Guide (New 2021) Actual CheckPoint 156-315.80 Exam Questions [Q122-Q138]

Share

Guide (New 2021) Actual CheckPoint 156-315.80 Exam Questions

156-315.80 Exam Dumps Pass with Updated 2021 Certified Exam Questions


How much 156-315.80 Exam Cost

The price of The price of the 156-315.80 exam is $250 USD.


Check Point CCSE Exam Certification Details:

Exam NameCheck Point Certified Security Expert (CCSE) R80
Exam Code156-315.80
Books / TrainingCCSE Training
Exam Price$250 (USD)
Sample QuestionsCheck Point CCSE Sample Questions
Number of Questions100
Duration90 mins
Passing Score70%
Schedule ExamPearson VUE

 

NEW QUESTION 122
What is the default shell for the command line interface?

  • A. Admin
  • B. Expert
  • C. Clish
  • D. Normal

Answer: C

Explanation:
The default shell of the CLI is called clish
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Gaia_WebAdmin/75697.htm

 

NEW QUESTION 123
Which of the following is NOT an alert option?

  • A. High alert
  • B. User defined alert
  • C. Mail
  • D. SNMP

Answer: A

 

NEW QUESTION 124
CoreXL is NOT supported when one of the following features is enabled: (Choose three)

  • A. Route-based VPN
  • B. IPv6
  • C. Overlapping NAT
  • D. IPS

Answer: A,B,C

Explanation:
CoreXL does not support Check Point Suite with these features:
Check Point QoS (Quality of Service)
Route-based VPN
IPv6 on IPSO
Overlapping NAT

 

NEW QUESTION 125
When simulating a problem on ClusterXL cluster with cphaprob -d STOP -s problem -t 0 register, to initiate a
failover on an active cluster member, what command allows you remove the problematic state?

  • A. cphaprob -d STOP unregister
  • B. cphaprob -d unregister STOP
  • C. cphaprob STOP unregister
  • D. cphaprob unregister STOP

Answer: A

 

NEW QUESTION 126
Which file contains the host address to be published, the MAC address that needs to be associated with the IP Address, and the unique IP of the interface that responds to ARP request?

  • A. $FWDIR/conf/local.arp
  • B. /opt/CPshrd-R80/conf/local.arp
  • C. /var/opt/CPshrd-R80/conf/local.arp
  • D. $CPDIR/conf/local.arp

Answer: A

 

NEW QUESTION 127

You are the administrator for ABC Corp. You have logged into your R80 Management server. You are making some changes in the Rule Base and notice that rule No.6 has a pencil icon next to it.
What does this mean?

  • A. This rule No. 6 has been marked for editing in another Management session.
  • B. This rule No. 6 has been marked for deletion in another Management session.
  • C. This rule No. 6 has been marked for editing in your Management session.
  • D. This rule No. 6 has been marked for deletion in your Management session.

Answer: C

 

NEW QUESTION 128
When gathering information about a gateway using CPINFO, what information is included or excluded when
using the "-x" parameter?

  • A. Output excludes connection table
  • B. Includes the registry
  • C. Does not resolve network addresses
  • D. Gets information about the specified Virtual System

Answer: D

 

NEW QUESTION 129
When gathering information about a gateway using CPINFO, what information is included or excluded when using the "-x" parameter?

  • A. Output excludes connection table
  • B. Includes the registry
  • C. Does not resolve network addresses
  • D. Gets information about the specified Virtual System

Answer: D

Explanation:
Explanation/Reference: https://www.networksecurityplus.net/2015/02/check-point-how-to-collect-cpinfo-cli.html

 

NEW QUESTION 130
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new CPU to replace the existing single core CPU. After installation, is the administrator required to perform any additional tasks?

  • A. Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway
  • B. Go to clash-Run cpstop | Run cpstart
  • C. Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores
  • D. Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway | Install Security Policy

Answer: A

 

NEW QUESTION 131
Which of the following Windows Security Events will not map a username to an IP address in Identity Awareness?

  • A. Kerberos Ticket Requested
  • B. Kerberos Ticket Timed Out
  • C. Account Logon
  • D. Kerberos Ticket Renewed

Answer: B

 

NEW QUESTION 132
What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?

  • A. VPN Routing Mode
  • B. Stateless Mode
  • C. Stateful Mode
  • D. Wire Mode

Answer: D

Explanation:
Wire Mode is a VPN-1 NGX feature that enables VPN connections to successfully fail over, bypassing Security Gateway enforcement. This improves performance and reduces downtime. Based on a trusted source and destination, Wire Mode uses internal interfaces and VPN Communities to maintain a private and secure VPN session, without employing Stateful Inspection. Since Stateful Inspection no longer takes place, dynamicrouting protocols that do not survive state verification in non-Wire Mode configurations can now be deployed.
The VPN connection is no different from any other connections along a dedicated wire, thus the meaning of "Wire Mode".
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30974

 

NEW QUESTION 133
What is the correct command to observe the Sync traffic in a VRRP environment?

  • A. fw monitor -e "accept port(6118;"
  • B. fw monitor -e "accept dst=224.0.0.18;"
  • C. fw monitor -e "accept proto=mcVRRP;"
  • D. fw monitor -e "accept[12:4,b]=224.0.0.18;"

Answer: B

 

NEW QUESTION 134
With MTA (Mail Transfer Agent) enabled the gateways manages SMTP traffic and holds external email with potentially malicious attachments. What is required in order to enable MTA (Mail Transfer Agent) functionality in the Security Gateway?

  • A. Traffic on port 25
  • B. Threat Prevention Software Blade Package
  • C. Endpoint Total Protection
  • D. Threat Cloud Intelligence

Answer: B

 

NEW QUESTION 135
At what point is the Internal Certificate Authority (ICA) created?

  • A. Upon creation of a certificate.
  • B. When an administrator initially logs into SmartConsole.
  • C. When an administrator decides to create one.
  • D. During the primary Security Management Server installation process.

Answer: D

Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_SecMan_WebAdmin/html_frameset.htm?
topic=documents/R76/CP_R76_SecMan_WebAdmin/13118

 

NEW QUESTION 136
SSL Network Extender (SNX) is a thin SSL VPN on-demand client that is installed on the remote user's machine via the web browser. What are the two modes of SNX?

  • A. Network and Application
  • B. Network and Layers
  • C. Application and Client Service
  • D. Virtual Adapter and Mobile App

Answer: A

Explanation:
Explanation/Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk67820

 

NEW QUESTION 137
You notice that your firewall is under a DDoS attack and would like to enable the Penalty Box feature, which
command you use?

  • A. sim erdos -x 1
  • B. sim erdos - m 1
  • C. sim erdos -v 1
  • D. sim erdos -e 1

Answer: D

 

NEW QUESTION 138
......

Pass Guaranteed Quiz 2021 Realistic Verified Free CheckPoint: https://actualtorrent.realvce.com/156-315.80-VCE-file.html