Question No: 4

You want VPN traffic to match packets from internal interfaces. You also want the traffic to exit the Security Gateway bound for all site-to-site VPN Communities, including Remote Access Communities. How should you configure the VPN match rule?

A. internal_clear > All_communities

B. Internal_clear > External_Clear

C. Communities > Communities

D. internal_clear > All_GwToGw

Answer: A

Question No: 5

You cannot use SmartDashboardu2019s User Directory features to connect to the LDAP server. What should you investigate?

1) Verify you have read-only permissions as administrator for the operating system.

2) Verify there are no restrictions blocking SmartDashboard's User Manager from connecting to the LDAP server.

3) Check that the login Distinguished Name configured has root permission (or at least write permission Administrative access) in the LDAP Server's access control configuration.

A. 1, 2, and 3

B. 2 and 3

C. 1 and 2

D. 1 and 3

Answer: B

Question No: 6

Can you implement a complete IPv6 deployment without IPv4 addresses?

A. No. SmartCenter cannot be accessed from everywhere on the Internet.

B. Yes. Only one TCP stack (IPv6 or IPv4) can be used at the same time.

C. Yes, There is no requirement for managing IPv4 addresses.

D. No. IPv4 addresses are required for management.

Answer: C

Question No: 7

Complete this statement from the options provided. Using Captive Portal, unidentified users may be either; blocked, allowed to enter required credentials, or required to download the .

A. Identity Awareness Agent

B. Full Endpoint Client

C. ICA Certificate

D. SecureClient

Answer: A

Question No: 8

Which Check Point tool allows you to open a debug file and see the VPN packet exchange details.

A. PacketDebug.exe

B. VPNDebugger.exe

C. IkeView.exe

D. IPSECDebug.exe

Answer: C

Question No: 9

Type the full fw command and syntax that allows you to disable only sync on a cluster firewall member. Answer:

fw ctl setsync off


Question No: 10

How granular may an administrator filter an Access Role with identity awareness? Per:

A. Specific ICA Certificate

B. AD User

C. Radius Group

D. Windows Domain

Answer: B

Question No: 11

When deploying multiple clustered firewalls on the same subnet, what does the firewall administrator need to configure to prevent CCP broadcasts being sent to the wrong cluster?

A. Set the fwha_mac_magic_forward parameter in the $CPDIR/boot/modules/ha_boot. conf

B. Set the fwha_mac_magic parameter in the $FWDIR/boot/fwkern.conf file

C. Set the cluster global ID using the command u201ccphaconf cluster_id set <value>u201d

D. Set the cluster global ID using the command u201cfw ctt set cluster_id <value>u201d

Answer: C

Question No: 12

Which of the following items should be configured for the Security Management Server to authenticate via LDAP?

A. Check Point Password

B. Active Directory Server object

C. Windows logon password

D. WMI object

Answer: B

Question No: 13

Match the ClusterXL modes with their configurations. Exhibit:

A. A-2, B-3, C-4, D-1

B. A-2, B-3, C-1, D-5

C. A-3, B-5, C-1, D-4

D. A-5, B-2, C-4, D-1

Answer: C

