Pass Your 156-215.81.20 Exam at the First Try with 100% Real Exam Questions
New CheckPoint 156-215.81.20 Dumps & Questions Updated on 2024
NEW QUESTION # 217
Which option would allow you to make a backup copy of the OS and Check Point configuration, without stopping Check Point processes?
- A. migrate export
- B. backup
- C. snapshot
- D. All options stop Check Point processes
Answer: C
NEW QUESTION # 218
Choose what BEST describes a Session
- A. Starts when an Administrator publishes all the changes made on SmartConsole
- B. Sessions ends when policy is pushed to the Security Gateway.
- C. Sessions locks the policy package for editing.
- D. Starts when an Administrator logs in through SmartConsole and ends when the Administrator logs out.
Answer: D
NEW QUESTION # 219
When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition?
- A. Any size
- B. More than 10GB and less than 20 GB
- C. Less than 20GB
- D. At least 20GB
Answer: D
NEW QUESTION # 220
Gaia includes Check Point Upgrade Service Engine (CPUSE), which can directly receive updates for what components?
- A. The Security Gateway (SG) and Security Management Server (SMS) software and the CPUSE engine.
- B. The CPUSE engine and the Gaia operating system.
- C. The Gaia operating system only.
- D. Licensed Check Point products for the Gala operating system and the Gaia operating system itself.
Answer: D
NEW QUESTION # 221
When URL Filtering is set, what identifying data gets sent to the Check Point Online Web Service?
- A. The URL and server certificate are sent to the Check Point Online Web Service
- B. The URL and IP address are sent to the Check Point Online Web Service
- C. The host part of the URL is sent to the Check Point Online Web Service
- D. The full URL, including page data, is sent to the Check Point Online Web Service
Answer: C
NEW QUESTION # 222
With URL Filtering, what portion of the traffic is sent to the Check Point Online Web Service for analysis?
- A. The complete communication is sent for inspection.
- B. The IP address of the source machine.
- C. The host portion of the URL.
- D. The end user credentials.
Answer: C
NEW QUESTION # 223
A security zone is a group of one or more network interfaces from different centrally managed gateways.
What is considered part of the zone?
- A. The local directly connected subnet defined by the subnet IP and subnet mask.
- B. The zone is based on the network topology and determined according to where the interface leads to.
- C. The firewall rule can be configured to include one or more subnets in a zone.
- D. Security Zones are not supported by Check Point firewalls.
Answer: B
NEW QUESTION # 224
In a Distributed deployment, the Security Gateway and the Security Management software are installed on what platforms?
- A. Different computers or appliances.
- B. Both on virtual machines or both on appliances but not mixed.
- C. In Azure and AWS cloud environments.
- D. The same computer or appliance.
Answer: A
NEW QUESTION # 225
In which deployment is the security management server and Security Gateway installed on the same appliance?
- A. Distributed
- B. Bridge Mode
- C. Standalone
- D. Remote
Answer: C
NEW QUESTION # 226
Which option in a firewall rule would only match and allow traffic to VPN gateways for one Community in common?
- A. Accept all encrypted traffic
- B. Specific VPN Communities
- C. All Connections (Clear or Encrypted)
- D. All Site-to-Site VPN Communities
Answer: B
NEW QUESTION # 227
In order to modify Security Policies, the administrator can use which of the following tools? (Choose the best answer.)
- A. mgmt_cli (API) or WebUI on Security Gateway and SmartConsole on the Security Management Server.
- B. Command line of the Security Management Server or mgmt_cli.exe on any Windows computer.
- C. SmartConsole or mgmt_cli (API) on any computer where SmartConsole is installed.
- D. SmartConsole and WebUI on the Security Management Server.
Answer: C
NEW QUESTION # 228
What type of NAT is a one-to-one relationship where each host is translated to a unique address?
- A. Destination
- B. Source
- C. Static
- D. Hide
Answer: C
NEW QUESTION # 229
You can see the following graphic:
What is presented on it?
- A. Shared secret properties of John's password.
- B. Expired. p12 certificate properties for user John.
- C. Properties of personal. p12 certificate file issued for user John.
- D. VPN certificate properties of the John's gateway.
Answer: C
NEW QUESTION # 230
Name one limitation of using Security Zones in the network?
- A. Security zones cannot be used in network topology
- B. Security zones will not work in Automatic NAT rules
- C. Security zone will not work in Manual NAT rules
- D. Security zones will not work in firewall policy layer
Answer: C
NEW QUESTION # 231
What is the default shell of Gaia CLI?
- A. clish
- B. Monitor
- C. Bash
- D. Read-only
Answer: A
NEW QUESTION # 232
Choose what BEST describes the reason why querying logs now are very fast.
- A. Indexing Engine indexes logs for faster search results.
- B. The amount of logs being stored is less than previous versions.
- C. SmartConsole now queries results directly from the Security Gateway.
- D. New Smart-1 appliances double the physical memory install.
Answer: A
NEW QUESTION # 233
Which of the following statements about Site-to-Site VPN Domain-based is NOT true?
- A. Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a service or user that can send or receive VPN traffic through a VPN Gateway.
- B. Route-based- The Security Gateways will have a Virtual Tunnel Interface (VTI) for each VPN Tunnel with a peer VPN Gateway. The Routing Table can have routes to forward traffic to these VTls. Any traffic routed through a VTI is automatically identified as VPN Traffic and is passed through the VPN Tunnel associated with the VTI.
- C. Domain-based- VPN domains are pre-defined for all VPN Gateways. When the Security Gateway encounters traffic originating from one VPN Domain with the destination to a VPN Domain of another VPN Gateway, that traffic is identified as VPN traffic and is sent through the VPN Tunnel between the two Gateways.
- D. Domain-based- VPN domains are pre-defined for all VPN Gateways. A VPN domain is a host or network that can send or receive VPN traffic through a VPN Gateway.
Answer: A
NEW QUESTION # 234
The "Hit count" feature allows tracking the number of connections that each rule matches.
Will the Hit count feature work independently from logging and Track the hits even if the Track option is set to "None"?
- A. No, it will not work independently. Hit Count will be shown only for rules with Track options set as Log or alert
- B. Yes, it will work independently as long as "analyze all rules" tick box is enabled on the Security Gateway
- C. Yes, it will work independently because when you enable Hit Count, the SMS collects the data from supported Security Gateways
- D. No, it will not work independently because hit count requires all rules to be logged
Answer: C
NEW QUESTION # 235
......
Updated Exam 156-215.81.20 Dumps with New Questions: https://pass4sure.troytecdumps.com/156-215.81.20-troytec-exam-dumps.html