2021 Realistic Verified Free CheckPoint 156-215.80 Exam Questions [Q119-Q135]

Share

2021 Realistic Verified Free CheckPoint 156-215.80 Exam Questions 

156-215.80 Real Exam Questions and Answers FREE

NEW QUESTION 119
You have two rules, ten users, and two user groups in a Security Policy. You create database version 1 for this configuration. You then delete two existing users and add a new user group. You modify one rule and add two new rules to the Rule Base. You save the Security Policy and create database version 2. After a while, you decide to roll back to version 1 to use the Rule Base, but you want to keep your user database.
How can you do this?

  • A. Restore the entire database, except the user database, and then create the new user and user group.
  • B. Restore the entire database, except the user database.
  • C. Run fwm dbexport -1 filename. Restore the database. Then, run fwm dbimport -1 filenameto import the users.
  • D. Run fwm_dbexportto export the user database. Select restore the entire database in the Database Revision screen. Then, run fwm_dbimport.

Answer: B

 

NEW QUESTION 120
Fill in the blank: Once a license is activated, a ________ should be installed.

  • A. License Management file
  • B. Security Gateway Contract file
  • C. Service Contract file
  • D. License Contract file

Answer: C

Explanation:
Service Contract File
Following the activation of the license, a Service Contract File should be installed. This file contains important information about all subscriptions purchased for a specific device and is installed via SmartUpdate. A detailed explanation of the Service Contract File can be found in sk33089.

 

NEW QUESTION 121
Choose the Best place to find a Security Management Server backup file named backup_fw, on a Check Point Appliance.

  • A. /var/log/Cpbackup/backups/backup/backup_fw.tgs
  • B. /var/log/Cpbackup/backups/backups/backup_fw.tar
  • C. /var/log/Cpbackup/backups/backup_fw.tgz
  • D. /var/log/Cpbackup/backups/backup/backup_fw.tar

Answer: C

Explanation:
Explanation
Gaia's Backup feature allows backing up the configuration of the Gaia OS and of the Security Management server database, or restoring a previously saved configuration.
The configuration is saved to a .tgz file in the following directory:
Gaia OS Version
Hardware
Local Directory
R75.40 - R77.20
Check Point appliances
/var/log/CPbackup/backups/
Open Server
/var/CPbackup/backups/
R77.30
Check Point appliances
/var/log/CPbackup/backups/
Open Server
References:

 

NEW QUESTION 122
You manage a global network extending from your base in Chicago to Tokyo, Calcutta and Dallas.
Management wants a report detailing the current software level of each Enterprise class Security Gateway.
You plan to take the opportunity to create a proposal outline, listing the most cost-effective way to upgrade your Gateways. Which two SmartConsole applications will you use to create this report and outline?

  • A. SmartDashboard and SmartView Tracker
  • B. SmartLSM and SmartUpdate
  • C. SmartView Tracker and SmartView Monitor
  • D. SmartView Monitor and SmartUpdate

Answer: D

 

NEW QUESTION 123
Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?

  • A. Security Management Server
  • B. SmartManager
  • C. SmartConsole
  • D. Security Gateway

Answer: D

 

NEW QUESTION 124
When doing a Stand-Alone Installation, you would install the Security Management Server with which other Check Point architecture component?

  • A. SmartConsole
  • B. Security Gateway
  • C. SecureClient
  • D. None, Security Management Server would be installed by itself.

Answer: B

Explanation:
Explanation/Reference:
Explanation: There are different deployment scenarios for Check Point software products.
Standalone Deployment - The Security Management Server and the Security Gateway are installed

on the same computer or appliance.
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Installation_and_Upgrade_Guide- webAdmin/86429.htm

 

NEW QUESTION 125
Where would an administrator enable Implied Rules logging?

  • A. In Global Properties under Firewall
  • B. In SmartDashboard on each rule
  • C. In Global Properties under log and alert
  • D. In Smart Log Rules View

Answer: B

 

NEW QUESTION 126
Two administrators Dave and Jon both manage R80 Management as administrators for ABC Corp. Jon logged into the R80 Management and then shortly after Dave logged in to the same server. They are both in the Security Policies view. From the screenshots below, why does Dave not have the rule no.6 in his SmartConsole view even though Jon has it his in his SmartConsole view?

  • A. Jon is currently editing rule no.6 but has not yet Published his changes.
  • B. Dave is currently editing rule no.6 and has deleted it from his Rule Base.
  • C. Jon is currently editing rule no.6 but has Published part of his changes.
  • D. Dave is currently editing rule no.6 and has marked this rule for deletion.

Answer: A

Explanation:
Explanation
When an administrator logs in to the Security Management Server through SmartConsole, a new editing session starts. The changes that the administrator makes during the session are only available to that administrator. Other administrators see a lock icon on object and rules that are being edited. To make changes available to all administrators, and to unlock the objects and rules that are being edited, the administrator must publish the session.
References:

 

NEW QUESTION 127
When should you generate new licenses?

  • A. When the existing license expires, license is upgraded, or the IP-address where the license is tied changes.
  • B. After an RMA procedure when the MAC address or serial number of the appliance changes.
  • C. Before installing contract files.
  • D. Only when the license is upgraded.

Answer: B

Explanation:
Explanation/Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk84802

 

NEW QUESTION 128
What is Identity Sharing?

  • A. Users can share identities with other users
  • B. Security Gateways can acquire and share identities with other Security Gateways
  • C. Administrators can share identifies with other administrators
  • D. Management servers can acquire and share identities with Security Gateways

Answer: B

Explanation:
Identity Sharing
Best Practice - In environments that use many Security Gateways and AD Query, we recommend that you set only one Security Gateway to acquire identities from a given Active Directory domain controller for each physical site. If more than one Security Gateway gets identities from the same AD server, the AD server can become overloaded with WMI queries.
Set these options on the Identity Awareness > Identity Sharing page of the Security Gateway object:

 

NEW QUESTION 129
Which of the below is the MOST correct process to reset SIC from SmartDashboard?

  • A. Click Communication > Reset on the Gateway object, and type a new activation key.
  • B. Run cpconfig, and select Secure Internal Communication > Change One Time
    Password.
  • C. Click the Communication button for the firewall object, then click Reset. Run cpconfig on the gateway and type a new activation key.
  • D. Run cpconfig, and click Reset.

Answer: C

 

NEW QUESTION 130
To enforce the Security Policy correctly, a Security Gateway requires:

  • A. a Security Policy install
  • B. a Demilitarized Zone
  • C. awareness of the network topology
  • D. a routing table

Answer: C

Explanation:
The network topology represents the internal network (both the LAN and the DMZ) protected by the gateway. The gateway must be aware of the layout of the network topology to:

 

NEW QUESTION 131
What is a role of Publishing?

  • A. Modifies network objects, such as servers, users, services, or IPS profiles, but not the Rule Base
  • B. The Publish operation sends the modifications made via SmartConsole in the private session and makes them public
  • C. The Security Management Server installs the updated policy and the entire database on Security Gateways
  • D. The Security Management Server installs the updated session and the entire Rule Base on Security Gateways

Answer: B

Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SecMGMT/html_frameset.htm?
topic=documents/R80/CP_R80_SecMGMT/119225

 

NEW QUESTION 132
Kofi, the administrator of the ABC Corp network wishes to change the default Gaia WebUI Portal port number currently set on the default HTTPS port. Which CLISH commands are required to be able to change this TCP port?

  • A. set Gaia-portal <new port number>
  • B. set Gaia-portal https-port <new port number>
  • C. set web ssl-port <new port number>
  • D. set web https-port <new port number>

Answer: C

Explanation:
Explanation
Explanation: In Clish
Connect to command line on Security Gateway / Cluster member.
Log in to Clish.
Set the desired port (e.g., port 4434):
HostName> set web ssl-port <Port_Number>
Save the changes:
HostName> save config
Verify that the configuration was saved:
[Expert@HostName]# grep 'httpd:ssl_port' /config/db/initial References:

 

NEW QUESTION 133
The R80 feature ________ permits blocking specific IP addresses for a specified time period.

  • A. Local Interface Spoofing
  • B. Suspicious Activity Monitoring
  • C. Adaptive Threat Prevention
  • D. Block Port Overflow

Answer: B

Explanation:
Suspicious Activity Rules Solution
Suspicious Activity Rules is a utility integrated into SmartView Monitor that is used to modify access privileges upon detection of any suspicious network activity (for example, several attempts to gain unauthorized access).
The detection of suspicious activity is based on the creation of Suspicious Activity rules. Suspicious Activity rules are Firewall rules that enable the system administrator to instantly block suspicious connections that are not restricted by the currently enforced security policy. These rules, once set (usually with an expiration date), can be applied immediately without the need to perform an Install Policy operation

 

NEW QUESTION 134
Kofi, the administrator of the ALPHA Corp network wishes to change the default Gaia WebUI Portal port number currently set on the default HTTPS port. Which CLISH commands are required to be able to change this TCP port?

  • A. set Gaia-portal <new port number>
  • B. set Gaia-portal https-port <new port number>
  • C. set web ssl-port <new port number>
  • D. set web https-port <new port number>

Answer: C

Explanation:
Explanation
In Clish
HostName> set web ssl-port <Port_Number>
HostName> save config
[Expert@HostName]# grep 'httpd:ssl_port' /config/db/initial

 

NEW QUESTION 135
......

Exam Dumps 156-215.80 Practice Free Latest CheckPoint Practice Tests: https://www.2pass4sure.com/CCSA-R80/156-215.80-actual-exam-braindumps.html

156-215.80 Exam Questions | Real 156-215.80 Practice Dumps: https://drive.google.com/open?id=16ed62hL6wIeq131dHMLBcQDy_wjsaZQS