[Q188-Q209] PASS 156-315.81 exam with CheckPoint Real Exam Questions - 100% Valid!

Share

PASS 156-315.81 exam with CheckPoint Real Exam Questions - 100% Valid!

Actual 156-315.81 Exam Recently Updated Questions with Free Demo

NEW QUESTION # 188
While using the Gaia CLI. what is the correct command to publish changes to the management server?

  • A. json publish
  • B. mgmt_cli commit
  • C. commit
  • D. mgmt publish

Answer: D


NEW QUESTION # 189
What are the three SecureXL Templates available in R81.10?

  • A. Accept Templates. Drop Templates. Reject Templates
  • B. PEP Templates. QoS Templates. VPN Templates
  • C. Accept Templates. Drop Templates. NAT Templates
  • D. Accept Templates. PDP Templates. PEP Templates

Answer: C


NEW QUESTION # 190
The following command is used to verify the CPUSE version:

  • A. [Expert@HostName:0]#show installer status
  • B. HostName:0>show installer status build
  • C. [Expert@HostName:0]#show installer status build
  • D. HostName:0>show installer build

Answer: B


NEW QUESTION # 191
SmartConsole R81 requires the following ports to be open for SmartEvent R81 management:

  • A. 19009,443
  • B. 19090,22
  • C. 19190,22
  • D. 18190,80

Answer: A


NEW QUESTION # 192
Which statement is true about ClusterXL?

  • A. Supports Dynamic Routing (Unicast and Multicast)
  • B. Does not support Dynamic Routing
  • C. Supports Dynamic Routing (Multicast Only)
  • D. Supports Dynamic Routing (Unicast Only)

Answer: A


NEW QUESTION # 193
What is the correct description for the Dynamic Balancing / Split feature?

  • A. Dynamic Balancing / Split dynamically distribute the traffic from one network interface to multiple SND's. The interface must support Multi-Queue. It is only available on Quantum Appliances (not on Quantum Spark or Open Server)
  • B. Dynamic Balancing / Split dynamically change the number of SND's and firewall instances based on the current load. It is only available on Quantum Appliances (not on Quantum Spark or Open Server)
  • C. Dynamic Balancing / Split dynamically distribute the traffic from one network interface to multiple SND's. The interface must support Multi-Queue. It is only available on Quantum Appliances and Open Server (not on Quantum Spark)
  • D. Dynamic Balancing / Split dynamically change the number of SND's and firewall instances based on the current load. It is only available on Quantum Appliances and Open Server (not on Quantum Spark)

Answer: B


NEW QUESTION # 194
When configuring SmartEvent Initial settings, you must specify a basic topology for SmartEvent to help it calculate traffic direction for events. What is this setting called and what are you defining?

  • A. Topology, and you are defining the Internal network
  • B. Internal addresses you are defining the gateways
  • C. Network, and defining your Class A space
  • D. Internal network(s) you are defining your networks

Answer: D


NEW QUESTION # 195
Using fw monitor you see the following inspection point notion E and i what does that mean?

  • A. E shows the packet leaving the external interface, i reaching the internal interface
  • B. E shows the packet before the VPN encryption, i after the inbound firewall VM
  • C. E shows the packet reaching the external interface, i leaving the internal interface
  • D. E shows the packet after the VPN encryption, i before the inbound firewall VM

Answer: D

Explanation:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-monitor.htm i (for example, eth4:i) Pre-Inbound - Before the inbound FireWall VM E (for example, eth4:E) Post-Outbound - VPN Outbound after encrypt


NEW QUESTION # 196
Which command lists firewall chain?

  • A. fw tab -t chainmod
  • B. fw chain module
  • C. fw list chain
  • D. fwctl chain

Answer: D

Explanation:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/CLI/fw-ctl-chain.htm#:~:text=Shows%20the%20list%20of%20Firewall%20Chain%20Modules.


NEW QUESTION # 197
What does it mean if Deyra sees the gateway status? (Choose the BEST answer.)

  • A. There is a blade reporting a problem.
  • B. VPN software blade is reporting a malfunction.
  • C. Security Gateway's MGNT NIC card is disconnected.
  • D. SmartCenter Server cannot reach this Security Gateway.

Answer: A


NEW QUESTION # 198
Which software blade does NOT accompany the Threat Prevention policy?

  • A. Application Control and URL Filtering
  • B. Anti-virus
  • C. Threat Emulation
  • D. IPS

Answer: A


NEW QUESTION # 199
In which scenario will an administrator need to manually define Proxy ARP?

  • A. When they configure a "Manual Hide NAT" which translates to an IP address that belongs to one of the firewall's interfaces.
  • B. When they configure an "Automatic Hide NAT" which translates to an IP address that does not belong to one of the firewall's interfaces.
  • C. When they configure a "Manual Static NAT" which translates to an IP address that does not belong to one of the firewall's interfaces.
  • D. When they configure an "Automatic Static NAT" which translates to an IP address that does not belong to one of the firewall's interfaces.

Answer: C

Explanation:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Working_with_Manual_NAT_Rules.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____2


NEW QUESTION # 200
Full synchronization between cluster members is handled by Firewall Kernel. Which port is used for this?

  • A. TCP port 265
  • B. UDP port 265
  • C. UDP port 256
  • D. TCP port 256

Answer: D

Explanation:
Synchronization works in two modes:
Full Sync transfers all Security Gateway kernel table information from one cluster member to another. It is handled by the fwd daemon using an encrypted TCP connection on port 256.
Delta Sync transfers changes in the kernel tables between cluster members. Delta sync is handled by the Security Gateway kernel using UDP connections on port 8116.


NEW QUESTION # 201
Within the Check Point Firewall Kernel resides Chain Modules, which are individually responsible for the inspection of a specific blade or feature that has been enabled in the configuration of the gateway. For Wire mode configuration, chain modules marked with _______ will not apply.

  • A. 00000001
  • B. ffffffff
  • C. 00000003
  • D. 00000002

Answer: A


NEW QUESTION # 202
What is the difference between an event and a log?

  • A. A log entry becomes an event when it matches any rule defined in Event Policy
  • B. Events are collected with SmartWorkflow form Trouble Ticket systems
  • C. Events are generated at gateway according to Event Policy
  • D. Log and Events are synonyms

Answer: A


NEW QUESTION # 203
Fill in the blank: An identity server uses a __________ for user authentication.

  • A. Shared secret
  • B. One-time password
  • C. Certificate
  • D. Token

Answer: A


NEW QUESTION # 204
Security Checkup Summary can be easily conducted within:

  • A. Views
  • B. Summary
  • C. Reports
  • D. Checkups

Answer: A


NEW QUESTION # 205
You had setup the VPN Community VPN-Stores'with 3 gateways. There are some issues with one remote gateway(1.1.1.1) and an your local gateway. What will be the best log filter to see only the IKE Phase 2 agreed networks for both gateways

  • A. action:"Key Install- AND 1.1.1.1 ANDQuick Mode
  • B. action:"Key Install" AND 1.1.1.1 AND Main Mode
  • C. Blade:"VPN" AND VPN-Stores AND Main Mode
  • D. Blade:"VPN" AND VPN-Stores AND Quick Mode

Answer: C


NEW QUESTION # 206
Which firewall daemon is responsible for the FW CLI commands?

  • A. cpd
  • B. fwd
  • C. cpm
  • D. fwm

Answer: B


NEW QUESTION # 207
What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL Filtering, Anti-Virus, IPS, and Threat Emulation?

  • A. Anti-Bot is a post-infection malware protection to prevent a host from establishing a connection to a Command & Control Center.
  • B. Anti-Bot is the only protection mechanism which starts a counter-attack against known Command & Control Centers
  • C. Anti-Bot is the only countermeasure against unknown malware
  • D. Anti-Bot is the only signature-based method of malware protection.

Answer: A


NEW QUESTION # 208
You need to see which hotfixes are installed on your gateway, which command would you use?

  • A. cpinfo -y all
  • B. cpinfo -h all
  • C. cpinfo -o hotfix
  • D. cpinfo -l hotfix

Answer: A


NEW QUESTION # 209
......

156-315.81 Free Sample Questions to Practice One Year Update: https://practicetorrent.exam4pdf.com/156-315.81-dumps-torrent.html