
Best Quality CheckPoint 156-315.80 Exam Questions VCEEngine Realistic Practice Exams [2021]
Critical Information To Check Point Certified Security Expert - R80 Pass the First Time
NEW QUESTION 188
What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL Filtering, Anti-Virus, IPS, and Threat Emulation?
- A. Anti-Bot is the only protection mechanism which starts a counter-attack against known Command & Control Centers
- B. Anti-Bot is the only signature-based method of malware protection.
- C. Anti-Bot is the only countermeasure against unknown malware
- D. Anti-Bot is a post-infection malware protection to prevent a host from establishing a connection to a Command & Control Center.
Answer: D
NEW QUESTION 189
You want to gather and analyze threats to your mobile device. It has to be a lightweight app. Which
application would you use?
- A. Check Point Protect
- B. SecuRemote
- C. Check Point Capsule Cloud
- D. SmartEvent Client Info
Answer: A
NEW QUESTION 190
The Firewall kernel is replicated multiple times, therefore:
- A. The Firewall can run the same policy on all cores.
On a Security Gateway with CoreXL enabled, the Firewall kernel is replicated multiple times. Each replicated copy, or instance, runs on one processing core. These instances handle traffic concurrently, and each instance is a complete and independent inspection kernel. When CoreXL is enabled, all the kernel instances in the Security Gateway process traffic through the same interfaces and apply the same security policy. - B. The Firewall kernel only touches the packet if the connection is accelerated
- C. The Firewall kernel is replicated only with new connections and deletes itself once the connection times out
- D. The Firewall can run different policies per core
Answer: A
NEW QUESTION 191
Tom has been tasked to install Check Point R80 in a distributed deployment. Before Tom installs the systems this way, how many machines will he need if he does NOT include a SmartConsole machine in his calculations?
- A. One machine
- B. Three machines
- C. Two machines
- D. One machine, but it needs to be installed using SecurePlatform for compatibility purposes.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
One for Security Management Server and the other one for the Security Gateway.
NEW QUESTION 192
When using CPSTAT, what is the default port used by the AMON server?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION 193
Which features are only supported with R80.10 Gateways but not R77.x?
- A. Time object to a rule to make the rule active only during specified times.
- B. Access Control policy unifies the Firewall, Application Control & URL Filtering, Data Awareness, and
Mobile Access Software Blade policies - C. The rule base can be built of layers, each containing a set of the security rules. Layers are inspected in
the order in which they are defined, allowing control over the rule base flow and which security
functionalities take precedence. - D. Limits the upload and download throughput for streaming media in the company to 1 Gbps.
Answer: C
NEW QUESTION 194
Which pre-defined Permission Profile should be assigned to an administrator that requires full access to audit all configurations without modifying them?
- A. Full Access
- B. Super User
- C. Read Only All
- D. Auditor
Answer: C
Explanation:
References:
NEW QUESTION 195
Which command would you use to set the network interfaces' affinity in Manual mode?
- A. sim affinity -a
- B. sim affinity -l
- C. sim affinity -s
- D. sim affinity -m
Answer: C
NEW QUESTION 196
In SmartConsole, objects are used to represent physical and virtual network components and also some logical components. These objects are divided into several categories. Which of the following is NOT an objects category?
- A. Network Object
- B. Limit
- C. Resource
- D. Custom Application / Site
Answer: C
Explanation:
References:
NEW QUESTION 197
Automatic affinity means that if SecureXL is running, the affinity for each interface is automatically reset
every
- A. 60 sec
- B. 15 sec
- C. 30 sec
- D. 5 sec
Answer: A
NEW QUESTION 198
SecureXL improves non-encrypted firewall traffic throughput and encrypted VPN traffic throughput.
- A. This statement is true because SecureXL does improve this traffic.
- B. This statement is false because SecureXL does not improve this traffic but CoreXL does.
- C. This statement is false because encrypted traffic cannot be inspected.
SecureXL improved non-encrypted firewall traffic throughput, and encrypted VPN traffic throughput, by nearly an order-of-magnitude- particularly for small packets flowing in long duration connections. - D. This statement is true because SecureXL does improve all traffic.
Answer: A
NEW QUESTION 199
What is considered Hybrid Emulation Mode?
- A. Load sharing between OS behavior and CPU Level emulation.
- B. Load sharing of emulation between an on premise appliance and the cloud.
- C. High availability between the local SandBlast appliance and the cloud.
- D. Manual configuration of file types on emulation location.
Answer: B
NEW QUESTION 200
Which Remote Access Client does not provide an Office-Mode Address?
- A. Endpoint Security VPN
- B. SecuRemote
- C. Check Point Mobile
- D. Endpoint Security Suite
Answer: B
Explanation:
References:
NEW QUESTION 201
Pamela is Cyber Security Engineer working for Global Instance Firm with large scale deployment of Check Point Enterprise Appliances using GAiA/R80.10. Company's Developer Team is having random access issue to newly deployed Application Server in DMZ's Application Server Farm Tier and blames DMZ Security Gateway as root cause. The ticket has been created and issue is at Pamela's desk for an investigation.
Pamela decides to use Check Point's Packet Analyzer Tool-fw monitor to iron out the issue during approved Maintenance window.
What do you recommend as the best suggestion for Pamela to make sure she successfully captures entire traffic in context of Firewall and problematic traffic?
- A. Pamela should check SecureXL status on DMZ Security Gateway and if it's turned OFF. She should turn ON SecureXL before using fw monitor to avoid misleading traffic captures.
- B. Pamela should use tcpdump over fw monitor tool as tcpdump works at OS-level and captures entire traffic.
- C. Pamela should check SecureXL status on DMZ Security gateway and if it's turned ON. She should turn OFF SecureXL before using fw monitor to avoid misleading traffic captures.
- D. Pamela should use snoop over fw monitor tool as snoop works at NIC driver level and captures entire traffic.
Answer: C
NEW QUESTION 202
What are different command sources that allow you to communication with the API server?
- A. SmartConsole GUI Console,MGMT_Cli Tool,Gala CLI, Web Services
- B. API_cli Tool Gala CLI, Web Services
- C. SmartView Monoter, API_cli Tool, Gala CLI. Web Services
- D. SmartConsole GUI Console API Console _cli Tool,CLI,Web Services
Answer: A
NEW QUESTION 203
Automatic affinity means that if SecureXL is running, the affinity for each interface is automatically reset every
- A. 60 sec
- B. 15 sec
- C. 30 sec
- D. 5 sec
Answer: A
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_PerformanceTuning_WebAdmin/6731.htm
NEW QUESTION 204
Fill in the blank: The R80 utilityfw monitoris used to troubleshoot ________.
- A. Phase two key negotiations
- B. Traffic issues
- C. LDAP conflicts
- D. User data base corruption
Answer: B
Explanation:
Check Point's FW Monitor is a powerful built-in tool for capturing network traffic at the packet level. The FW Monitor utility captures network packets at multiple capture points along the FireWall inspection chains. These captured packets can be inspected later using the WireShark Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk30583
NEW QUESTION 205
Which command collects diagnostic data for analyzing customer setup remotely?
- A. cpinfo
- B. sysinfo
- C. cpview
- D. migrate export
Answer: A
Explanation:
CPInfo is an auto-updatable utility that collects diagnostics data on a customer's machine at the time of execution and uploads it to Check Point servers (it replaces the standalone cp_uploader utility for uploading files to Check Point servers).
The CPInfo output file allows analyzing customer setups from a remote location. Check Point support engineers can open the CPInfo file in a demo mode, while viewing actual customer Security Policies and Objects. This allows the in-depth analysis of customer's configuration and environment settings.
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739
NEW QUESTION 206
The Firewall kernel is replicated multiple times, therefore:
- A. The Firewall kernel only touches the packet if the connection is accelerated
- B. The Firewall kernel is replicated only with new connections and deletes itself once the connection times out
- C. The Firewall can run the same policy on all cores.
- D. The Firewall can run different policies per core
Answer: C
Explanation:
On a Security Gateway with CoreXL enabled, the Firewall kernel is replicated multiple times. Each replicated copy, or instance, runs on one processing core. These instances handle traffic concurrently, and each instance is a complete and independent inspection kernel. When CoreXL is enabled, all the kernel instances in the Security Gateway process traffic through the same interfaces and apply the same security policy.
NEW QUESTION 207
Which feature is NOT provided by all Check Point Mobile Access solutions?
- A. Support for IPv6
- B. Secure connectivity
- C. Strong user authentication
- D. Granular access control
Answer: A
NEW QUESTION 208
......
156-315.80 EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.vceengine.com/156-315.80-vce-test-engine.html
Best Quality CheckPoint 156-315.80 Exam Questions: https://drive.google.com/open?id=1cF2_ygtrU3MXLl9ZW2_qWLLfDxy68dUt
