New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Checkpoint 156-115.80 Dumps Questions Answers

Page: 1 / 6
Total 159 questions

Check Point Certified Security Master - R80 Questions and Answers

Question 1

Which kernel table stores information about NAT connections?

Options:

A.

connections

B.

tab_nat_conn

C.

xlate

D.

fwx_alloc

Buy Now
Question 2

The packet processing infrastructure consists of 4 components. Which component contains the CLOB, the object that contains information about the packet that is needed to make security decisions?

Options:

A.

Classifiers

B.

Handlers

C.

Manager

D.

Observers

Question 3

Which command would show you the status of the clustered interfaces as well as the virtual interfaces?

Options:

A.

cphaprob –i list

B.

cphaprob –i if

C.

cphaprob –a if

D.

cphaprob if stat

Question 4

What is the default and maximum number of entries in the ARP Cache Table in a Check Point appliance?

Options:

A.

1,024 and 4,096

B.

4,096 and 16,384

C.

4,096 and 65,536

D.

1,024 and 16,384

Question 5

What does CMI stand for in relation to the Access Control Policy?

Options:

A.

Content Matching Infrastructure

B.

Content Management Interface

C.

Context Management Infrastructure

D.

Context Manipulation Interface

Question 6

What is enabled by the command “vpn debug mon”?

Options:

A.

statistics monitoring for vpn encrypted packets

B.

vpn daemon monitor mode

C.

ike monitor

D.

vpn debug mode

Question 7

When running a debug with fw monitor, which parameter will create a more verbose output?

Options:

A.

-l

B.

-i

C.

-D

D.

-d

Question 8

Fill in the blank: The R80 featurepermits blocking specific IP addresses for a specified time period.

Options:

A.

Block Port Overflow

B.

Local Interface Spoofing

C.

Suspicious Activity Monitoring

D.

Adaptive Threat Prevention

Question 9

Which command(s) can be used to set up 5 core files per process?

Options:

A.

set core-dump per_process 5 save config

B.

set core-dump per_process amount = 5 save config

C.

set core-dump per_process 5

D.

add core-dump per_process 5 save config

Question 10

When dealing with monolithic operating systems such as Gaia, where are system calls initiated from to achieve a required system level function?

Options:

A.

Slow Path

B.

Medium Path

C.

Kernel Mode

D.

User Mode

Question 11

During firewall kernel debug with fw ctl zdebug you received less information than expected. You noticed that a lot of messages were lost since the time the debug was started. What should you do to resolve this issue?

Options:

A.

Increase debug buffer; Use fw ctl debug –buf 32768

B.

Redirect debug output to file; Use fw ctl zdebug –o ./debug.elg

C.

Increase debug buffer; Use fw ctl zdebug –buf 32768

D.

Redirect debug output to file; Use fw ctl debug –o ./debug.elg

Question 12

What is the name of the table that an administrator would review to investigate a port exhaustion error when using Hide NAT?

Options:

A.

dyn_nat_table

B.

connection

C.

nat_dyn_table

D.

fwx_alloc

Question 13

Static NAT has been configured and NAT rules were created automatically. The global properties option “Translate destination on client side” is not checked. Clients are complaining that they are not able to connect to one of your web servers using its public address. How would you solve the problem without changing the global properties and reinstalling the security policy?

Options:

A.

On the security gateway, add a static route for the web server’s public ip address

B.

Rebooting the security gateway will resolve the problem

C.

You will have the global properties and reinstall the security policy

D.

Configure manual NAT

Question 14

Where does the translation occur with Hide NAT?

Options:

A.

The destination translation occurs at the client side

B.

The source translation occurs at the server side

C.

The source translation occurs at the client side

D.

The destination translation occurs at the server side

Question 15

Where will the usermode core files located?

Options:

A.

/var/log/dump/usermode

B.

/var/suroot

C.

$FWDIR/var/log/dump/usermode

D.

$CPDIR/var/log/dump/usermode

Question 16

Fill in the blank: The commandprovides the most complete restoration of a R80 configuration.

Options:

A.

upgrade_import

B.

cpconfig

C.

fwm dbimport –p

D.

cpinfo -recover

Question 17

Which of the following features is supported in Check Point’s implementation of IPv6?

Options:

A.

Security Servers

B.

QoS

C.

ClusterXL High Availability

D.

SAM

Question 18

Which of the following is NOT a special consideration while running fw monitor on production firewall?

Options:

A.

While executing fw monitor, you need to specify an expression so that it captures the required traffic instead of all traffic

B.

While running fw monitor on a busy firewall, the –ci and –co switches can be used to limit the number of packets captured

C.

While running fw monitor, it resets all the debug flags

D.

During a fw monitor, the firewall will have to process more packets because SecureXL acceleration should be disabled

Question 19

Consider an IKE debug file that has been generated when debugging an issue with site to site VPN. What is the purpose of a NONCE?

Options:

A.

Randomly generated part of key generation

B.

Vendor ID and Remote Gateway ID

C.

Protocol 50 and 51 representations

D.

Fixed hex value of Phase 2 keys with PFS

Question 20

What is the command to check the number of CoreXL firewall instances?

Options:

A.

show corexl stat

B.

fw ctl multik stat

C.

coreXL_admin stat

D.

fw ctl corexl stats

Question 21

After determining that the IPS Blade is causing high resource utilization in the gateway, which would be an appropriate strategy to improve IPS performance?

Options:

A.

Enabling CoreXL

B.

Enable Bypass mode

C.

Disabling SecureXL

D.

Enabling SecureXL

Question 22

If you are experiencing performance issues on a gateway and you suspect it may be related to the interfaces, what command will assist in determining if packets are not being received into the gateway?

Options:

A.

netstat –rn

B.

show arp dynamic all

C.

ifconfig -a and look for RX drops

D.

ifconfig –a and look for TX drops

Question 23

Which of the following is NOT a feature of ClusterXL?

Options:

A.

Transparent upgrades

B.

Zero downtime for mission-critical environments with State Synchronization

C.

Enhanced throughput in all ClusterXL modes (2 gateway cluster compared with 1 gateway)

D.

Transparent failover in case of device failures

Page: 1 / 6
Total 159 questions