[Aug 31, 2021] 156-915.80 Ultimate Study Guide - Pass4training [Q267-Q287]

Share

[Aug 31, 2021] 156-915.80 Ultimate Study Guide -  Pass4training

Ultimate Guide to Prepare 156-915.80 Certification Exam for CCSE Update in 2021

NEW QUESTION 267
How could you compare the Fingerprint shown to the Fingerprint on the server?
Exhibit:

  • A. Run sysconfig, select the Server Fingerprint option and view the fingerprint
  • B. Run cpconfig, select the GUI Clients option and view the fingerprint
  • C. Run cpconfig, select the Certificate's Fingerprint option and view the fingerprint
  • D. Run cpconfig, select the Certificate Authority option and view the fingerprint

Answer: C

 

NEW QUESTION 268
Which of the following are authentication methods that Security Gateway R80 uses to validate connection attempts? Select the response below that includes the MOST complete list of valid authentication methods.

  • A. Connection, User, Client
  • B. Proxied, User, Dynamic, Session
  • C. User, Proxied, Session
  • D. User, Client, Session

Answer: D

 

NEW QUESTION 269
Fill in the blank.

In Load Sharing Unicast mode, the internal cluster IP address is 10.4.8.3.
The internal interfaces on two members are 10.4.8.1 and 10.4.8.2.
Internal host 10.4.8.108 Pings 10.4.8.3, and receives replies.
The following is the ARP table from the internal Windows host 10.4.8.108.
Review the exhibit and type the IP address of the member serving as the pivot machine in the space below.

Answer:

Explanation:
10.4.8.2

 

NEW QUESTION 270
Jack has finished building his new SMS server, Red, on new hardware. He used SCP to move over the Redold.tgz export of his old SMS server. What is the command he will use to import this into the new server?

  • A. Expert@Red# ./upgrade import Red-old.tgz
  • B. Expert@Red# ./migrate import Red-old.tgz
  • C. Red> ./upgrade import Red-old.tgz
  • D. Red> ./migrate import Red-old.tgz

Answer: D

Explanation:
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Installation_and_Upgrade_GuidewebAdmin/
16535.htm

 

NEW QUESTION 271
For Management High Availability, which of the following is NOT a valid synchronization status?

  • A. Never been synchronized
  • B. Lagging
  • C. Down
  • D. Collision

Answer: C

 

NEW QUESTION 272
For interfaces can you configure to use the Multi-Queue
a valid synchronization status?

  • A. Never been synchronized
  • B. Lagging
  • C. Down
  • D. Collision

Answer: C

 

NEW QUESTION 273
When using GAiA, it might be necessary to temporarily change the MAC address of the interface eth 0 to
00:0C:29:12:34:56. After restarting the network the old MAC address should be active. How do you configure this change?

  • A. Option A
  • B. Option D
  • C. Option B
  • D. Option C

Answer: A

 

NEW QUESTION 274
Assume you are a Security Administrator for ABCTech. You have allowed authenticated access to users from Mkting_net to Finance_net. But in the user's properties, connections are only permitted within Mkting_net. What is the BEST way to resolve this conflict?

  • A. Select Intersect with user database or Ignore Database in the Action Properties window.
  • B. Permit access to Finance_net.
  • C. Select Intersect with user database in the Action Properties window.
  • D. Select Ignore Database in the Action Properties window.

Answer: A

 

NEW QUESTION 275
In Threat Prevention, you can create new or clone profiles but you CANNOT change the out-of-the-box profiles of:

  • A. General, purposed, Strict
  • B. General, Escalation, Severe
  • C. Basic, Optimized, Strict
  • D. Basic, Optimized, Severe

Answer: C

Explanation:
Explanation/Reference:
Reference: https://sc1.checkpoint.com/documents/R80/CP_R80BC_ThreatPrevention/html_frameset.htm?
topic=documents/R80/CP_R80BC_ThreatPrevention/136486

 

NEW QUESTION 276
Which packet info is ignored with Session Rate Acceleration?

  • A. same info from Packet Acceleration is used
  • B. source ip
  • C. source port
  • D. source port ranges

Answer: C

Explanation:
Section: (none)
Explanation/Reference:
Reference: http://trlj.blogspot.com/2015/10/check-point-acceleration.html

 

NEW QUESTION 277
Before upgrading SecurePlatform to GAiA, you should create a backup. To save time, many administrators use the command backup. This creates a backup of the Check Point configuration as well as the system configuration.
An administrator has installed the latest HFA on the system for fixing traffic problem after creating a backup file. There is a mistake in the very complex static routing configuration. The Check Point configuration has not been changed. Can the administrator use a restore to fix the errors in static routing?

  • A. The restore is done by selecting Snapshot Management from the boot menu of GAiA.
  • B. A backup cannot be restored, because the binary files are missing.
  • C. The restore is not possible because the backup file does not have the same build number (version).
  • D. The restore can be done easily by the command restore and copying netconf.C from the production environment.

Answer: D

 

NEW QUESTION 278
Firewall policies must be configured to accept VRRP packets on the GAiA platform if it runs Firewall software. The Multicast destination assigned by the Internet Assigned Numbers Authority (IANA) for VRRP is:

  • A. 224.0.0.18
  • B. 224.0.0.5
  • C. 224.0.0.102
  • D. 224.0.0.22

Answer: A

Explanation:
Section: (none)
Explanation/Reference:
Reference: https://www.iana.org/assignments/multicast-addresses/multicast-addresses.xhtml

 

NEW QUESTION 279
When simulating a problem on CLusterXL cluster with cphaprob -d STOP -s problem -t 0 register, to initiate a failover on an active cluster member, what command allows you remove the problematic state?

  • A. cphaprob -d STOP unregister
  • B. cphaprob -d unregister STOP
  • C. cphaprob unregister STOP
  • D. cphaprob STOP unregister

Answer: A

Explanation:
Explanation
esting a failover in a controlled manner using following command;
# cphaprob -d STOP -s problem -t 0 register
This will register a problem state on the cluster member this was entered on;If you then run;
# cphaprob list
this will show an entry named STOP.
to remove this problematic register run following;
# cphaprob -d STOP unregister
References:

 

NEW QUESTION 280
Fill in the blank. To verify that a VPN Tunnel is properly established, use the command _________?

Answer:

Explanation:
vpn tunnelutil

 

NEW QUESTION 281
Paul has just joined the MegaCorp security administration team. Natalie, the administrator, creates a new administrator account for Paul in SmartDashboard and installs the policy. When Paul tries to login it fails.
How can Natalie verify whether Paul's IP address is predefined on the security management server?

  • A. Login to Smart Dashboard, access Properties of the SMS, and verify whether Paul's IP address is listed.
  • B. Type cpconfig on the Management Server and select the option "GUI client List" to see if Paul's IP address is listed.
  • C. Login in to Smart Dashboard, access Global Properties, and select Security Management, to verify whether Paul's IP address is listed.
  • D. Access the WEBUI on the Security Gateway, and verify whether Paul's IP address is listed as a GUI client.

Answer: B

 

NEW QUESTION 282
CORRECT TEXT
Fill in the blank with a numeric value. The default port number for Secure Sockets Layer (SSL) connections with the LDAP Server is

Answer:

Explanation:
636

 

NEW QUESTION 283
You are investigating issues with two gateway cluster members that are not able to establish the first initial cluster synchronization. What service is used by the FWD daemon to do a Full Synchronization?

  • A. TCP port 256
  • B. UDP port 8116
  • C. TCP port 443
  • D. TCP port 257

Answer: A

Explanation:
Synchronization works in two modes:
Full sync transfers all Security Gateway kernel table information from one cluster member to another. It is handled by the fwd daemon using an encrypted TCP connection.
Delta sync transfers changes in the kernel tables between cluster members. Delta sync is handled by the Security Gateway kernel using UDP multicast or broadcast on port 8116.
Full sync is used for initial transfers of state information, for many thousands of connections. If a cluster member is brought up after being down, it will perform full sync. After all members are synchronized, only updates are transferred via delta sync. Delta sync is quicker than full sync.

 

NEW QUESTION 284
You are running a R80 Security Gateway on GAiA.
In case of a hardware failure, you have a server with the exact same hardware and firewall version installed. What back up method could be used to quickly put the secondary firewall into production?

  • A. backup
  • B. upgrade_export
  • C. snapshot
  • D. manual backup

Answer: C

 

NEW QUESTION 285
Which statements below are CORRECT regarding Threat Prevention profiles in SmartConsole?

  • A. You can assign only one profile pre gateway and a profile can be assigned to one or more rules.
  • B. You can assign multiple profiles per gateway and a profile can be assigned to one or more rules.
  • C. You can assign only one profile per gateway and a profile can be assigned to one rule Only.
  • D. You can assign multiple profiles per gateway and a profile can be assigned to one rule only.

Answer: B

 

NEW QUESTION 286
What is the most ideal Synchronization Status for Security Management Server High Availability deployment?

  • A. Never been synchronized
  • B. Lagging
  • C. Synchronized
  • D. Collision

Answer: C

Explanation:
Explanation
The possible synchronization statuses are:
* Never been synchronized - immediately after the Secondary Security Management server has been installed, it has not yet undergone the first manual synchronization that brings it up to date with the Primary Security Management server.
* Synchronized - the peer is properly synchronized and has the same database information and installed Security Policy.
* Lagging - the peer SMS has not been synchronized properly.
For instance, on account of the fact that the Active SMS has undergone changes since the previous synchronization (objects have been edited, or the Security Policy has been newly installed), the information on the Standby SMS is lagging.
* Advanced - the peer SMS is more up-to-date.
For instance, in the above figure, if a system administrators logs into Security Management server B before it has been synchronized with the Security Management server A, the status of the Security Management server A is Advanced, since it contains more up-to-date information which the former does not have.
In this case, manual synchronization must be initiated by the system administrator by changing the Active SMS to a Standby SMS. Perform a synch me operation from the more advanced server to the Standby SMS.
Change the Standby SMS to the Active SMS.
* Collision - the Active SMS and its peer have different installed policies and databases. The administrator must perform manual synchronization and decide which of the SMSs to overwrite.

 

NEW QUESTION 287
......

CCSE Update Fundamentals-156-915.80 Exam-Practice-Dumps: https://www.pass4training.com/156-915.80-pass-exam-training.html