Question No: 1

The connection to the ClusterXL member u2021Au2021 breaks. The ClusterXL member u2021Au2021 status is now u2021downu2021. Afterwards the switch admin set a port to ClusterXL member u2021Bu2021 to u2021downu2021. What will happen?

A. ClusterXL member u2021Bu2021 also left the cluster.

B. ClusterXL member u2021Bu2021 stays active as last member.

C. Both ClusterXL members share load equally.

D. ClusterXL member u2021Au2021 is asked to come back to cluster.

Answer: B

Question No: 2

John is configuring a new R80 Gateway cluster but he can not configure the cluster as Third Party IP Clustering because this option is not available in Gateway Cluster Properties.

Whatu2021s happening?

A. ClusterXL needs to be unselected to permit third party clustering configuration.

B. Third Party Clustering is not available for R80 Security Gateways.

C. John has an invalid ClusterXL license.

D. John is not using third party hardware as IP Clustering is part of Check Pointu2021s IP Appliance.

Answer: A

Question No: 3

In SmartDashboard, Translate destination on client side is checked in Global Properties. When Network Address Translation is used:

A. It is not necessary to add a static route to the Gatewayu2021s routing table.

B. It is necessary to add a static route to the Gatewayu2021s routing table.

C. The Security Gatewayu2021s ARP file must be modified.

D. VLAN tagging cannot be defined for any hosts protected by the Gateway.

Answer: A

Question No: 4

Why would you not see a CoreXL configuration option in cpconfig?

A. The gateway only has one processor

B. CoreXL is not licenses

C. CoreXL is disabled via policy

D. CoreXL is not enabled in the gateway object

Answer: A

Question No: 5

Which of the following statements accurately describes the command upgrade_export?

A. upgrade_export stores network-configuration data, objects, global properties, and the database revisions prior to upgrading the Security Management Server.

B. Used primarily when upgrading the Security Management Server, upgrade_export stores all object databases and the /conf directories for importing to a newer Security Gateway version.

C. upgrade_export is used when upgrading the Security Gateway, and allows certain files to be included or excluded before exporting.

D. This command is no longer supported in GAiA.

Answer: B

Question No: 6

You are MegaCorpu2021s Security Administrator. There are various network objects which must be NATed. Some of them use the Automatic Hide NAT method, while others use the Automatic Static NAT method. What is the rule order if both methods are used together? Give the BEST answer.

A. The Administrator decides the rule order by shifting the corresponding rules up and down.

B. The Static NAT rules have priority over the Hide NAT rules and the NAT on a node has priority over the NAT on a network or an address range.

C. The Hide NAT rules have priority over the Static NAT rules and the NAT on a node has priority over the NAT on a network or an address range.

D. The rule position depends on the time of their creation. The rules created first are placed at the top; rules created later are placed successively below the others.

Answer: B

Question No: 7

To run GAiA in 64bit mode, which of the following is true?

1) Run set edition default 64-bit.

2) Install more than 4 GB RAM.

3) Install more than 4 TB of Hard Disk.

A. 1 and 3

B. 1 and 2

C. 2 and 3

D. 1, 2, and 3

Answer: B

Question No: 8

Which is a suitable command to check whether Drop Templates are activated or not?

A. fw ctl get int activate _drop_ templates

B. fwaccel stat

C. fwaccel stats

D. fw ctl templates u2013d

Answer: B

Question No: 9

Check Point APIs allow system engineers and developers to make changes to their organizationu2021s security policy with CLI tools and Web Services for all of the following except?

A. Create new dashboards to manage 3rd party task

B. Create products that use and enhance 3rd party solutions.

C. Execute automated scripts to perform common tasks.

D. Create products that use and enhance the Check Point Solution.

Answer: A


Check Point APIs let system administrators and developers make changes to the security policy with CLI tools and web-services. You can use an API to:

Use an automated script to perform common tasks

Integrate Check Point products with 3rd party solutions

Create products that use and enhance the Check Point solution

Question No: 10

You have a diskless appliance platform. How do you keep swap file wear to a minimum?

A. Issue FW-1 bases its package structure on the Security Management Server, dynamically loading when the firewall is booted.

B. The external PCMCIA-based flash extension has the swap file mapped to it, allowing easy replacement.

C. Use PRAM flash devices, eliminating the longevity.

D. A RAM drive reduces the swap file thrashing which causes fast wear on the device.

Answer: D

