[Nov 25, 2021] Verified 156-215.80 dumps and 525 unique questions [Q159-Q179]

Share

[Nov 25, 2021] Verified 156-215.80 dumps and 525 unique questions

156-215.80 Dumps for Pass Guaranteed - Pass 156-215.80 Exam 2021


How much 156-215.80 Exam Cost

The price of the 156-215.80 exam is $250 USD.

 

NEW QUESTION 159
Fill in the blank: When LDAP is integrated with Check Point Security Management, it is then referred to as
_______

  • A. User Directory
  • B. UserCheck
  • C. User Center
  • D. User Administration

Answer: A

Explanation:
Explanation/Reference:
Explanation: Check Point User Directory integrates LDAP, and other external user management technologies, with the Check Point solution. If you have a large user count, we recommend that you use an external user management database such as LDAP for enhanced Security Management Server performance.
Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SecMGMT/html_frameset.htm?
topic=documents/R80/CP_R80_SecMGMT/118981

 

NEW QUESTION 160
Which of the following are types of VPN communities?

  • A. Star, octagon, and combination
  • B. Pentagon, star, and combination
  • C. Combined and star
  • D. Meshed, star, and combination

Answer: D

Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm?
topic=documents/R77/CP_R77_VPN_AdminGuide/13894

 

NEW QUESTION 161
Which information is included in the "Full Log" tracking option, but is not included in the "Log" tracking option?

  • A. file attributes
  • B. application information
  • C. destination port
  • D. data type information

Answer: D

 

NEW QUESTION 162
What is the BEST method to deploy Identity Awareness for roaming users?

  • A. Use captive portal
  • B. Use Office Mode
  • C. Use identity agents
  • D. Share user identities between gateways

Answer: C

Explanation:
Using Endpoint Identity Agents give you:
* User and machine identity
* Minimal user intervention - all necessary configuration is done by administrators and does not require user input.
* Seamless connectivity - transparent authentication using Kerberos Single Sign-On (SSO) when users are logged in to the domain. If you do not want to use SSO, users enter their credentials manually. You can let them save these credentials.
* Connectivity through roaming - users stay automatically identified when they move between networks, as the client detects the movement and reconnects.
Reference: https://www.checkpoint.com/products/identity-awareness-software-blade/

 

NEW QUESTION 163
Fill in the blank: Browser-based Authentication sends users to a web page to acquire identities using ________ .

  • A. UserCheck
  • B. Captive Portaland Transparent Kerberos Authentication
  • C. User Directory
  • D. Captive Portal

Answer: B

Explanation:
To enable Identity Awareness:
The Identity Awareness Configuration wizard opens.

 

NEW QUESTION 164
Fill in the blank: Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or__________.

  • A. On all satellite gateway to satellite gateway tunnels
  • B. On specific tunnels in the community
  • C. On specific satellite gateway to central gateway tunnels
  • D. On specific tunnels for specific gateways

Answer: B

Explanation:
Each VPN tunnel in the community may be set to be a Permanent Tunnel. Since Permanent Tunnels are constantly monitored, if the VPN tunnel is down, then a log, alert, or user defined action, can be issued. A VPN tunnel is monitored by periodically sending "tunnel test" packets. As long as responses to the packets are received the VPN tunnel is considered "up." If no response is received within a given time period, the VPN tunnel is considered "down." Permanent Tunnels can only be established between Check Point Security Gateways. The configuration of Permanent Tunnels takes place on the community level and:

 

NEW QUESTION 165
Ken wants to obtain a configuration lock from other administrator on R80 Security
Management Server. He can do this via WebUI or a via CLI. Which command should be use in CLI? Choose the correct answer.

  • A. The database feature has two commands: lock database override and unlock database.
    Both will work.
  • B. remove database lock
  • C. The database feature has onecommandlock database override.
  • D. override database lock

Answer: A

Explanation:
Use the database feature to obtain the configuration lock. The databasefeature has two commands:
The commands do the same thing: obtain the configuration lock from another administrator.
Description
Use the lock database override and unlock database commands to get exclusiveread-write access to the database by taking write privileges to the database away from other administrators logged into the system.
Syntax

 

NEW QUESTION 166
What are the three tabs available in SmartView Tracker?

  • A. Endpoint, Active, and Custom Queries
  • B. Network & Endpoint, Management, and Active
  • C. Network, Endpoint, and Active
  • D. Predefined, All Records, Custom Queries

Answer: D

 

NEW QUESTION 167
The organization's security manager wishes to back up just the Gaia operating system parameters such as interface details, Static routes and Proxy ARP entries. Which command would be BEST suited to accomplish this task?

  • A. upgrade export
  • B. migrate export
  • C. save configuration
  • D. backup

Answer: D

Explanation:
System Backup (and System Restore)
System Backup can be used to backup current system configuration. A backup creates a compressed file that contains the Check Point configuration including the networking and operating system parameters, such as routing and interface configuration etc., but unlike a snapshot, it does not include the operating system, product binaries, and hotfixes.
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk108902

 

NEW QUESTION 168
The IT Management team is interested in the new features of the Check Point R80 Management and wants to upgrade but they are concerned that the existing R77.30 Gaia Gateways cannot be managed by R80 because it is so different. As the administrator responsible for the Firewalls, how can you answer or confirm these concerns?

  • A. R80 Management contains compatibility packages for managing earlier versions of Check Point Gateways prior to R80. Consult the R80 Release Notes for more information.
  • B. R80 Management requires the separate installation of compatibility hotfix packages for managing the earlier versions of Check Point Gateways prior to R80. Consult the R80 Release Notes for more information.
  • C. R80 Management was designed as a completely different Management system and so can only monitor Check Point Gateways prior to R80.
  • D. R80 Management cannot manage earlier versions of Check Point Gateways prior to R80. Only R80 and above Gateways can be managed. Consult the R80 Release Notes for more information.

Answer: A

Explanation:
Explanation/Reference:
Explanation:

Reference: http://dl3.checkpoint.com/paid/1f/1f7e21da67aa992954aa12a0a84e53a8/ CP_R80_ReleaseNotes.pdf?HashKey=1479838085_d6ffcb36c6a3128708b3f6d7bcc4f94e&xtn=.pdf

 

NEW QUESTION 169
A ____ license requires an administrator to designate a gateway for attachment whereas a _____ license is automatically attached to a Security Gateway.

  • A. Local; formal
  • B. Formal; corporate
  • C. Central; local
  • D. Local; central

Answer: C

 

NEW QUESTION 170
Review the rules. Assume domain UDP is enabled in the implied rules.

What happens when a user from the internal network tries to browse to the internet using HTTP? The user:

  • A. is prompted three times before connecting to the Internet successfully.
  • B. can connect to the Internet successfully after being authenticated.
  • C. can go to the Internet after Telnetting to the client authentication daemon port 259.
  • D. can go to the Internet, without being prompted for authentication.

Answer: D

 

NEW QUESTION 171
How is communication between different Check Point components secured in R80?

  • A. By using ICA
  • B. By using IPSEC
  • C. By using SIC
  • D. By using 3DES

Answer: C

Explanation:
Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SecMGMT/html_frameset.htm?topic=documents/R80/CP_R80_SecMGMT/125443

 

NEW QUESTION 172
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?

  • A. Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores
  • B. Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway | Install Security Policy
  • C. Go to clash-Run cpstop | Run cpstart
  • D. Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway

Answer: D

Explanation:
Explanation/Reference:

 

NEW QUESTION 173
Which of the following is NOT a license activation method?

  • A. Online Activation
  • B. SmartConsole Wizard
  • C. License Activation Wizard
  • D. Offline Activation

Answer: B

 

NEW QUESTION 174
Which of the following Automatically Generated Rules NAT rules have the lowest implementation priority?

  • A. Machine Static NAT
  • B. Network Hide NAT
  • C. Address Range Hide NAT
  • D. Machine Hide NAT

Answer: B,C

Explanation:
Explanation/Reference:
Explanation:
SmartDashboard organizes the automatic NAT rules in this order:
1. Static NAT rules for Firewall, or node (computer or server) objects
2. Hide NAT rules for Firewall, or node objects
3. Static NAT rules for network or address range objects
4. Hide NAT rules for network or address range objects
Reference:
https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_WebAdmin/6724.htm

 

NEW QUESTION 175
What is Identity Sharing?

  • A. Users can share identities with other users
  • B. Security Gateways can acquire and share identities with other Security Gateways
  • C. Administrators can share identifies with other administrators
  • D. Management servers can acquire and share identities with Security Gateways

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Identity Sharing
Best Practice - In environments that use many Security Gateways and AD Query, we recommend that you set only one Security Gateway to acquire identities from a given Active Directory domain controller for each physical site. If more than one Security Gateway gets identities from the same AD server, the AD server can become overloaded with WMI queries.
Set these options on the Identity Awareness > Identity Sharing page of the Security Gateway object:
One Security Gateway to share identities with other Security Gateways. This is the Security Gateway

that gets identities from a given domain controller.
All other Security Gateways to get identities from the Security Gateway that acquires identities from the

given domain controller.
Reference:
https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/
CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.10/ WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/63005

 

NEW QUESTION 176
One of major features in R80 SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB and AdminC are editing the same Security Policy?

  • A. A lock icon shows that a rule or an object is locked and will be available.
  • B. AdminA and AdminB are editing the same rule at the same time.
  • C. AdminA, AdminB and AdminC are editing three different rules at the same time.
  • D. A lock icon next to a rule informs that any Administrator is working on this particular rule.

Answer: C

 

NEW QUESTION 177
Packet acceleration (SecureXL) identifies connections by several attributes. Which of the attributes is NOT used for identifying connection?

  • A. TCP Acknowledgment Number
  • B. Source Port
  • C. Source Address
  • D. Destination Address

Answer: A

Explanation:
Reference:
https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_WebAdmin/92711.htm

 

NEW QUESTION 178
Which of the following is NOT an option for internal network definition of Anti-spoofing?

  • A. Specific - derived from a selected object
  • B. Route-based - derived from gateway routing table
  • C. Not-defined
  • D. Network defined by the interface IP and Net Mask

Answer: B

 

NEW QUESTION 179
......

Latest 100% Passing Guarantee - Brilliant 156-215.80 Exam Questions PDF: https://www.dumps4pdf.com/156-215.80-valid-braindumps.html

156-215.80 Exam Dumps - Try Best 156-215.80 Exam Questions: https://drive.google.com/open?id=1fh7rGDNu-ySwjjNh9XwaWDy_lJ8Ae_9V