
Latest 156-215.81.20 Practice Test Questions Verified Answers As Experienced in the Actual Test!
Pass CheckPoint 156-215.81.20 Exam in First Attempt Easily
NEW QUESTION # 187
To view statistics on detected threats, which Threat Tool would an administrator use?
- A. ThreatWiki
- B. Protections
- C. IPS Protections
- D. Profiles
Answer: A
NEW QUESTION # 188
URL Filtering cannot be used to:
- A. Improve organizational security
- B. Decrease legal liability
- C. Control Bandwidth issues
- D. Control Data Security
Answer: C
NEW QUESTION # 189
The competition between stateful inspection and proxies was based on performance, protocol support, and security. Considering stateful Inspections and Proxies, which statement is correct?
- A. Stateful Inspection is limited to Layer 3 visibility, with no Layer 4 to Layer 7 visibility capabilities.
- B. Proxies offer far more security because of being able to give visibility of the payload (the data).
- C. When it comes to performance, proxies were significantly faster than stateful inspection firewalls.
- D. When it comes to performance, stateful inspection was significantly faster than proxies.
Answer: D
NEW QUESTION # 190
When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?
- A. User Group
- B. SmartDirectory Group
- C. Access Role
- D. Group Template
Answer: C
NEW QUESTION # 191
What needs to be configured if the NAT property 'Translate destination on client side' is not enabled in Global properties?
- A. Enabling 'Allow bi-directional NAT' for NAT to work correctly
- B. Nothing, the Gateway takes care of all details necessary
- C. Use the file local.arp to add the ARP entries for NAT to work
- D. A host route to route to the destination IP
Answer: B
NEW QUESTION # 192
Which tool allows you to monitor the top bandwidth on smart console?
- A. Logs & Monitoring
- B. SmartView Monitor
- C. Gateways & Severs Tab
- D. Smart Event
Answer: B
NEW QUESTION # 193
True or False: In R80, more than one administrator can login to the Security Management Server with write permission at the same time.
- A. True, every administrator works on a different database that is independent of the other administrators.
- B. True, every administrator works in a session that is independent of the other administrators.
- C. False, only one administrator can login with write permission.
- D. False, this feature has to be enabled in the Global Properties.
Answer: B
NEW QUESTION # 194
An administrator can use section titles to more easily navigate between large rule bases.
Which of these statements is FALSE?
- A. Sectional Titles do not need to be created in the SmartConsole.
- B. Section titles are not sent to the gateway side.
- C. These sections are simple visual divisions of the Rule Base and do not hinder the order of rule enforcement.
- D. A Sectional Title can be used to disable multiple rules by disabling only the sectional title.
Answer: D
NEW QUESTION # 195
Which back up method uses the command line to create an image of the OS?
- A. Migrate
- B. snapshot
- C. Save Configuration
- D. System backup
Answer: B
NEW QUESTION # 196
Fill in the blanks: Default port numbers for an LDAP server is ______ for standard connections and _______ SSL connections.
- A. 636, 290
- B. 675, 389
- C. 290, 675
- D. 389, 636
Answer: D
NEW QUESTION # 197
Which of the following is NOT a valid application navigation tab in the R80 SmartConsole?
- A. Logs and Monitor
- B. Security Policies
- C. Manage and Command Line
- D. Gateway and Servers
Answer: C
NEW QUESTION # 198
The Network Operations Center administrator needs access to Check Point Security devices mostly for troubleshooting purposes. You do not want to give her access to the expert mode, but she still should be able to run tcpdump.
How can you achieve this requirement?
- A. Create a new access role.Add expert-mode access to the role.Create new user with any UID and assign role to the user.
- B. Add tcpdump to CLISH using add command.Create a new access role.Add tcpdump to the role.Create new user with any UID and assign role to the user.
- C. Create a new access role.Add expert-mode access to the role.Create new user with UID 0 and assign role to the user.
- D. Add tcpdump to CLISH using add command.Create a new access role.Add tcpdump to the role.Create new user with UID 0 and assign role to the user.
Answer: B
NEW QUESTION # 199
Both major kinds of NAT support Hide and Static NAT. However, one offers more flexibility.
Which statement is true?
- A. Automatic NAT can offer more flexibility than Manual NAT.
- B. Dynamic NAT with Port Address Translation can offer more flexibility than Network Address Translation (NAT) Overloading.
- C. Dynamic Network Address Translation (NAT) Overloading can offer more flexibility than Port Address Translation.
- D. Manual NAT can offer more flexibility than Automatic NAT.
Answer: D
NEW QUESTION # 200
What is the purpose of the Clean-up Rule?
- A. To remove all rules that could have a conflict with other rules in the database
- B. To clean up policies found inconsistent with the compliance blade reports
- C. To eliminate duplicate log entries in the Security Gateway
- D. To log all traffic that is not explicitly allowed or denied in the Rule Base
Answer: D
NEW QUESTION # 201
Which of the following statements about Site-to-Site VPN Domain-based is NOT true?
- A. Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a service or user that can send or receive VPN traffic through a VPN Gateway.
- B. Route-based- The Security Gateways will have a Virtual Tunnel Interface (VTI) for each VPN Tunnel with a peer VPN Gateway. The Routing Table can have routes to forward traffic to these VTls. Any traffic routed through a VTI is automatically identified as VPN Traffic and is passed through the VPN Tunnel associated with the VTI.
- C. Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a host or network that can send or receive VPN traffic through a VPN Gateway.
- D. Domain-based- VPN domains are pre-defined for all VPN Gateways. When the Security Gateway encounters traffic originating from one VPN Domain with the destination to a VPN Domain of another VPN Gateway, that traffic is identified as VPN traffic and is sent through the VPN Tunnel between the two Gateways.
Answer: A
NEW QUESTION # 202
When you upload a package or license to the appropriate repository in SmartUpdate. where is the package or license stored?
- A. Security Management Server
- B. Security Gateway
- C. SmartConsole installed device
- D. Check Point user center
Answer: A
NEW QUESTION # 203
What are the two types of NAT supported by the Security Gateway?
- A. Hide and Static
- B. Destination and Hide
- C. Static and Source
- D. Source and Destination
Answer: A
NEW QUESTION # 204
......
We offers you the latest free online 156-215.81.20 dumps to practice: https://www.prep4sureguide.com/156-215.81.20-prep4sure-exam-guide.html
The Most Efficient 156-215.81.20 Pdf Dumps For Assured Success : https://drive.google.com/open?id=1zzknfP_HXjx-1pDN67VA0sJjS5TVLloC