[Oct 25, 2022] 156-215.80 PDF Dumps is essential on your 156-215.80 Exam Questions Certain Success!
156-215.80 PDF Questions - Perfect Prospect To Go With 156-215.80 Practice Exam
Certification Path
The Check Point Certified Security Administrator (CCSA R80) 156-215.80 Exam certification path includes only one 156-215.80 certification exam.
Ideal Audience
The Check Point Certified Security Administrator (CCSA) certificate targets administrators tasked with managing and maintaining the day to day operations of the Check Point systems and products. Thus, it is the most suitable option for the following groups:
- System Administrators;
- Network Engineers;
- Firewall Analysts;
- Security Managers;
- All individuals eyeing the CCSA certification.
NEW QUESTION 176
Web Control Layer has been set up using the settings in the following dialogue:
Consider the following policy and select the BEST answer.
- A. Anyone from internal network can access the internet, expect the traffic defined in drop rules 5.2, 5.5 and
5.6. - B. Access to Youtube and Vimeo is allowed only once a day.
- C. Traffic that does not match any rule in the subpolicy is dropped.
- D. All employees can access only Youtube and Vimeo.
Answer: A
Explanation:
Policy Layers and Sub-Policies
R80 introduces the concept of layers and sub-policies, allowing you to segment your policy according to your network segments or business units/functions. In addition, you can also assign granular privileges by layer or sub-policy to distribute workload and tasks to the most qualified administrators
* With layers, the rule base is organized into a set of security rules. These set of rules or layers, are inspected in the order in which they are defined, allowing control over the rule base flow and the security functionalities that take precedence. If an "accept" action is performed across a layer, the inspection will continue to the next layer. For example, a compliance layer can be created to overlay across a cross- section of rules.
* Sub-policies are sets of rules that are created for a specific network segment, branch office or business unit, so if a rule is matched, inspection will continue through this subset of rules before it moves on to the next rule.
* Sub-policies and layers can be managed by specific administrators, according to their permissions profiles.
This facilitates task delegation and workload distribution.
Reference: https://community.checkpoint.com/docs/DOC-1065
NEW QUESTION 177
Which of the following is NOT a back up method?
- A. System backup
- B. snapshot
- C. Save backup
- D. Migrate
Answer: C
Explanation:
Explanation
The built-in Gaia backup procedures:
Check Point provides three different procedures for backing up (and restoring) the operating system and
networking parameters on your appliances.
NEW QUESTION 178
In R80 Management, apart from using SmartConsole, objects or rules can also be modified using:
- A. 3rd Party integration of CLI and API for Gateways prior to R80.
- B. A complete CLI and API interface for Management with 3rd Party integration.
- C. 3rd Party integration of CLI and API for Management prior to R80.
- D. A complete CLI and API interface using SSH and custom CPCode integration.
Answer: D
NEW QUESTION 179
On the following picture an administrator configures Identity Awareness:
After clicking "Next" the above configuration is supported by:
- A. Obligatory usage of Captive Portal
- B. The ports 443 or 80 what will be used by Browser-Based and configured Authentication
- C. Kerberos SSO which will be working for Active Directory integration
- D. Based on Active Directory integration which allows the Security Gateway to correlate Active Directory users and machines to IP addresses in a method that is completely transparent to the user
Answer: D
Explanation:
Explanation
To enable Identity Awareness:
Log in to R80 SmartConsole.
From the Gateways & Servers view, double-click the Security Gateway on which to enable Identity Awareness.
On the Network Security tab, select
The Identity Awareness Configuration wizard opens.
Select one or more options. These options set the methods for acquiring identities of managed and unmanaged assets.
AD Query - Lets the Security Gateway seamlessly identify Active Directory users and computers.
Browser-Based Authentication - Sends users to a Web page to acquire identities from unidentified users. If Transparent Kerberos Authentication is configured, AD users may be identified transparently.
Terminal Servers - Identify users in a Terminal Server environment (originating from one IP address).
NEW QUESTION 180
In order to modify Security Policies the administrator can use which of the following tools?
Select the BEST answer.
- A. mgmt_cli or WebUI on Security Gateway and SmartConsole on the Security
Management Server. - B. SmartConsole or mgmt_cli on any computer where SmartConsole is installed.
- C. SmartConsole and WebUI on the Security Management Server.
- D. Command line of the Security Management Server or mgmt_cli.exe on any Windows computer.
Answer: B
NEW QUESTION 181
Review the following screenshot and select the BEST answer.
- A. Data Center Layer is an inline layer in the Access Control Policy.
- B. If a connection is dropped in Network Layer, it will not be matched against the rules in Data Center Layer.
- C. By default all layers are shared with all policies.
- D. If a connection is accepted in Network-layer, it will not be matched against the rules in Data Center Layer.
Answer: B
NEW QUESTION 182
SmartEvent does NOT use which of the following procedures to identity events:
- A. Matching a log against global exclusions
- B. Create an event candidate
- C. Matching a log against local exclusions
- D. Matching a log against each event definition
Answer: C
NEW QUESTION 183
Which configuration element determines which traffic should be encrypted into a VPN tunnel vs. sent in the
clear?
- A. The Rule Base
- B. The firewall topologies
- C. The VPN Domains
- D. NAT Rules
Answer: A
NEW QUESTION 184
What data MUST be supplied to the SmartConsole System Restore window to restore a backup?
- A. Server, Protocol, Username, Password, Path
- B. Username, Password, Path, Version
- C. Server, Username, Password, Path, Version
- D. Server, Protocol, Username, Password, Destination Path
Answer: A
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SmartDashboard_OLH/html_frameset.htm?
topic=documents/R80/CP_R80_SmartDashboard_OLH/ud_B7RJG2xrUQywsBK5buA2
NEW QUESTION 185
Fill in the blank: An identity server uses a ___________ for user authentication.
- A. Certificate
- B. Shared secret
- C. One-time password
- D. Token
Answer: B
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_IdentityAwareness_AdminGuide/62050.htm
NEW QUESTION 186
Which R80 GUI would you use to see the number of packets accepted since the last policy install?
- A. SmartView Tracker
- B. SmartView Monitor
- C. SmartDashboard
- D. SmartView Status
Answer: B
NEW QUESTION 187
There are 4 ways to use the Management API for creating host object with R80 Management API. Which one is NOT correct?
- A. Using CLISH
- B. Using SmartConsole GUI console
- C. Using Web Services
- D. Using Mgmt_cli tool
Answer: A
Explanation:
Explanation/Reference: http://dl3.checkpoint.com/paid/29/29532b9eec50d0a947719ae631f640d0/ CP_R80_CheckPoint_API_ReferenceGuide.pdf?
HashKey=1517088487_4c0acda205460a92f44c83d399826a7b&xtn=.pdf
NEW QUESTION 188
If there is an Accept Implied Policy set to "First", what is the reason Jorge cannot see any logs?
- A. Log Implied Rule was not selected on GlobalProperties.
- B. Track log column is set to Log instead of Full Log.
- C. Track log column is set to none.
- D. Log Implied Rule was not set correctly on the track column on the rules base.
Answer: A
Explanation:
Implied Rules are configured only on Global Properties.
NEW QUESTION 189
What is the SOLR database for?
- A. Enables powerful matching capabilities and writes data to the database
- B. Used for full text search and enables powerful matching capabilities
- C. Writes data to the database and full text search
- D. Serves GUI responsible to transfer request to the DLE server
Answer: B
Explanation:
Explanation
References:
NEW QUESTION 190
When using Monitored circuit VRRP, what is a priority delta?
- A. When an interface fails the priority delta decides if the other interfaces takes over
- B. When an interface fails the priority changes to the priority delta
- C. When an interface fails the priority delta is subtracted from the priority
- D. When an interface fails the delta claims the priority
Answer: C
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Gaia_WebAdmin/87911.htm
NEW QUESTION 191
Which of the following is NOT a component of Check Point Capsule?
- A. Capsule Enterprise
- B. Capsule Cloud
- C. Capsule Docs
- D. Capsule Workspace
Answer: A
NEW QUESTION 192
When launching SmartDashboard, what information is required to log into R77?
- A. User Name, Password, Management Server IP
- B. User Name, Management Server IP, certificate fingerprint file
- C. Password, Management Server IP, LDAP Server IP
- D. Password, Management Server IP
Answer: A
NEW QUESTION 193
After the initial installation the First Time Configuration Wizard should be run. Select the
BEST answer.
- A. Firsttime Configuration Wizard can only be run from the WebUI.
- B. First Time Configuration Wizard can be run from the Unified SmartConsole.
- C. Connection to the internet is required before running the First Time Configuration wizard.
- D. First Time Configuration Wizard can be run from the command line or from the WebUI.
Answer: D
Explanation:
Check Point Security Gateway and Check Point Security Management requirerunning the
First Time Configuration Wizard in order to be configured correctly. The First Time
Configuration Wizard is available in Gaia Portal and also through CLI.
To invoke the First Time Configuration Wizard through CLI, run
the config_system commandfrom the Expert shell.
NEW QUESTION 194
Look at the screenshot below. What CLISH command provides this output?
- A. show configuration
- B. show configuration all
- C. show confd configuration all
- D. show confd configuration
Answer: A
Explanation:
Explanation
NEW QUESTION 195
Which feature is NOT provided by all Check Point Mobile Access solutions?
- A. Secure connectivity
- B. Support for IPv6
- C. Granular access control
- D. Strong user authentication
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Types of Solutions
All of Check Point's Remote Access solutions provide:
Enterprise-grade, secure connectivity to corporate resources.
Strong user authentication.
Granular access control.
Reference: https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/83586.htm
NEW QUESTION 196
......
156-215.80 Exam with Accurate Check Point Certified Security Administrator R80 PDF Questions: https://www.testpassking.com/156-215.80-exam-testking-pass.html