
[Dec-2021] 156-315.80 Braindumps – 156-315.80 Questions to Get Better Grades
156-315.80 Exam Dumps - Try Best 156-315.80 Exam Questions - ITPassLeader
Check Point 156-315.80 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Advanced Firewall | Objectives:
|
| CoreXL: Multicore Acceleration | - Supported Platforms and Features- Default Configuration - Processing Core Allocation - Allocating Processing Cores - Adding Processing Cores to the Hardware - Allocating an Additional Core to the SND - Allocating a Core for Heavy Logging - Packet Flows with SecureXL Enabled |
| VPN Debug | - vpn debug Command- vpn debug on | off - vpn debug ikeon |ikeoff - vpn Log Files - vpn debug trunc - VPN Environment Variables - vpn Command - vpn tu - Comparing SAs |
| Troubleshooting User Authentication and User Directory (LDAP) | - Common Configuration Pitfalls- Some LDAP Tools - Troubleshooting User Authentication |
| Identity Awareness | - Enabling AD Query- AD Query Setup - Identifying users behind an HTTP Proxy - Verifying there’s a logged on AD user at the source IP - Checking the source computer OS - Using SmartView Tracker |
| ClusterXL: Load Sharing | - Multicast Load Sharing- Unicast Load Sharing - How Packets Travel Through a Unicast - LS Cluster - Sticky Connections |
| SmartEvent | -SmartEvent Intro |
| Lab 1: Upgrading to Check PointR77 | - Install Security Management Server - Migrating Management server Data - Importing the Check Point Database - LaunchSmartDashboard - Upgrading the Security Gateway |
| Security Gateway | - User and Kernel Mode Processes- CPC Core Process -FWM - FWD -CPWD - Inbound and Outbound Packet Flow - Inbound FW CTL Chain Modules - Outbound Chain Modules - Columns in a Chain - Stateful Inspection |
| SecureXL: Security Acceleration | - What SecureXL Does- Packet Acceleration - Session Rate Acceleration - Masking the Source Port - Application Layer Protocol - An Example with HTTP HTTP 1.1 - Factors that Preclude Acceleration - Factors that Preclude Templating (Session Acceleration) - Packet Flow - VPN Capabilities |
| Kernel Tables | - Connections Table- Connections Table Format |
| Tunnel Management | - Permanent Tunnels- Tunnel Testing - VPN Tunnel Sharing - Tunnel-Management Configuration - Permanent-Tunnel Configuration - Tracking Options - Advanced Permanent-Tunnel configuration - VPN Tunnel Sharing Configuration |
| Upgrading | Objectives:
|
| Lab 7: SmartEvent and SmartReporter | - Configure the Network Object in SmartDashboard- Configuring Security Gateways to work with SmartEvent - Monitoring Events with SmartEvent - Generate Reports Based on Activities |
| SmartReporter | -Report Types |
| Auditing and Reporting | Objectives:
|
| Check Point Firewall Infrastructure | - GUI Clients - Management |
| Check Point Firewall Key Features | - Packet Inspection Flow- Policy Installation Flow - Policy Installation Process - Policy Installation Process Flow |
| Lab 4: Configuring SmartDashboard to Interface with Active Directory | - Creating the Active Directory Object in SmartDashboard- Verify SmartDashboard Communication with the AD Server |
| Upgrading Standalone Full High Availability | |
| User Management | - Active Directory OU Structure- Using LDAP Servers with Check Point - LDAP User Management with User Directory - Defining an Account Unit - Configuring Active Directory Schemas - Multiple User Directory (LDAP) Servers - Authentication Process Flow - Limitations of Authentication Flow - User Directory (LDAP) Profiles |
| Clustering and Acceleration | Objectives:
|
| Network Address Translation | - How NAT Works- Hide NAT Process - Security Servers - How a Security Server Works - Basic Firewall Administration - Common Commands |
| Troubleshooting | -VPN Encryption Issues |
| Advanced User Management | Objectives:
|
| VRRP | - VRRP vs ClusterXL- Monitored Circuit VRRP - Troubleshooting VRRP |
| FW Monitor | - What is FW Monitor- C2S Connections and S2C Packets fw monitor |
| Advanced IPsec VPN and Remote Access | Objectives:
|
| Clustering and Acceleration | - Clustering Terms- ClusterXL - Cluster Synchronization - Synchronized-Cluster Restrictions - Securing the Sync Interface - To Synchronize or Not to Synchronize |
| Multiple Entry Point VPNs | - How Does MEP Work- Explicit MEP - Implicit MEP |
| Advanced VPN Concepts and Practices | - IPsec- Internet Key Exchange (IKE) - IKE Key Exchange Process – Phase 1/ Phase 2 Stages |
| Lab 3 Migrating to a Clustering Solution | - Installing and Configuring the Secondary Security Gateway Re-configuring the Primary Gateway - Configuring Management Server Routing - Configuring the Cluster Object - Testing High Availability - Installing the Secondary Management Server - Configuring Management High Availability |
| Lab 5: Configure Site-to-Site VPNs with Third Party Certificates | - Configuring Access to the Active Directory Server- Creating the Certificate - Importing the Certificate Chain and Generating Encryption Keys - Installing the Certificate - Establishing Environment Specific Configuration - Testing the VPN Using 3rd Party Certificates |
| Management HA | - The Management High Availability Environment- Active vs. Standby - What Data is Backed Up? - Synchronization Modes - Synchronization Status |
| Lab 6: Remote Access with Endpoint Security VPN | - Defining LDAP Users and Groups- Configuring LDAP User Access - Defining Encryption Rules - Defining Remote Access Rules - Configuring the Client Side |
| Remote Access VPNs | - Connection Initiation- Link Selection |
| Backup and Restore Security Gateways and Management Servers | - Snapshot management - Upgrade Tools - Backup Schedule Recommendations - Upgrade Tools - Performing Upgrades - Support Contract |
| SmartEvent Architecture | - Component Communication Process- Event Policy User Interface |
| Lab 2: Core CLI Elements of Firewall Administration | - Policy Management and Status- Verification from the CLI - Using cpinfo - Run cpinfo on the Security Management Server - Analyzing cpinfo in InfoView - Using fw ctl pstat - Using tcpdump |
| Auditing and Reporting Process | -Auditing and Reporting Standards |
| Maintenance Tasks and Tools | - Perform a Manual Failover of the FW Cluster- Advanced Cluster Configuration |
What is the duration of the 156-315.80 Exam
- Number of Questions: 100
- Passing Score: 70%
- Length of Examination: 90 minutes
- Format: Multiple choices, multiple answers
NEW QUESTION 267
Fill in the blank: The R80 feature ______ permits blocking specific IP addresses for a specific time period.
- A. Suspicious Activity Monitoring
- B. Block Port Overflow
- C. Local Interface Spoofing
- D. Adaptive Threat Prevention
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Suspicious Activity Rules Solution
Suspicious Activity Rules is a utility integrated into SmartView Monitor that is used to modify access privileges upon detection of any suspicious network activity (for example, several attempts to gain unauthorized access).
The detection of suspicious activity is based on the creation of Suspicious Activity rules. Suspicious Activity rules are Firewall rules that enable the system administrator to instantly block suspicious connections that are not restricted by the currently enforced security policy. These rules, once set (usually with an expiration date), can be applied immediately without the need to perform an Install Policy operation Reference: https://sc1.checkpoint.com/documents/R76/ CP_R76_SmartViewMonitor_AdminGuide/17670.htm
NEW QUESTION 268
The CPD daemon is a Firewall Kernel Process that does NOT do which of the following?
- A. Pulls application monitoring status
- B. Secure Internal Communication (SIC)
- C. Transfers messages between Firewall processes
- D. Restart Daemons if they fail
Answer: A
NEW QUESTION 269
In R80.10, how do you manage your Mobile Access Policy?
- A. From the Dedicated Mobility Tab
- B. Through the Mobile Console
- C. Through the Unified Policy
- D. From SmartDashboard
Answer: D
NEW QUESTION 270
In SmartEvent, what are the different types of automatic reactions that the administrator can configure?
- A. Mail, Block Source, Block Destination, External Script, SNMP Trap
- B. Mail, Block Source, Block Event Activity, External Script, SNMP Trap
- C. Mail, Block Source, Block Event Activity, Packet Capture, SNMP Trap
- D. Mail, Block Source, Block Destination, Block Services, SNMP Trap
Answer: B
Explanation:
References:
NEW QUESTION 271
Fill in the blank: The R80 utility fw monitoris used to troubleshoot ________.
- A. User data base corruption
- B. LDAP conflicts
- C. Traffic issues
- D. Phase two key negotiations
Answer: C
Explanation:
Explanation/Reference:
Check Point's FW Monitor is a powerful built-in tool for capturing network traffic at the packet level. The FW Monitor utility captures network packets at multiple capture points along the FireWall inspection chains. These captured packets can be inspected later using the WireShark Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk30583
NEW QUESTION 272
Which file gives you a list of all security servers in use, including port number?
- A. $FWDIR/conf/serversd.conf
- B. $FWDIR/conf/fwauthd.conf
- C. $FWDIR/conf/servers.conf
- D. $FWDIR/conf/conf.conf
Answer: B
NEW QUESTION 273
Which of the following is NOT a VPN routing option available in a star community?
- A. To center only.
- B. To satellites through center only.
- C. To center, or through the center to other satellites, to Internet and other VPN targets.
- D. To center and to other satellites through center.
Answer: A,B
NEW QUESTION 274
Which of the following links will take you to the SmartView web application?
- A. Error! Hyperlink reference not valid. Management Server host name>smartviewweb
- B. Error! Hyperlink reference not valid. Management Server IP Address>/smartview
- C. Error! Hyperlink reference not valid. Management Server host name>/smartviewweb/
- D. Error! Hyperlink reference not valid. Management Server IP Address>/smartview/
Answer: D
Explanation:
References:
NEW QUESTION 275
In order to get info about assignment (FW, SND) of all CPUs in your SGW, what is the most accurate CLI command?
- A. fw ctl sdstat
- B. fw ctl affinity -l a -r -v
- C. cpinfo
- D. fw ctl multik stat
Answer: B
NEW QUESTION 276
To add a file to the Threat Prevention Whitelist, what two items are needed?
- A. File name and Gateway
- B. Object Name and MD5 signature
- C. MD5 signature and Gateway
- D. IP address of Management Server and Gateway
Answer: B
NEW QUESTION 277
What is the purpose of Priority Delta in VRRP?
- A. When an Interface is up, Effective Priority = Priority + Priority Delta
- B. When a box up, Effective Priority = Priority + Priority Delta
- C. When a box fail, Effective Priority = Priority - Priority Delta
- D. When an Interface fail, Effective Priority = Priority - Priority Delta
Answer: D
Explanation:
Each instance of VRRP running on a supported interface may monitor the link state of other interfaces. The monitored interfaces do not have to be running VRRP.
If a monitored interface loses its link state, then VRRP will decrement its priority over a VRID by the specified delta value and then will send out a new VRRP HELLO packet. If the new effective priority is less than the priority a backup platform has, then the backup platform will beging to send out its own HELLO packet.
Once the master sees this packet with a priority greater than its own, then it releases the VIP.
NEW QUESTION 278
You notice that your firewall is under a DDoS attack and would like to enable the Penalty Box feature, which command you use?
- A. sim erdos -x 1
- B. sim erdos -e 1
- C. sim erdos - m 1
- D. sim erdos -v 1
Answer: B
NEW QUESTION 279
You want to gather and analyze threats to your mobile device. It has to be a lightweight app. Which application would you use?
- A. SecuRemote
- B. Check Point Capsule Cloud
- C. Check Point Protect
- D. SmartEvent Client Info
Answer: C
Explanation:
Reference: https://www.insight.com/content/dam/insight-web/en_US/pdfs/check- point/mobile-threatprevention-behavioral-risk-analysis.pdf
NEW QUESTION 280
Which is not a blade option when configuring SmartEvent?
- A. Log Server
- B. Correlation Unit
- C. SmartEvent Unit
- D. SmartEvent Server
Answer: C
Explanation:
Explanation
On the Management tab, enable these Software Blades:
NEW QUESTION 281
What is the correct order of the default "fw monitor" inspection points?
- A. i, I, o, O
- B. i, o, I, O
- C. I, i, O, o
- D. 1, 2, 3, 4
Answer: B
NEW QUESTION 282
Please choose correct command to add an "emailserver1" host with IP address 10.50.23.90 using GAiA management CLI?
- A. mgmt: add host name ip-address 10.50.23.90
- B. add host name emailserver1 ip-address 10.50.23.90
- C. host name myHost12 ip-address 10.50.23.90
- D. mgmt: add host name emailserver1 ip-address 10.50.23.90
Answer: D
NEW QUESTION 283
CoreXL is supported when one of the following features is enabled:
- A. IPv6
- B. Route-based VPN
- C. IPS
- D. Overlapping NAT
Answer: C
Explanation:
CoreXL does not support Check Point Suite with these features:
References:
NEW QUESTION 284
CoreXL is supported when one of the following features is enabled:
- A. IPv6
- B. Route-based VPN
- C. IPS
- D. Overlapping NAT
Answer: C
Explanation:
CoreXL does not support Check Point Suite with these features:
NEW QUESTION 285
Which command shows detailed information about VPN tunnels?
- A. vpn tu
- B. cat $FWDIR/conf/vpn.conf
- C. cpview
- D. vpn tu tlist
Answer: D
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/ CP_R80.20_CLI_ReferenceGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/ CP_R80.20_CLI_ReferenceGuide/209239
NEW QUESTION 286
What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL Filtering, Anti- Virus, IPS, and Threat Emulation?
- A. Anti-Bot is a post-infection malware protection to prevent a host from establishing a connection to a Command & Control Center.
- B. Anti-Bot is the only protection mechanism which starts a counter-attack against known Command & Control Centers
- C. Anti-Bot is the only countermeasure against unknown malware
- D. Anti-Bot is the only signature-based method of malware protection.
Answer: A
Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_AntiBotAntiVirus_AdminGuide/index.html
NEW QUESTION 287
Using mgmt_cli, what is the correct syntax to import a host object called Server_1 from the CLI?
- A. mgmt_cli add object-host "Server_1" ip-address "10.15.123.10" --format json
- B. mgmt_cli add host name "Server_1" ip-address "10.15.123.10" --format json
- C. mgmt._cli add object "Server-1" ip-address "10.15.123.10" --format json
- D. mgmt_cli add-host "Server_1" ip_address "10.15.123.10" --format txt
Answer: B
Explanation:
Explanation/Reference:
Example:
mgmt_cli add host name "New Host 1" ip-address "192.0.2.1" --format json
* "--format json" is optional. By default the output is presented in plain text.
Reference: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-host~v1.1%20
NEW QUESTION 288
How many interfaces can you configure to use the Multi-Queue feature?
- A. 3 interfaces
- B. 4 interfaces
- C. 10 interfaces
- D. 5 interfaces
Answer: D
Explanation:
Note -
References:
NEW QUESTION 289
Which Check Point software blades could be enforced under Threat Prevention profile using Check Point
R80.10 SmartConsole application?
- A. IPS, Anti-Bot, URL Filtering, Application Control, Threat Emulation.
- B. Firewall, IPS, Anti-Bot, Anti-Virus, Threat Emulation.
- C. IPS, Anti-Bot, Anti-Virus, Threat Emulation, Threat Extraction.
- D. Firewall, IPS, Threat Emulation, Application Control.
Answer: C
NEW QUESTION 290
John detected high load on sync interface. Which is most recommended solution?
- A. Add a second interface to handle sync traffic
- B. For short connections like icmp service - delay sync for 2 seconds
- C. For short connections like http service - do not sync
- D. For FTP connections - do not sync
Answer: D
NEW QUESTION 291
......
Who should take the 156-315.80 exam
The Check Point Certified Security Expert certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled in System Security Consultant and Server Managers. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Check Point Certified Security Expert - R80 156-315.80 Exam certification provides proof of this advanced knowledge and skill. If a person has passed the prerequisite Check Point Certified Security Administrator (CCSA R80) 156-315.80 Exam and has following skills required of a Check Point Certified Security Expert - R80 156-315.80 Exam then he should take this exam.
- Deployment Platforms & Security Policies
- Monitoring Traffic & Connections
- Resolving Security Administration Issues
- Check Point Technologies
Verified 156-315.80 exam dumps Q&As with Correct 457 Questions and Answers: https://www.itpassleader.com/CheckPoint/156-315.80-dumps-pass-exam.html
Get New 156-315.80 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1ATE7ErmAT2i-x5Tu3B6fWOhRe3oliBge