[2022] Use Valid 156-215.81 Exam - Actual Exam Question & Answer
Test Engine to Practice 156-215.81 Test Questions
NEW QUESTION 245
When installing a dedicated R80 SmartEvent server, what is the recommended size of the root partition?
- A. More than 10GB and less than 20 GB
- B. At least 20GB
- C. Any size
- D. Less than 20GB
Answer: B
NEW QUESTION 246
What is the purpose of a Stealth Rule?
- A. To drop any traffic destined for the firewall that is not otherwise explicitly allowed.
- B. A rule at the end of your policy to drop any traffic that is not explicitly allowed.
- C. A rule that allows administrators to access SmartDashboard from any device.
- D. A rule used to hide a server's IP address from the outside world.
Answer: A
NEW QUESTION 247
What is the Manual Client Authentication TELNET port?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 248
Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.
- A. Failovers
- B. Asymmetric routing
- C. Anti-Spoofing
- D. Symmetric routing
Answer: A
NEW QUESTION 249
Fill in the blank: A(n) _____ rule is created by an administrator and is located before the first and before last rules in the Rule Base.
- A. Implicit drop
- B. Implied
- C. Firewall drop
- D. Explicit
- E. Implicit accept
Answer: B
Explanation:
This is the order that rules are enforced:
NEW QUESTION 250
Which option in a firewall rule would only match and allow traffic to VPN gateways for one Community in common?
- A. All Connections (Clear or Encrypted)
- B. Specific VPN Communities
- C. All Site-to-Site VPN Communities
- D. Accept all encrypted traffic
Answer: B
NEW QUESTION 251
Which of the following is NOT defined by an Access Role object?
- A. Source User
- B. Source Network
- C. Source Machine
- D. Source Server
Answer: D
NEW QUESTION 252
During the Check Point Stateful Inspection Process, for packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are:
- A. Dropped without logs and without sending a negative acknowledgment
- B. Dropped without sending a negative acknowledgment
- C. Dropped with logs and without sending a negative acknowledgment
- D. Dropped with negative acknowledgment
Answer: C
NEW QUESTION 253
One of major features in R80.x SmartConsole is concurrent administration. Which of the following is NOT possible considering that AdminA, AdminB, and AdminC are editing the same Security Policy?
- A. AdminA, AdminB and AdminC are editing three different rules at the same time.
- B. AdminA and AdminB are editing the same rule at the same time.
- C. AdminC sees a lock icon which indicates that the rule is locked for editing by another administrator.
- D. AdminB sees a pencil icon next the rule that AdminB is currently editing.
Answer: C
Explanation:
In SmartConsole, administrators work with sessions. A session is created each time an administrator logs into SmartConsole. Changes made in the session are saved automatically. These changes are private and available only to the administrator. To avoid configuration conflicts, other administrators see a lock icon on objects and rules that are being edited in other sessions.
Reference:
http://downloads.checkpoint.com/dc/download.htm?ID=65846
NEW QUESTION 254
Which is NOT an encryption algorithm that can be used in an IPSEC Security Association (Phase 2)?
- A. AES-GCM-256
- B. AES-CBC-256
- C. AES-GCM-128
Answer: B
NEW QUESTION 255
You are asked to check the status of several user-mode processes on the management server and gateway. Which of the following processes can only be seen on a Management Server?
- A. fwd
- B. fwm
- C. cpwd
- D. cpd
Answer: B
NEW QUESTION 256
Which of the following is NOT a policy type available for each policy package?
- A. Threat Emulation
- B. Access Control
- C. Desktop Security
- D. Threat Prevention
Answer: A
NEW QUESTION 257
You can see the following graphic:
What is presented on it?
- A. Expired .p12 certificate properties for user John.
- B. VPN certificate properties of the John's gateway.
- C. Properties of personal .p12 certificate file issued for user John.
- D. Shared secret properties of John's password.
Answer: C
NEW QUESTION 258
Which repositories are installed on the Security Management Server by SmartUpdate?
- A. License and Update
- B. Package Repository and Licenses
- C. License & Contract and Package Repository
- D. Update and License & Contract
Answer: C
NEW QUESTION 259
Which of the following Windows Security Events will NOT map a username to an IP address in Identity Awareness?
- A. Kerberos Ticket Timed Out
- B. Account Logon
- C. Kerberos Ticket Renewed
- D. Kerberos Ticket Requested
Answer: A
NEW QUESTION 260
Fill in the blank: In Security Gateways R75 and above, SIC uses ______________ for encryption.
- A. 3DES
- B. DES
- C. AES-128
- D. AES-256
Answer: C
NEW QUESTION 261
Fill in the blank: ________information is included in the "Full Log" tracking option, but is not included in the "Log" tracking option?
- A. file attributes
- B. destination port
- C. application
- D. data type
Answer: D
Explanation:
Tracking Options
NEW QUESTION 262
Which of the following is NOT an advantage to using multiple LDAP servers?
- A. You gain High Availability by replicating the same information on several servers
- B. Information on a user is hidden, yet distributed across several servers
- C. You achieve a faster access time by placing LDAP servers containing the database at remote sites
- D. You achieve compartmentalization by allowing a large number of users to be distributed across several servers
Answer: B
NEW QUESTION 263
Which command can you use to verify the number of active concurrent connections?
- A. fw ctl pst pstat
- B. fw conn all
- C. show all connections
- D. show connections
Answer: A
NEW QUESTION 264
Which Threat Prevention Profile is not included by default in R80 Management?
- A. Optimized - Provides excellent protection for common network products and protocols against recent or popular attacks
- B. Recommended - Provides all protection for all common network products and servers, with impact on network performance
- C. Basic - Provides reliable protection on a range of non-HTTP protocols for servers, with minimal impact on network performance
- D. Strict - Provides a wide coverage for all products and protocols, with impact on network performance
Answer: B
NEW QUESTION 265
......
156-215.81 Actual Questions Answers PDF 100% Cover Real Exam Questions: https://pdftorrent.actual4test.com/156-215.81_examcollection.html