Check Point 156-215.76 Certification Exam Material - Free Download and Guaranteed Pass
Exam code : 156-215.76
Exam name : Check Point Certified Security Administrator – Gaia
Which of the following are available SmartConsole clients which can be installed from the
R76 Windows CD? Read all answers and select the most complete and valid list.
A. SmartView Tracker, CPINFO, SmartUpdate
B. SmartView Tracker, SmartDashboard, SmartLSM, SmartView Monitor
C. SmartView Tracker, SmartDashboard, CPINFO, SmartUpdate, SmartView Status
D. Security Policy Editor, Log Viewer, Real Time Monitor GUI
Answer: A
You manage a global network extending from your base in Chicago to Tokyo, Calcutta and
Dallas. Management wants a report detailing the current software level of each Enterprise
class Security Gateway. You plan to take the opportunity to create a proposal outline,
listing the most cost-effective way to upgrade your Gateways. Which two SmartConsole
applications will you use to create this report and outline?
A. SmartLSM and SmartUpdate
B. SmartView Tracker and SmartView Monitor
C. SmartView Monitor and SmartUpdate
D. SmartDashboard and SmartView Tracker
Answer: D
Your bank's distributed R76 installation has Security Gateways up for renewal. Which
SmartConsole application will tell you which Security Gateways have licenses that will
expire within the next 30 days?
A. SmartView Tracker
B. SmartPortal
C. SmartUpdate
D. SmartDashboard
Answer: A
When launching SmartDashboard, what information is required to log into R76?
A. User Name, Management Server IP, certificate fingerprint file
B. User Name, Password, Management Server IP
C. Password, Management Server IP
D. Password, Management Server IP, LDAP Server IP
Answer: D
Message digests use which of the following?
A. SHA-1 and MD5
B. IDEA and RC4
C. SSL and MD4
D. DES and RC4
Answer: A
Which of the following is a hash algorithm?
A. DES
B. IDEA
C. MD5
D. 3DES
Answer: C
Which of the following uses the same key to decrypt as it does to encrypt?
A. Asymmetric encryption
B. Symmetric encryption
C. Certificate-based encryption
D. Dynamic encryption
Answer: B
You believe Phase 2 negotiations are failing while you are attempting to configure a site-tosite
VPN with one of your firm's business partners. Which SmartConsole application should
you use to confirm your suspicions?
A. SmartDashboard
B. SmartView Tracker
C. SmartUpdate
D. SmartView Status
Answer: B
A digital signature:
A. Provides a secure key exchange mechanism over the Internet.
B. Automatically exchanges shared keys.
C. Guarantees the authenticity and integrity of a message.
D. Decrypts data to its original form.
Answer: C
Which component functions as the Internal Certificate Authority for R76?
A. Security Gateway
B. Management Server
C. Policy Server
D. SmartLSM
Answer: B
Which SmartConsole component can Administrators use to track changes to the Rule
Base?
A. SmartView Monitor
B. SmartReporter
C. WebUI
D. SmartView Tracker
Answer: D
UDP packets are delivered if they are ___________.
A. referenced in the SAM related dynamic tables
B. a valid response to an allowed request on the inverse UDP ports and IP
C. a stateful ACK to a valid SYN-SYN/ACK on the inverse UDP ports and IP
D. bypassing the kernel by the forwarding layer of ClusterXL
Answer: B
The INSPECT engine inserts itself into the kernel between which two OSI model layers?
A. Physical and Data
B. Session and Transport
C. Data link and Network
D. Presentation and Application
Answer: C
The customer has a small Check Point installation, which includes one SecurePlatform
server working as the SmartConsole, and a second server running Windows 2008 as both
Security Management Server and Security Gateway. This is an example of a(n):
A. Distributed Installation
B. Stand-Alone Installation
C. Hybrid Installation
D. Unsupported configuration
Answer: D
The customer has a small Check Point installation which includes one Windows 2008
server as the SmartConsole and a second server running SecurePlatform as both Security
Management Server and the Security Gateway. This is an example of a(n):
A. Stand-Alone Installation
B. Distributed Installation
C. Unsupported configuration
D. Hybrid Installation
Answer: A
The customer has a small Check Point installation which includes one Windows 7
workstation as the SmartConsole, one GAiA device working as Security Management
Server, and a third server running SecurePlatform as Security Gateway. This is an example
of a(n):
A. Unsupported configuration
B. Stand-Alone Installation
C. Hybrid Installation
D. Distributed Installation
Answer: D
The customer has a small Check Point installation which includes one Windows 2008
server as SmartConsole and Security Management Server with a second server running
SecurePlatform as Security Gateway. This is an example of a(n):
A. Stand-Alone Installation.
B. Distributed Installation.
C. Hybrid Installation.
D. Unsupported configuration.
Answer: B
When doing a Stand-Alone Installation, you would install the Security Management Server
with which other Check Point architecture component?
A. SecureClient
B. Security Gateway
C. None, Security Management Server would be installed by itself.
D. SmartConsole
Answer: B
Tom has been tasked to install Check Point R76 in a distributed deployment. Before Tom
installs the systems this way, how many machines will he need if he does not include a
SmartConsole machine in his calculations?
A. Three machines
B. One machine
C. One machine, but it needs to be installed using SecurePlatform for compatibility
purposes
D. Two machines
Answer: D
Which of the following statements is TRUE about management plug-ins?
A. A management plug-in interacts with a Security Management Server to provide new
features and support for new products.
B. The plug-in is a package installed on the Security Gateway.
C. Using a plug-in offers full central management only if special licensing is applied to
specific features of the plug-in.
D. Installing a management plug-in is just like an upgrade process.
Answer: A
You are installing a Security Management Server. Your security plan calls for three
administrators for this particular server. How many can you create during installation?
A. Depends on the license installed on the Security Management Server
B. One
C. As many as you want
D. Only one with full access and one with read-only access
Answer: B
During which step in the installation process is it necessary to note the fingerprint for firsttime
verification?
A. When configuring the Security Gateway object in SmartDashboard
B. When configuring the Security Management Server using cpconfig
C. When establishing SIC between the Security Management Server and the Gateway
D. When configuring the Gateway in the WebUI
Answer: B
How can you most quickly reset Secure Internal Communications (SIC) between a Security
Management Server and Security Gateway?
A. From the Security Management Server's command line, type fw putkey -p <shared key>
<IP Address of Security Gateway>.
B. Run the command fwm sic_reset to reinitialize the Security Management Server Internal
Certificate Authority (ICA). Then retype the activation key on the Security Gateway from
SmartDashboard.
C. Use SmartUpdate to retype the Security Gateway activation key. This will automatically
sync SIC to both the Security Management Server and Gateway.
D. From cpconfig on the Gateway, choose the Secure Internal Communication option and
retype the activation key. Next, retype the same key in the Gateway object in
SmartDashboard and reinitialize Secure Internal Communications (SIC).
Answer: D
How can you recreate the Security Administrator account, which was created during initial
Management Server installation on SecurePlatform?
A. Launch cpconfig and delete the Administrator's account. Recreate the account with the
same name.
B. Launch SmartDashboard in the User Management screen, and delete the cpconfig
administrator.
C. Export the user database into an ASCII file with fwm dbexport. Open this file with an
editor, and delete the Administrator Account portion of the file. You will be prompted to
create a new account.
D. Type cpm -a, and provide the existing Administrator's account name. Reset the Security
Administrator's password.
Answer: A
When Jon first installed his new security system, he forgot to configure DNS servers on his
Security Gateway. How could Jon configure DNS servers now that his Security Gateway is
in production?
A. Login to the SmartDashboard, edit the firewall Gateway object, select the tab Interfaces
> Domain Name Servers.
B. Login to the firewall using SSH and run cpconfig, then select Domain Name Servers.
C. Login to the firewall using SSH and run fwm, then select System Configuration >
Domain Name Servers.
D. Login to the firewall using SSH and run sysconfig, then select Domain Name Servers.
Answer: D
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment