New Check Point 156-915.80 Exam Dumps Collection (Question 6 - Question 15)

Question No: 6

Review the Rule Base displayed.

For which rules will the connection templates be generated in SecureXL?

A. Rules 2 and 5

B. Rules 2 through 5

C. Rule 2 only

D. All rules except Rule 3

Answer: D

Question No: 7

Which command will only show the number of entries in the connection table?

A. fw tab -t connections -s

B. fw tab -t connections -u

C. fw tab -t connections

D. fw tab

Answer: A

Question No: 8

Which three of the following are ClusterXL member requirements?

1) same operating systems

2) same Check Point version

3) same appliance model

4) same policy

A. 1, 3, and 4

B. 1, 2, and 4

C. 2, 3, and 4

D. 1, 2, and 3

Answer: B

Question No: 9

Looking at the SYN packets in the Wireshark output, select the statement that is true about NAT.

A. This is an example of Hide NAT.

B. There is not enough information provided in the Wireshark capture to determine the NAT settings.

C. This is an example of Static NAT and Translate destination on client side unchecked in Global Properties.

D. This is an example of Static NAT and Translate destination on client side checked in Global Properties.

Answer: D

Question No: 10

Your company is running Security Management Server R80 on GAiA, which has been migrated through each version starting from Check Point 4.1. How do you add a new administrator account?

A. Using SmartDashboard, under Users, select Add New Administrator

B. Using SmartDashboard or cpconfig

C. Using the Web console on GAiA under Product configuration, select Administrators

D. Using cpconfig on the Security Management Server, choose Administrators

Answer: A

Question No: 11

Paul has just joined the MegaCorp security administration team. Natalie, the administrator, creates a new administrator account for Paul in SmartDashboard and installs the policy. When Paul tries to login it fails. How can Natalie verify whether Paulu2021s IP address is predefined on the security management server?

A. Login to Smart Dashboard, access Properties of the SMS, and verify whether Paulu2021s IP address is listed.

B. Type cpconfig on the Management Server and select the option u201cGUI client Listu201d to see if Paulu2021s IP address is listed.

C. Login in to Smart Dashboard, access Global Properties, and select Security Management, to verify whether Paulu2021s IP address is listed.

D. Access the WEBUI on the Security Gateway, and verify whether Paulu2021s IP address is listed as a GUI client.

Answer: B

Question No: 12

What is the primary benefit of using the command upgrade_export over either backup or snapshot?

A. upgrade_export is operating system independent and can be used when backup or snapshot is not available.

B. upgrade_export will back up routing tables, hosts files, and manual ARP configurations, where backup and snapshot will not.

C. The commands backup and snapshot can take a long time to run whereas upgrade_export will take a much shorter amount of time.

D. upgrade_export has an option to back up the system and SmartView Tracker logs while backup and snapshot will not.

Answer: A

Question No: 13

MegaCorp is running Smartcenter R70, some Gateways at R65 and some other Gateways with R60. Management wants to upgrade to the most comprehensive IPv6 support. What should the administrator do first?

A. Upgrade Smartcenter to R80 first.

B. Upgrade R60-Gateways to R65.

C. Upgrade every unit directly to R80.

D. Check the ReleaseNotes to verify that every step is supported.

Answer: D

Question No: 14

You have three servers located in a DMZ, using private IP addresses. You want internal users from 10.10.10.x to access the DMZ servers by public IP addresses. Internal_net 10.10.10.x is configured for Hide NAT behind the Security Gatewayu2021s external interface.

What is the best configuration for 10.10.10.x users to access the DMZ servers, using the DMZ serversu2021 public IP addresses?

A. When connecting to internal network 10.10.10.x, configure Hide NAT for the DMZ network behind the Security Gateway DMZ interface.

B. When the source is the internal network 10.10.10.x, configure manual static NAT rules to translate the DMZ servers.

C. When connecting to the Internet, configure manual Static NAT rules to translate the DMZ servers.

D. When trying to access DMZ servers, configure Hide NAT for 10.10.10.x behind the DMZu2021s interface.

Answer: B

Question No: 15

Match the VPN-related terms with their definitions. Each correct term is only used once. Exhibit:

A. A-3, B-4, C-1, D-5

B. A-4, B-3, C-5, D-2

C. A-2, B-5, C-4, D-1

D. A-3, B-2, C-1, D-4

Answer: B

