Verified 156-215.80 Exam Dumps Q&As - Provide 156-215.80 with Correct Answers [Q39-Q55]

Share

Verified 156-215.80 Exam Dumps Q&As - Provide 156-215.80 with Correct Answers

Pass Your 156-215.80 Dumps Free Latest CheckPoint Practice Tests


Who should take the 156-215.80 exam

The Check Point Certified Security Administrator certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled in Security Administrator and Check Point Professionals. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Check Point Certified Security Administrator (CCSA R80) 156-215.80 Exam certification provides proof of this advanced knowledge and skill. If a person has the prerequisite TCP/IP and routing fundamentals knowledge and skills required of a Check Point Certified Security Administrator (CCSA R80) 156-215.80 Exam then he should take this exam.

 

NEW QUESTION 39
In order to modify Security Policies the administrator can use which of the following tools?
Select the BEST answer.

  • A. SmartConsole or mgmt_cli on any computer where SmartConsole is installed.
  • B. mgmt_cli or WebUI on Security Gateway and SmartConsole on the Security
    Management Server.
  • C. SmartConsole and WebUI on the Security Management Server.
  • D. Command line of the Security Management Server or mgmt_cli.exe on any Windows computer.

Answer: A

 

NEW QUESTION 40
Study the Rule base and Client Authentication Action properties screen.


After being authenticated by the Security Gateways, a user starts a HTTP connection to a Web site. What happens when the user tries to FTP to another site using the command line? The:

  • A. FTP data connection is dropped after the user is authenticated successfully.
  • B. user is prompted to authenticate from that FTP site only, and does not need to enter his username and password for Client Authentication
  • C. user is prompted for authentication by the Security Gateways again.
  • D. FTP connection is dropped by Rule 2.

Answer: B

 

NEW QUESTION 41
When connected to the Check Point R80 Management Server using the SmartConsole the first administrator to connect has a lock on:

  • A. The entire Management Database and all sessions and other administrators can connect only as Read- only.
  • B. Only the objects being modified in his session of the Management Database and other administrators can connect to make changes using different sessions.
  • C. The entire Management Database and other administrators can connect to make changes only if the first administrator switches to Read-only.
  • D. Only the objects being modified in the Management Database and other administrators can connect to make changes using a special session as long as they all connect from the same LAN network.

Answer: B

Explanation:
Explanation

 

NEW QUESTION 42
Which of the following is NOT a license activation method?

  • A. Online Activation
  • B. SmartConsole Wizard
  • C. License Activation Wizard
  • D. Offline Activation

Answer: B

 

NEW QUESTION 43
A _______ is used by a VPN gateway to send traffic as if it was a physical interface.

  • A. VPN community
  • B. VPN Tunnel Interface
  • C. VPN interface
  • D. VPN router

Answer: B

Explanation:
Route Based VPN
VPN traffic is routed according to the routing settings (static or dynamic) of the Security Gateway operating system. The Security Gateway uses a VTI (VPN Tunnel Interface) to send the VPN traffic as if it was a physical interface. The VTIs of Security Gateways in a VPN community connect and can support dynamic routing protocols.
Reference: http://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/13868.htm

 

NEW QUESTION 44
How are the backups stored in Check Point appliances?

  • A. Saved as*tgz under /var/log/CPbackup/backups
  • B. Saved as*tgz under /var/CPbackup
  • C. Saved as*.tar under /var/log/CPbackup/backups
  • D. Saved as*tar under /var/CPbackup

Answer: B

Explanation:
Backup configurations are stored in: /var/CPbackup/backups/
Reference:
https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/ html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/107104

 

NEW QUESTION 45
On the following graphic, you will find layers of policies.

What is a precedence of traffic inspection for the defined polices?

  • A. A packet arrives at the gateway, it is checked against the rules in the networks policy layer and then if there is any rule which accepts the packet, it comes next to IPS layer and then after accepting the packet it passes to Threat Prevention layer
  • B. A packet arrives at the gateway, it is checked against the rules in the networks policy layer and then if there is any rule which accepts the packet, it comes next to Threat Prevention layer and then after accepting the packet it passes to IPS layer.
  • C. A packet arrives at the gateway, it is checked against the rules in the networks policy layer and then if implicit Drop Rule drops the packet, it comes next to IPS layer and then after accepting the packet it passes to Threat Prevention layer.
  • D. A packet arrives at the gateway, it is checked against the rules in IPS policy layer and then it comes next to the Network policy layer and then after accepting the packet it passes to Threat Prevention layer.

Answer: A

Explanation:
Explanation/Reference:
Explanation: To simplify Policy management, R80 organizes the policy into Policy Layers. A layer is a set of rules, or a Rule Base.
For example, when you upgrade to R80 from earlier versions:
Gateways that have the Firewall and the Application Control Software Blades enabled will have their

Access Control Policy split into two ordered layers: Network and Applications.
When the gateway matches a rule in a layer, it starts to evaluate the rules in the next layer.
Gateways that have the IPS and Threat Emulation Software Blades enabled will have their Threat

Prevention policies split into two parallel layers: IPS and Threat Prevention.
All layers are evaluated in parallel
Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SecMGMT/html_frameset.htm?
topic=documents/R80/CP_R80_SecMGMT/126197

 

NEW QUESTION 46
Choose the Best place to find a Security Management Server backup file named backup_fw, on a Check Point Appliance.

  • A. /var/log/Cpbackup/backups/backup/backup_fw.tgs
  • B. /var/log/Cpbackup/backups/backup/backup_fw.tar
  • C. /var/log/Cpbackup/backups/backup_fw.tgz
  • D. /var/log/Cpbackup/backups/backups/backup_fw.tar

Answer: C

Explanation:
Explanation
Gaia's Backup feature allows backing up the configuration of the Gaia OS and of the Security Management server database, or restoring a previously saved configuration.
The configuration is saved to a .tgz file in the following directory:
Gaia OS Version
Hardware
Local Directory
R75.40 - R77.20
Check Point appliances
/var/log/CPbackup/backups/
Open Server
/var/CPbackup/backups/
R77.30
Check Point appliances
/var/log/CPbackup/backups/
Open Server

 

NEW QUESTION 47
Choose what BEST describes the Policy Layer Traffic Inspection.

  • A. If a packet does not match any of the inline layers, the matching continues to the next Layer.
  • B. If a packet does not match any of the inline layers, the packet will be matched against the Implicit Clean-up Rule.
  • C. If a packet does not match a Network Policy Layer, the matching continues to its inline layer.
  • D. If a packet matches an inline layer, it will continue matching the next layer.

Answer: D

 

NEW QUESTION 48
Identify the API that is not supported by Check Point currently.

  • A. Open REST API
  • B. R80 Management API-
  • C. OPSEC SDK
  • D. Identity Awareness Web Services API

Answer: A

Explanation:
Explanation/Reference:
Reference: http://dl3.checkpoint.com/paid/29/29532b9eec50d0a947719ae631f640d0/ CP_R80_CheckPoint_API_ReferenceGuide.pdf?
HashKey=1517091458_be29bd4732d8d22283df32ccaaffc482&xtn=.pdf

 

NEW QUESTION 49
Examine the following Rule Base.

What can we infer about the recent changes made to the Rule Base?

  • A. Te rules 1, 5 and 6 cannot be edited by the 'admin' administrator
  • B. Rule 1 and object webserver are locked by another administrator
  • C. 8 changes have been made by administrators since the last policy installation
  • D. Rule 7 was created by the 'admin' administrator in the current session

Answer: B

Explanation:
Explanation/Reference:
Explantation: On top of the print screen there is a number "8" which consists for the number of changes made and not saved.
Session Management Toolbar (top of SmartConsole)

Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_SecMGMT/html_frameset.htm?
topic=documents/R80/CP_R80_SecMGMT/117948

 

NEW QUESTION 50
Joey wants to configure NTP on R80 Security Management Server. He decided to do this via WebUI. What is
the correct address to access the Web UI for Gaia platform via browser?

  • A. https://<Device_IP_Address>:4434
  • B. https://<Device_IP_Address>
  • C. https://<Device_IP_Address>:443
  • D. https://<Device_IP_Address>:10000

Answer: B

Explanation:
Explanation
Access to Web UI Gaia administration interface, initiate a connection from a browser to the default
administration IP address: Logging in to the WebUI
Logging in
To log in to the WebUI:
https://<Gaia IP address>

 

NEW QUESTION 51
Which command is used to add users to or from existing roles?

  • A. Add user <User Name>
  • B. Add user <User Name> roles <List>
  • C. Add rba user <User Name>
  • D. Add rba user <User Name> roles <List>

Answer: D

Explanation:
Configuring Roles - CLI (rba)

Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Gaia_WebAdmin/73101.htm

 

NEW QUESTION 52
Packages and licenses are loaded from all of these sources EXCEPT

  • A. Check Point DVD
  • B. User Center
  • C. UserUpdate
  • D. Download Center Web site

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Packages and licenses are loaded into these repositories from several sources:
* the Download Center web site (packages)
* the Check Point DVD (packages)
* the User Center (licenses)
* by importing a file (packages and licenses)
* by running the cpliccommand line
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Installation_and_Upgrade_Guide- webAdmin/13128.htm

 

NEW QUESTION 53
RADIUS protocol uses ______ to communicate with the gateway.

  • A. CCP
  • B. TDP
  • C. UDP
  • D. HTTP

Answer: C

Explanation:
Parameters:

 

NEW QUESTION 54
You are unable to login to SmartDashboard. You log into the management server and run #cpwd_admin list with the following output:

What reason could possibly BEST explain why you are unable to connect to SmartDashboard?

  • A. CDP is down
  • B. CPSM is down
  • C. SVR is down
  • D. FWM is down

Answer: D

Explanation:
Explanation
The correct answer would be FWM (is the process making available communication between SmartConsole applications and Security Management Server.). STATE is T (Terminate = Down) Symptoms
[Expert@HostName:0]# ps -aux | grep fwm
[Expert@HostName:0]# cpwd_admin start -name FWM -path "$FWDIR/bin/fwm" -command "fwm"

 

NEW QUESTION 55
......


Test Requisites

To sit for the Check Point 156-80 or Check Point Certified Security Administrator (CCSA R80) exam, the students must satisfy a few prerequisites as listed below:

  • They need to have 6 months or 1 year of experience working with Check point products;
  • Have some fundamental knowledge of networking.

What is the duration of the 156-215.80 Exam

  • Length of Examination: 90 minutes
  • Format: Multiple choices, multiple answers
  • Passing Score: 70%
  • Number of Questions: 100

 

Get Top-Rated CheckPoint 156-215.80 Exam Dumps Now: https://www.exams4sures.com/CheckPoint/156-215.80-practice-exam-dumps.html