
Guaranteed High Marks with Updated & Real 156-215.81.20 Dumps pdf Free Updates
PASS RATE CCSA 156-215.81.20 Certified Exam DUMP
NEW QUESTION # 138
Security Zones do no work with what type of defined rule?
- A. Manual NAT rule
- B. Firewall rule
- C. IPS bypass rule
- D. Application Control rule
Answer: A
NEW QUESTION # 139
When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?
- A. Group Template
- B. Access Role
- C. User Group
- D. SmartDirectory Group
Answer: B
NEW QUESTION # 140
Which of the following is considered a "Subscription Blade", requiring renewal every 1-3 years?
- A. IPS blade
- B. Firewall Blade
- C. Identity Awareness Blade
- D. IPSEC VPN Blade
Answer: A
NEW QUESTION # 141
What Check Point tool is used to automatically update Check Point products for the Gaia OS?
- A. Check Point Update Engine
- B. Check Point INSPECT Engine
- C. Check Point Upgrade Installation Service
- D. Check Point Upgrade Service Engine
Answer: D
NEW QUESTION # 142
In SmartEvent, a correlation unit (CU) is used to do what?
- A. Send SAM block rules to the firewalls during a DOS attack.
- B. Collect security gateway logs, Index the logs and then compress the logs.
- C. Receive firewall and other software blade logs in a region and forward them to the primary log server.
- D. Analyze log entries and identify events.
Answer: D
NEW QUESTION # 143
After a new Log Server is added to the environment and the SIC trust has been established with the SMS what will the gateways do?
- A. Logs are not automatically forwarded to a new Log Server. SmartConsole must be used to manually configure each gateway to send its logs to the server.
- B. Gateways will send new firewall logs to the new Log Server as soon as the SIC trust is set up between the SMS and the new Log Server.
- C. The gateways can only send logs to an SMS and cannot send logs to a Log Server. Log Servers are proprietary log archive servers.
- D. The firewalls will detect the new Log Server after the next policy install and redirect the new logs to the new Log Server.
Answer: A
NEW QUESTION # 144
What are the steps to configure the HTTPS Inspection Policy?
- A. Go to Application&url filtering blade > Https Inspection > Policy
- B. Go to Application&url filtering blade > Advanced > Https Inspection > Policy
- C. Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
- D. Go to Manage&Settings > Blades > HTTPS Inspection > Policy
Answer: D
NEW QUESTION # 145
Session unique identifiers are passed to the web api using which http header option?
- A. X-chkp-sid
- B. Accept-Charset
- C. Application
- D. Proxy-Authorization
Answer: A
NEW QUESTION # 146
Which icon in the WebUI indicates that read/write access is enabled?
- A. Eyeglasses
- B. Pencil
- C. Padlock
- D. Book
Answer: B
NEW QUESTION # 147
Which of the following is NOT an identity source used for Identity Awareness?
- A. AD Query
- B. UserCheck
- C. Remote Access
- D. RADIUS
Answer: B
NEW QUESTION # 148
Which of the following is NOT supported by Bridge Mode on the Check Point Security Gateway?
- A. NAT
- B. Antivirus
- C. Application Control
- D. Data Loss Prevention
Answer: A
NEW QUESTION # 149
How many users can have read/write access in Gaia Operating System at one time?
- A. Two
- B. Infinite
- C. Three
- D. One
Answer: D
NEW QUESTION # 150
The Online Activation method is available for Check Point manufactured appliances.
How does the administrator use the Online Activation method?
- A. No action is required if the firewall has internet access and a DNS server to resolve domain names.
- B. Using the Gaia First Time Configuration Wizard, the appliance connects to the Check Point User Center and downloads all necessary licenses and contracts.
- C. The SmartLicensing GUI tool must be launched from the SmartConsole for the Online Activation tool to start automatically.
- D. The cpinfo command must be run on the firewall with the switch -online-license-activation.
Answer: B
NEW QUESTION # 151
What are the three components for Check Point Capsule?
- A. Capsule Workspace, Capsule Docs, Capsule Connect
- B. Capsule Docs, Capsule Cloud, Capsule Connect
- C. Capsule Workspace, Capsule Docs, Capsule Cloud
- D. Capsule Workspace, Capsule Cloud, Capsule Connect
Answer: C
NEW QUESTION # 152
What is the Transport layer of the TCP/IP model responsible for?
- A. It defines the protocols that are used to exchange data between networks and how host programs interact with the Application layer.
- B. It manages the flow of data between two hosts to ensure that the packets are correctly assembled and delivered to the target application.
- C. It transports packets as datagrams along different routes to reach their destination.
- D. It deals with all aspects of the physical components of network connectivity and connects with different network types.
Answer: B
NEW QUESTION # 153
What are two basic rules Check Point recommending for building an effective security policy?
- A. Accept Rule and Drop Rule
- B. Cleanup Rule and Stealth Rule
- C. NAT Rule and Reject Rule
- D. Explicit Rule and Implied Rule
Answer: B
NEW QUESTION # 154
When a SAM rule is required on Security Gateway to quickly block suspicious connections which are not restricted by the Security Policy, what actions does the administrator need to take?
- A. The administrator should open the LOGS & MONITOR view and find the relevant log. Right clicking on the log entry will show the Create New SAM rule option.
- B. The policy type SAM must be added to the Policy Package and a new SAM rule must be applied. Simply Publishing the changes applies the SAM rule on the firewall.
- C. The administrator must work on the firewall CLI (for example with SSH and PuTTY) and the command 'sam block' must be used with the right parameters.
- D. SmartView Monitor should be opened and then the SAM rule/s can be applied immediately. Installing policy is not required.
Answer: D
NEW QUESTION # 155
A stateful inspection firewall works by registering connection data and compiling this information. Where is the information stored?
- A. In a CSV file on the firewall hard drive located in $FWDIR/conf/.
- B. In the Sessions table.
- C. In the system SMEM memory pool.
- D. In State tables.
Answer: D
NEW QUESTION # 156
What two ordered layers make up the Access Control Policy Layer?
- A. Application Control and URL Filtering
- B. URL Filtering and Network
- C. Network and Application Control
- D. Network and Threat Prevention
Answer: D
NEW QUESTION # 157
Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?
- A. Remote Desktop Protocol (RDP)
- B. Windows Management Instrumentation (WMI)
- C. Lightweight Directory Access Protocol (LDAP)
- D. Hypertext Transfer Protocol Secure (HTTPS)
Answer: C
NEW QUESTION # 158
When using Monitored circuit VRRP, what is a priority delta?
- A. When an interface fails the priority delta is subtracted from the priority
- B. When an interface fails the delta claims the priority
- C. When an interface fails the priority delta decides if the other interfaces takes over
- D. When an interface fails the priority changes to the priority delta
Answer: A
NEW QUESTION # 159
Which repositories are installed on the Security Management Server by SmartUpdate?
- A. License and Update
- B. Update and License & Contract
- C. Package Repository and Licenses
- D. License & Contract and Package Repository
Answer: D
NEW QUESTION # 160
You had setup the VPN Community NPN-Stores' with 3 gateways. There are some issues with one remote gateway(l .1.1.1) and an your local gateway.
What will be the best log filter to see only the IKE Phase 2 agreed networks for both gateways.
- A. Blade:"VPN"AND VPN-Stores AND Quick Mode
- B. action:"Key Install" AND 1.1.1.1 AND Quick Mode
- C. Blade:"VPN"AND VPN-Stores AND Main Mode
- D. action:"Key Install" AND 1.1.1.1 AND Main Mode
Answer: B
NEW QUESTION # 161
......
Best 156-215.81.20 Exam Preparation Material with New Dumps Questions: https://passleader.bootcamppdf.com/156-215.81.20-exam-actual-tests.html