. The rule No.6 has been marked for editing in another Management session.
- D. The rule No.6 has been marked for deletion in another Management session.
Answer: A
NEW QUESTION 147
The technical-support department has a requirement to access an intranet server. When configuring a User Authentication rule to achieve this, which of the following should you remember?
- A. You can only use the rule for Telnet, FTP, SMPT, and rlogin services.
- B. You can limit the authentication attempts in the User Properties' Authentication tab.
- C. Once a user is first authenticated, the user will not be prompted for authentication again until logging out.
- D. The Security Gateway first checks if there is any rule that does not require authentication for this type of connection before invoking the Authentication Security Server.
Answer: D
NEW QUESTION 148
Why would an administrator see the message below?
- A. A new Policy Package created on the Gateway is going to be installed on the existing
Management. - B. A new Policy Package created on the Gateway and transferred to the management will be overwritten by the Policy Package currently on the Gateway but can be restored from a periodic backup on the Gateway.
- C. A new Policy Package created on the Management is going to be installed to the existing Gateway.
- D. A new Policy Package created on both the Management and Gateway will be deleted and must be packed up first before proceeding.
Answer: C
NEW QUESTION 149
On the following picture an administrator configures Identity Awareness:
After clicking "Next" the above configuration is supported by:
- A. Kerberos SSO which will be working for Active Directory integration
- B. The ports 443 or 80 what will be used by Browser-Based and configured Authentication
- C. Obligatory usage of Captive Portal
- D. Based on Active Directory integration which allows the Security Gateway to correlate Active Directory users and machines to IP addresses in a method that is completely transparent to the user
Answer: D
Explanation:
To enable Identity Awareness:
The Identity Awareness Configuration wizard opens.
NEW QUESTION 150
Study the Rule base and Client Authentication Action properties screen.

After being authenticated by the Security Gateways, a user starts a HTTP connection to a Web site. What happens when the user tries to FTP to another site using the command line? The:
- A. FTP data connection is dropped after the user is authenticated successfully.
- B. FTP connection is dropped by Rule 2.
- C. user is prompted to authenticate from that FTP site only, and does not need to enter his username and password for Client Authentication
- D. user is prompted for authentication by the Security Gateways again.
Answer: C
NEW QUESTION 151
......
Authentic Best resources for 156-215.80 Online Practice Exam: https://www.passexamdumps.com/156-215.80-valid-exam-dumps.html
156-215.80 Test Engine Practice Exam: https://drive.google.com/open?id=1UqTfa1lyG_Hfx9Vsbj0ZVhC_lAZIja8O
