
CheckPoint 156-315.80 Dumps - The Sure Way To Pass Exam
156-315.80 Exam Questions (Updated 2023) 100% Real Question Answers
The CheckPoint 156-315.80 exam covers several topics, including advanced firewall administration, VPN management, advanced user management, and policy management. The exam is made up of 90 multiple-choice questions and is timed for 120 minutes. The passing score for the exam is 70%, and it is available in several languages, including English, Japanese, and Chinese.
NEW QUESTION # 201
What happen when IPS profile is set in Detect Only Mode for troubleshooting?
- A. It will generate Geo-Protection traffic
- B. Bypass licenses requirement for Geo-Protection control
- C. It will not block malicious traffic
- D. Automatically uploads debugging logs to Check Point Support Center
Answer: C
Explanation:
It is recommended to enable Detect-Only for Troubleshooting on the profile during the initial installation of IPS.
This option overrides any protections that are set to Prevent so that they will not block any traffic.
During this time you can analyze the alerts that IPS generates to see how IPS will handle network traffic, while avoiding any impact on the flow of traffic.
Reference:
https://sc1.checkpoint.com/documents/R76/CP_R76_IPS_AdminGuide/12750.htm
NEW QUESTION # 202
Your manager asked you to check the status of SecureXL, and its enable templates and features, what
command will you use to provide such information to manager?
- A. fwaccel stats
- B. fw accel stat
- C. fw acces stats
- D. fwaccel stat
Answer: D
NEW QUESTION # 203
The "Hit count" feature allows tracking the number of connections that each rule matches. Will the Hit count feature work independently from logging and Track the hits if the Track option is set to "None"?
- A. Yes it will work independently as long as "analyze all rules" tick box is enabled on the Security Gateway.
- B. No, it will not work independently because hit count requires all rules to be logged.
- C. No, it will work independently. Hit Count will be shown only for rules Track option set as Log or alert.
- D. Yes it will work independently because when you enable Hit Count, the SMS collects the data from supported Security Gateways.
Answer: D
Explanation:
References:
NEW QUESTION # 204
SecureXL improves non-encrypted firewall traffic throughput and encrypted VPN traffic throughput.
- A. This statement is true because SecureXL does improve all traffic.
- B. This statement is false because SecureXL does not improve this traffic but CoreXL does.
- C. This statement is true because SecureXL does improve this traffic.
- D. This statement is false because encrypted traffic cannot be inspected.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
SecureXL improved non-encrypted firewall traffic throughput, and encrypted VPN traffic throughput, by nearly an order-of-magnitude- particularly for small packets flowing in long duration connections.
Reference: https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/10001/FILE/ SecureXL_and_Nokia_IPSO_White_Paper_20080401.pdf
NEW QUESTION # 205
What are the three components for Check Point Capsule?
- A. Capsule Workspace, Capsule Docs, Capsule Cloud
- B. Capsule Workspace, Capsule Docs, Capsule Connect
- C. Capsule Docs, Capsule Cloud, Capsule Connect
- D. Capsule Workspace, Capsule Cloud, Capsule Connect
Answer: A
NEW QUESTION # 206
In ClusterXL Load Sharing Multicast Mode:
- A. only the primary member received packets sent to the cluster IP address
- B. every member of the cluster received all of the packets sent to the cluster IP address
- C. packets sent to the cluster IP address are distributed equally between all members of the cluster
- D. only the secondary member receives packets sent to the cluster IP address
Answer: B
Explanation:
References:
NEW QUESTION # 207
Fill in the blank: The R80 feature ______ permits blocking specific IP addresses for a specific time period.
- A. Suspicious Activity Monitoring
- B. Local Interface Spoofing
- C. Block Port Overflow
- D. Adaptive Threat Prevention
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Suspicious Activity Rules Solution
Suspicious Activity Rules is a utility integrated into SmartView Monitor that is used to modify access privileges upon detection of any suspicious network activity (for example, several attempts to gain unauthorized access).
The detection of suspicious activity is based on the creation of Suspicious Activity rules. Suspicious Activity rules are Firewall rules that enable the system administrator to instantly block suspicious connections that are not restricted by the currently enforced security policy. These rules, once set (usually with an expiration date), can be applied immediately without the need to perform an Install Policy operation Reference: https://sc1.checkpoint.com/documents/R76/ CP_R76_SmartViewMonitor_AdminGuide/17670.htm
NEW QUESTION # 208
Which of the following is a new R80.10 Gateway feature that had not been available in R77.X and older?
- A. The rule base can be built of layers, each containing a set of the security rules. Layers are inspected in the order in which they are defined, allowing control over the rule base flow and which security functionalities take precedence.
- B. Sub Policies ae sets of rules that can be created and attached to specific rules. If the rule is matched, inspection will continue in the sub policy attached to it rather than in the next rule.
- C. Time object to a rule to make the rule active only during specified times.
- D. Limits the upload and download throughput for streaming media in the company to 1 Gbps.
Answer: B
Explanation:
Explanation/Reference:
Reference: http://dl3.checkpoint.com/paid/1f/1f850d1640792cf885336cc6ae8b2743/ CP_R80_ReleaseNotes.pdf?HashKey=1517092603_dd917544d92dccc060e5b25d28a46f79&xtn=.pdf
NEW QUESTION # 209
Which command shows the current connections distributed by CoreXL FW instances?
- A. fw ctl affinity -l
- B. fw ctl iflist
- C. fw ctl instances -v
- D. fw ctl multik stat
Answer: D
NEW QUESTION # 210
In ClusterXL Load Sharing Multicast Mode:
- A. only the primary member received packets sent to the cluster IP address
- B. every member of the cluster received all of the packets sent to the cluster IP address
- C. packets sent to the cluster IP address are distributed equally between all members of the cluster
- D. only the secondary member receives packets sent to the cluster IP address
Answer: B
NEW QUESTION # 211
What are the blades of Threat Prevention?
- A. IPS, AntiVirus, AntiBot, Sandblast Threat Emulation/Extraction
- B. DLP, AntiVirus, QoS, AntiBot, Sandblast Threat Emulation/Extraction
- C. IPS, AntiVirus, AntiBot
- D. IPS, DLP, AntiVirus, AntiBot, Sandblast Threat Emulation/Extraction
Answer: A
NEW QUESTION # 212
What is the recommended number of physical network interfaces in a Mobile Access cluster deployment?
- A. 2 Interfaces - a data interface leading to the organization and the Internet, a second interface for synchronization.
- B. 1 Interface - an interface leading to the organization and the Internet, and configure for synchronization.
- C. 3 Interfaces - an interface leading to the organization, a second interface leading to the Internet, a third interface for synchronization.
- D. 4 Interfaces - an interface leading to the organization, a second interface leading to the internet, a third interface for synchronization, a fourth interface leading to the Security Management Server.
Answer: C
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Mobile_Access_WebAdmin/41723.htm
NEW QUESTION # 213
What is a best practice before starting to troubleshooting using the ''fw monitor'' tool?
- A. Run the command: fw monitor debug on
- B. Disable CoreXL
- C. Disable SecureXL
- D. Clear the connections table
Answer: C
NEW QUESTION # 214
Which command lists all tables in Gaia?
- A. fw tab -list
- B. Fw tab-t
- C. fw tab-I
- D. fw tab-s
Answer: B
NEW QUESTION # 215
Which CLI command will reset the IPS pattern matcher statistics?
- A. ips pstats reset
- B. ips pmstats refresh
- C. ips pmstats reset
- D. ips reset pmstat
Answer: C
NEW QUESTION # 216
Which of the following is NOT supported by CPUSE?
- A. Installation of private hotfixes
- B. Automatic download of hotfixes
- C. Automatic download of full installation and upgrade packages
- D. Offline installations
Answer: D
Explanation:
https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_AdminWebAdminGuide/ html_frameset.htm?topic=documents/R77/CP_R77_Gaia_AdminWebAdminGuide/112109
NEW QUESTION # 217
You have a Geo-Protection policy blocking Australia and a number of other countries. Your network now requires a Check Point Firewall to be installed in Sydney, Australia.
What must you do to get SIC to work?
- A. Remove Geo-Protection, as the IP-to-country database is updated externally, and you have no control of this.
- B. Nothing - Check Point control connections function regardless of Geo-Protection policy
- C. Create a rule at the top in the Sydney firewall to allow control traffic from your network
- D. Create a rule at the top in your Check Point firewall to bypass the Geo-Protection
Answer: B
Explanation:
References:
NEW QUESTION # 218
Fill in the blank: The R80 utilityfw monitoris used to troubleshoot ________.
- A. Traffic issues
- B. LDAP conflicts
- C. User data base corruption
- D. Phase two key negotiations
Answer: A
Explanation:
Check Point's FW Monitor is a powerful built-in tool for capturing network traffic at the packet level. The FW Monitor utility captures network packets at multiple capture points along the FireWall inspection chains. These captured packets can be inspected later using the WireShark Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk30583
NEW QUESTION # 219
What is true about the IPS-Blade?
- A. In R80, in the IPS Layer, the only three possible actions are Basic, Optimized and Strict
- B. In R80, IPS is managed by the Threat Prevention Policy
- C. In R80, the GeoPolicy Exceptions and the Threat Prevention Exceptions are the same
- D. In R80, IPS Exceptions cannot be attached to "all rules"
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION # 220
Which statement is true regarding redundancy?
- A. System Administrators know when their cluster has failed over and can also see why it failed over by using the cphaprob -f if command.
- B. ClusterXL offers three different Load Sharing solutions: Unicast, Broadcast, and Multicast.
- C. Machines in a ClusterXL High Availability configuration must be synchronized.
- D. Both ClusterXL and VRRP are fully supported by Gaia and available to all Check Point appliances, open servers, and virtualized environments.
Answer: D
NEW QUESTION # 221
What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL Filtering, Anti-Virus, IPS, and Threat Emulation?
- A. Anti-Bot is the only protection mechanism which starts a counter-attack against known Command & Control Centers
- B. Anti-Bot is the only signature-based method of malware protection.
- C. Anti-Bot is the only countermeasure against unknown malware
- D. Anti-Bot is a post-infection malware protection to prevent a host from establishing a connection to a Command & Control Center.
Answer: D
Explanation:
Explanation/Reference:
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_AntiBotAntiVirus_AdminGuide/index.html
NEW QUESTION # 222
Which Check point software blades cloud be enforced under Threat Prevention profile using Point1R80.10 SmartConsole application?
- A. Firewall, IPS Threat Emulation, Application Control
- B. IPS, Anti-Bot, URL Filtering, Application Control, Threat Emulation
- C. IPS, Anti-Bot, Anti-virus, Threat Emulation, Threat Extraction
- D. Firewall, IPS Anti-Bot, Anti-Virus, Threat Emulation
Answer: C
Explanation:
Explanation
https://sc1.checkpoint.com/documents/R80.10/SmartConsole_OLH/EN/html_frameset.htm?topic=docume
NEW QUESTION # 223
The SmartEvent R80 Web application for real-time event monitoring is called:
- A. There is no Web application for SmartEvent
- B. SmartView Monitor
- C. SmartView
- D. SmartEventWeb
Answer: D
NEW QUESTION # 224
The following command is used to verify the CPUSE version:
- A. HostName:0>show installer build
- B. [Expert@HostName:0]#show installer status
- C. HostName:0>show installer status build
- D. [Expert@HostName:0]#show installer status build
Answer: C
Explanation:
Explanation/Reference: http://dkcheckpoint.blogspot.com/2017/11/how-to-fix-deployment-agent-issues.html
NEW QUESTION # 225
Check point recommends configuring Disk Management parameters to delete old log available disk space is less than or equal to?
- A. 50%
- B. 45%
- C. 75%
- D. 80%
Answer: A
NEW QUESTION # 226
......
Pass CheckPoint 156-315.80 Exam Quickly With DumpsKing: https://www.dumpsking.com/156-315.80-testking-dumps.html
Prepare 156-315.80 Question Answers - 156-315.80 Exam Dumps: https://drive.google.com/open?id=1zhSuZ1bFsyEIBImZDioQM4dDQ1fLVzPL
