
Latest 156-315.81.20 exam dumps with real CheckPoint questions and answers
156-315.81.20 Exam in First Attempt Guaranteed
NEW QUESTION # 218
What is the correct command to observe the Sync traffic in a VRRP environment?
- A. fw monitor -e "accept[12:4,b]=224.0.0.18;"
- B. fw monitor -e "accept proto=mcVRRP;"
- C. fw monitor -e "accept port(6118;"
- D. fw monitor -e "accept dst=224.0.0.18;"
Answer: D
NEW QUESTION # 219
Which of the following type of authentication on Mobile Access can NOT be used as the first authentication method?
- A. RADIUS
- B. Dynamic ID
- C. Certificate
- D. Username and Password
Answer: B
NEW QUESTION # 220
To fully enable Dynamic Dispatcher with Firewall Priority Queues on a Security Gateway, run the following command in Expert mode then reboot:
- A. fw ctl Dynamic_Priority_Queue on
- B. fw ctl multik set_mode 9
- C. fw ctl multik set_mode 1
- D. fw ctl Dynamic_Priority_Queue enable
Answer: B
NEW QUESTION # 221
What is the purpose of the command "ps aux | grep twd"?
- A. You can convert the log file into Post Script format.
- B. You can check whether the IPS default setting is set to Detect or Prevent mode
- C. You can list all Process IDs for all running services.
- D. You can check the Process ID and the processing time of the twd process.
Answer: D
NEW QUESTION # 222
How can you switch the active log file?
- A. Run fw logswitch on the Management Server
- B. Run fwm logswitch on the Management Server
- C. Run fw logswitch on the gateway
- D. Run fwm logswitch on the gateway
Answer: A
NEW QUESTION # 223
Ken wants to obtain a configuration lock from other administrator on R81 Security Management Server. He can do this via WebUI or via CLI.
Which command should he use in CLI? (Choose the correct answer.)
- A. The database feature has two commands lock database override and unlock database. Both will work.
- B. override database lock
- C. The database feature has one command lock database override.
- D. remove database lock
Answer: A
NEW QUESTION # 224
Fill in the blank: Permanent VPN tunnels can be set on all tunnels in the community, on all tunnels for specific gateways, or ______ .
- A. On specific tunnels in the community
- B. On specific satellite gateway to central gateway tunnels
- C. On specific tunnels for specific gateways
- D. On all satellite gateway to satellite gateway tunnels
Answer: A
NEW QUESTION # 225
How long may verification of one file take for Sandblast Threat Emulation?
- A. up to 3 minutes
- B. within seconds cleaned file will be provided
- C. up to 1 minutes
- D. up to 5 minutes
Answer: A
NEW QUESTION # 226
Which type of Endpoint Identity Agent includes packet tagging and computer authentication?
- A. Light
- B. Complete
- C. Full
- D. Custom
Answer: C
NEW QUESTION # 227
To optimize Rule Base efficiency, the most hit rules should be where?
- A. Removed from the Rule Base.
- B. Towards the bottom of the Rule Base.
- C. Towards the top of the Rule Base.
- D. Towards the middle of the Rule Base.
Answer: C
NEW QUESTION # 228
Which one of the following is true about Threat Extraction?
- A. Always delivers a file to user
- B. Delivers file only if no threats found
- C. Works on all MS Office, Executables, and PDF files
- D. Can take up to 3 minutes to complete
Answer: A
NEW QUESTION # 229
If an administrator wants to add manual NAT for addresses now owned by the Check Point firewall, what else is necessary to be completed for it to function properly?
- A. Add the proxy ARP configurations in a file called $CPDIR/conf/local.arp
- B. Nothing - the proxy ARP is automatically handled in the R81 version
- C. Add the proxy ARP configurations in a file called /etc/conf/local.arp
- D. Add the proxy ARP configurations in a file called $FWDIR/conf/local.arp
Answer: D
NEW QUESTION # 230
Which of the following Windows Security Events will not map a username to an IP address in Identity Awareness?
- A. Kerberos Ticket Requested
- B. Account Logon
- C. Kerberos Ticket Timed Out
- D. Kerberos Ticket Renewed
Answer: C
NEW QUESTION # 231
After having saved the Cllsh Configuration with the "save configuration config.txt* command, where can you find the config.txt file?
- A. You can locate the file via SmartConsole > Command Line.
- B. You have to launch the WebUl and go to "Config" -> "Export Conflg File" and specifly the destination directory of your local tile system
- C. You will find it in the home directory of your usef account (e.g. /home/admirV)
- D. You cannot locate the file in the file system sine Clish does not have any access to the bash fie system
Answer: A
NEW QUESTION # 232
Identity Awareness lets an administrator easily configure network access and auditing based on three items. Choose the correct statement.
- A. Geographical location, the identity of a user and the identity of a machine.
- B. Network location, the identity of a user and the identity of a machine.
- C. Network location, the telephone number of a user and the UID of a machine.
- D. Network location, the identity of a user and the active directory membership.
Answer: B
NEW QUESTION # 233
How can SmartView application accessed?
- A. http://<Security Management IP Address>/smartview
- B. https://<Security Management IP Address>/smartview/
- C. https://<Security Management host name>:4434/smartview/
- D. http://<Security Management IP Address>:4434/smartview/
Answer: B
NEW QUESTION # 234
Which command would you use to set the network interfaces' affinity in Manual mode?
- A. sim affinity -m
- B. sim affinity -l
- C. sim affinity -s
- D. sim affinity -a
Answer: C
NEW QUESTION # 235
What does the Log "Views" tab show when SmartEvent is Correlating events?
- A. Details of a selected logs
- B. Top events with charts and graphs
- C. Reports for customization
- D. A list of common reports
Answer: A
NEW QUESTION # 236
Which components allow you to reset a VPN tunnel?
- A. SmartView monitor only
- B. vpn tunnelutil or delete vpn ike sa command
- C. vpn tu command or SmartView monitor
- D. delete vpn ike sa or vpn she11 command
Answer: C
NEW QUESTION # 237
Which of the following Central Deployment is NOT a limitation in R81.20 SmartConsole?
- A. Dedicated SmartEvent Server
- B. Security Gateways/Clusters in ClusterXL HA new mode
- C. Security Gateway Clusters in Load Sharing mode
- D. Dedicated Log Server
Answer: C
NEW QUESTION # 238
How many images are included with Check Point TE appliance in Recommended Mode?
- A. 2(OS) images
- B. as many as licensed for
- C. the newest image
- D. images are chosen by administrator during installation
Answer: A
NEW QUESTION # 239
Vanessa is a Firewall administrator. She wants to test a backup of her company's production Firewall cluster Dallas_GW. She has a lab environment that is identical to her production environment. She decided to restore production backup via SmartConsole in lab environment.
Which details she need to fill in System Restore window before she can click OK button and test the backup?
- A. Server, SCP, Username, Password, Path, Comment, Member
- B. Server, Protocol, Username, Password, Path, Comment, All Members
- C. Server, Protocol, username Password, Path, Comment, Member
- D. Server, TFTP, Username, Password, Path, Comment, All Members
Answer: B
NEW QUESTION # 240
Alice & Bob are going to use Management Data Plane Separation and therefore the routing separation needs to be enabled.
Which of the following command is true for enabling the Management Data Plane Separation (MDPS):
- A. set mdps mgmt plane on
- B. set mdps split plane on
- C. set mdps data plane off
- D. set mdps split brain on
Answer: A
NEW QUESTION # 241
An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security Management Server. While configuring the VPN community to specify the pre-shared secret the administrator found that the check box to enable pre-shared secret and cannot be enabled.
Why does it not allow him to specify the pre-shared secret?
- A. Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS.
- B. Pre-shared can only be used while creating a VPN between a third party vendor and Check Point Security Gateway.
- C. IPsec VPN blade should be enabled on both Security Gateway.
- D. The Security Gateways are pre-R75.40.
Answer: A
NEW QUESTION # 242
When attempting to start a VPN tunnel, in the logs the error "no proposal chosen" is seen numerous times. No other VPN-related entries are present.
Which phase of the VPN negotiations has failed?
- A. IPSEC Phase 1
- B. IKE Phase 1
- C. IPSEC Phase 2
- D. IKE Phase 2
Answer: B
NEW QUESTION # 243
......
Exam Sure Pass CheckPoint Certification with 156-315.81.20 exam questions: https://www.troytecdumps.com/156-315.81.20-troytec-exam-dumps.html
Download Real 156-315.81.20 Exam Dumps for candidates. 100% Free Dump Files: https://drive.google.com/open?id=1rlJBXp5nKHfLbnEGJcU0mmlz8WxoEZRF