Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Checkpoint 156-315.82 Check Point Certified Security Expert R82 Exam Practice Test

Demo: 38 questions
Total 128 questions

Check Point Certified Security Expert R82 Questions and Answers

Question 1

SmartEvent general settings and event policy are configured using which interface or tool?

Options:

A.

SmartEvent GUI Client

B.

SmartView in Web Browser

C.

SmartConsole Logs & Monitor

D.

SmartLog

Question 2

Which technology family does ElasticXL belong to?

Options:

A.

ClusterXL

B.

Scalable Platforms

C.

SecurePlatform

D.

SyncXL

Question 3

Alice and Bob are tasked by their security team lead with deploying Advanced Security Monitoring for all their Check Point Security systems. Which of the features and capabilities of SmartEvent is included?

Options:

A.

Statistics forensics and log investigation

B.

Real-time logging and status investigation

C.

Historical forensics and real-time investigation

D.

Real-time forensic and event investigation

Question 4

What should be upgraded first in Advanced Upgrade Method?

Options:

A.

Dedicated Log Server

B.

Secondary Management Server

C.

Primary Management Server

D.

Security Gateway

Question 5

In SmartConsole, where can the administrator adjust the timing of the Security Management High Availability automatic synchronization?

Options:

A.

Edit the Primary SMS object and click Other > Management HA.

B.

Automatic synchronization is not available in Security Management HA and must be done manually.

C.

Synchronization settings are preconfigured and cannot be changed by the administrator.

D.

Global Properties > Advanced > Management High Availability.

Question 6

What happens if two VPN Gateways are members of different VPN Communities?

Options:

A.

During renegotiation both parties will generate a random number. The higher number wins and can decide which Security Association to take.

B.

The weaker encryption algorithm in Phase 1 and Phase 2 will be used.

C.

The stronger encryption algorithm for Phase 1 and Phase 2 will be used.

D.

This is a non-supported configuration.

Question 7

To which directory does CPTA transfer policy files on the Security Gateway?

Options:

A.

$FWDIR/state/_tmp/FW1

B.

$FWDIR/state/local/FW1

C.

$CPDIR/state/tmp/FW1

D.

$FWDIR/state_tmp/FW1

Question 8

How many Secondary Security Management Servers does Check Point allow a customer to deploy?

Options:

A.

On-premises deployments allow only one Secondary server. Public cloud deployments allow multiple Secondary servers.

B.

You can install only one Secondary Security Management Server. The licenses limit the solution to only one Standby server.

C.

You can install one or more Secondary Security Management Servers.

D.

You can install only one Security Management Server. The Active server can only synchronize to one Standby server.

Question 9

In a standard HA configuration, what is known as Collision Mode?

Options:

A.

There are situations where there might be more than one Primary Management Server.

B.

This happens when the Primary and Secondary Management Servers have issues synchronizing their local time.

C.

There are situations where there might be more than one Standby Management Server.

D.

There are situations where there might be more than one Active Management Server.

Question 10

What is true when using the In-place upgrade method?

Options:

A.

Only cluster members are allowed to be upgraded with this method.

B.

Only Management Servers are allowed to be upgraded with this method. Security Gateways must be upgraded using Central Deployment or a fresh installation.

C.

Only the Primary and Secondary Management Servers are allowed to be upgraded with this method.

D.

Any of the Management Servers or Gateways are allowed to be upgraded using this method.

Question 11

Alice knows about the Check Point Management HA installation from Bob and needs to know which Check Point Security Management Server is currently in the “Active” state. Alice uses the Check Point SmartConsole tool. Which Check Point console location is needed to look up the Management High Availability status?

Options:

A.

SmartView Tracker > Log Search > HA Status

B.

SmartUpdate > Package Repository > Management High Availability

C.

Gaia Portal > Overall View > Management High Availability

D.

Check Point SmartConsole > Menu > Management High Availability

Question 12

Choose the correct command to export the Management Database with logs and log indexes.

Options:

A.

$FWDIR/scripts/migrate_server export -v < target version > -n < file >

B.

$FWDIR/bin/upgrade_tools/migrate export -l < file >

C.

$FWDIR/scripts/migrate_server export -v < target version > -x < file >

D.

$FWDIR/bin/upgrade_tools/migrate export -x < file >

Question 13

ElasticXL Cluster provides a better administrator experience and performance than legacy ClusterXL. The Single Management Object, SMO, provides IP access for use in management communication and policy installation, simplifying the management process. How many IP addresses are used for the management communication?

Options:

A.

3 IP addresses

B.

1 single IP address

C.

4 IP addresses

D.

2 IP addresses

Question 14

Network Feed objects are used as a Source or Destination in Access Control, HTTPS Inspection, and Threat Prevention Policies. What file formats are supported for download in Network Feed objects?

Options:

A.

Flat list only

B.

Flat list and XML

C.

JSON only

D.

Flat list or JSON

Question 15

When installing policy, which process is responsible for verification/conversion?

Options:

A.

CPD

B.

CPM

C.

FWM

D.

FWD

Question 16

With R81 and higher, what are the two types of database dumps?

Options:

A.

CPD Dump and CPM Dump

B.

CPM Dump and Monitoring Dump

C.

Legacy Dump and Modern Dump

D.

FWD Dump and AUM Dump

Question 17

How would you import an exported Management Database?

Options:

A.

$FWDIR/usr/bin/migrate import / < Path > / < ExportFileName >

B.

$FWDIR/scripts/migrate_server import -v R82 / < Path > / < ExportFileName > .tgz

C.

$FWDIR/bin/upgrade_tools/migrate import

D.

You can only accomplish this task via Gaia Portal.

Question 18

How does SmartEvent determine whether events originated internally or externally?

Options:

A.

By defining the Internal Network under the Initial Settings in the SmartEvent GUI Client.

B.

Events with non-routable private source IPs are considered to be originating from internal networks.

C.

SmartEvent queries Security Gateway topology to determine the direction of events.

D.

SmartEvent uses AI/ML to determine the direction of events.

Question 19

SmartEvent reports can be exported to which formats?

Options:

A.

CSV, XLS, DOC

B.

PDF, DOC, CSV

C.

PDF, CSV

D.

TXT, CSV, PDF

Question 20

What is the command to get the state information of the interfaces of a cluster node?

Options:

A.

get cluster elastic interfaces

B.

show interfaces -a

C.

show cluster info interfaces

D.

ifconfig -a -ax

Question 21

What is crucial in translating services, specifically destination ports, in a NAT rule?

Options:

A.

This can only be accomplished with the Automatic NAT Rule with “Translate Destination on Server Side” enabled.

B.

This can only be accomplished with Automatic NAT Rule in conjunction with Bi-Directional NAT.

C.

This can only be accomplished with the Automatic NAT Rule with “Automatic ARP Configuration” enabled.

D.

This has to be done with a Manual NAT Rule.

Question 22

According to the policy installation flow, the transfer stage, CPTA, is invoked by the FWM process, which initiates the Transfer/Commit phase. On the Security Gateway side, a process receives the policy files and first stores them into a temporary directory. Which process is responsible for receiving these files?

Options:

A.

FWD

B.

CPD

C.

FWM

D.

RAD

Question 23

Which components can be upgraded using Central Deployment Tool, CDT?

Options:

A.

Gateways / Cluster Members

B.

Multi-Domain Servers, Management Servers, and Gateways

C.

Gateways, Clusters, and Management Servers

D.

Gateways, Clusters, and Standalone Deployments

Question 24

With release R82 and higher, ElasticXL Cluster is an alternative to the existing ClusterXL technology. ElasticXL Cluster is a Scalable Platform Security Gateway based on a hyperscale model. It can scale up nodes with possible sites. How many?

Options:

A.

4 nodes per site and only 1 site possible.

B.

3 nodes per site and 2 possible sites.

C.

6 nodes per site and 3 possible sites.

D.

2 nodes per site and 1 possible site.

Question 25

Alice is preparing the import of the exported R82 Management Database. She wants to verify that the installed tools on the new target Security Management machine are able to handle the R82 release. Which Check Point command is correct?

Options:

A.

$FWDIR/scripts/migrate_server print_tools -v R81.20

B.

$CPDIR/scripts/migrate_server print_installed_tools -v R81.20

C.

$FWDIR/scripts/migrate_server print_installed_tools -v R77.30

D.

$FWDIR/scripts/migrate_server print_installed_tools -v R82

Question 26

Which command do you need to run before importing the Management Database on a freshly installed Security Management Server?

Options:

A.

$FWDIR/scripts/migrate_server print --installed-tools -v < target version >

B.

$FWDIR/scripts/migrate_server print_installed_tools -v < target version >

C.

$FWDIR/scripts/migrate_server show_upgrade_tools -v < target version >

D.

$FWDIR/scripts/migrate_server show --upgrade_tools -v < target version >

Question 27

Under which circumstances are automatic scans performed for Continuous Compliance Monitoring?

Options:

A.

Every time the CPM and CPD processes are restarted.

B.

Every time the FWD or CPM service on the gateway is restarted.

C.

Daily and when SmartConsole changes are published.

D.

Daily and weekly.

Question 28

Which daemon makes the decision whether Modern Dump or Legacy Dump should be used during policy installation?

Options:

A.

FWM, Firewall Management

B.

CPTA, Check Point Transfer Agent

C.

CPD, Check Point Daemon

D.

CPM, Check Point Management

Question 29

Alice and Bob are tasked by their security team lead with deploying Advanced Security Monitoring for all their Check Point Security systems. Which of the features and capabilities of SmartEvent is included?

Options:

A.

Full threat visibility

B.

Medium threat visibility

C.

Low threat visibility

D.

High threat visibility

Question 30

When it comes to manual synchronization, what statement is true?

Options:

A.

You can only initiate a Full Synchronization via Manual Sync.

B.

You can only initiate a Delta Synchronization via Manual Sync.

C.

You can choose whether to perform a Full Sync or Delta Sync when it comes to do a Manual Sync.

D.

Manual Sync is only done at the very beginning to force a Cluster Join after having installed the Secondary Management Server.

Question 31

Any VPN Gateway that can establish a direct VPN tunnel with any peer Gateway is a member of which VPN Community?

Options:

A.

Direct Community

B.

Any Community

C.

Star Community

D.

Mesh Community

Question 32

In Management HA, the failover is:

Options:

A.

Always manual

B.

Automatic by default, but can be changed to manual

C.

Manual by default, can be changed to automatic

D.

Always automatic

Question 33

How many members are supported by an ElasticXL Cluster?

Options:

A.

Maximum three members per site with a maximum of three sites.

B.

Three members per site with a maximum of two sites.

C.

Maximum two members per site with a maximum of three sites.

D.

Up to four members per site with a maximum of two sites.

Question 34

When using SmartEvent, what feature can be used to analyze previously generated log files for Event Policy analysis?

Options:

A.

The command CPLogInvestigator -f < log file name >

B.

SmartEvent can only analyze new incoming logs or logs less than 24 hours old.

C.

Correlation Unit > Add > Historical Log Analysis

D.

An Offline Job

Question 35

According to the policy installation flow, the transfer stage, CPTA, is invoked by the FWM process, which initiates the Transfer/Commit phase. On the Security Gateway side, a process receives the policy files and first stores them into a temporary directory. Which directory for the Commit phase is correct for receiving these files?

Options:

A.

$FWDIR/state/_tmp/FW1

B.

$CPDIR/state/local/FW-1

C.

$FWDIR/state/local/FW1

D.

$FWDIR/state/local/FW-1

Question 36

What is the SMO?

Options:

A.

The SMO is the name given to the cluster member with the highest priority in the SmartConsole Cluster object. The SMO distributes the policy to the other cluster members defined in the Cluster object.

B.

The SMO is a Security Gateway object in SmartConsole that defines the IP address and the security features deployed on the ElasticXL Cluster.

C.

The Single Management Object, SMO, is a special object reserved for Quantum Maestro solutions.

D.

The SMO is the only cluster member added to the cluster object and it defines the IP address for policy installation.

Question 37

The Management Server Database is exported during an Advanced Upgrade and later imported on a freshly deployed Management Server. The items that go along with this export include:

Options:

A.

Only objects are exported and imported with the database. Policies, certificates, and other settings are not included.

B.

Only objects and policies are exported with the database. Certificates are stored in a reserved area and cannot be exported.

C.

Network and routing configuration and all settings of the Check Point environment.

D.

Objects, policies, certificates, and other settings of the Check Point environment.

Question 38

Which of these methods is best suited for upgrading existing Security Management and Log Servers?

Options:

A.

Central Deployment Tool, CDT

B.

Central Deployment with SmartConsole

C.

UpgradeMeNow Tool

D.

CPUSE

Demo: 38 questions
Total 128 questions