Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Checkpoint 156-590 Check Point Certified Threat Prevention Specialist (CTPS) Exam Practice Test

Demo: 22 questions
Total 75 questions

Check Point Certified Threat Prevention Specialist (CTPS) Questions and Answers

Question 1

What is a distinct limitation of Active Streaming compared to Passive Streaming in conjunction with Anti-Virus?

Options:

A.

Only scheduled scans are possible.

B.

File size limits.

C.

There is no limitation.

D.

Only a subset of file types supported.

Question 2

Who owns and maintains the CVE program and database?

Options:

A.

Check Point

B.

US Department of Homeland Security (DHS)

C.

MITRE Corporation

D.

National Institute of Standards and Technology (NIST)

Question 3

What is necessary to activate the exception to all Security Gateways?

Options:

A.

Install Database is sufficient.

B.

You have to re-install the Threat Prevention policy.

C.

You have to re-install the Access Control policy.

D.

The changes will be applied immediately, so no need to do anything.

Question 4

What are the common features included in the NGFW, NGTP and SNBT packages, respectively?

Options:

A.

Firewall, Antivirus, Threat Emulation

B.

Firewall, Identity Awareness, Content Awareness, and IPS

C.

Firewall, IPS, Antivirus, Antibot

D.

Firewall, IPS, Antivirus, Threat Emulation

Question 5

What is the primary benefit of DNS Trap?

Options:

A.

Infected host identification

B.

Blocking known bad URLs

C.

Blocking outbound malicious DNS queries

D.

Blocking inbound malicious DNS queries

Question 6

How many Custom Threat Indicators patterns/observables does R81.20 support?

Options:

A.

10 million

B.

2 hundred thousand

C.

6 million

D.

2 million

Question 7

What are the three IPS update options?

Options:

A.

Auto Update, Policy Update, Update Now

B.

Update Now, Schedule Update, Follow Protections

C.

Update Now, Schedule Update, Follow policy

D.

Manual Update, Scheduled Update, Auto Update

Question 8

Mike wants to block all files in the event of internal failure; what option should he choose?

Options:

A.

open system

B.

fail-close

C.

fail-open

D.

closed system

Question 9

What is/are the enabled by default protocols supported by the Antivirus Blade?

Options:

A.

HTTP/HTTPS, FTP, SMB, SMTP

B.

HTTP/HTTPS, FTP, SMB

C.

HTTP/HTTPS

D.

HTTP/HTTPS, FTP

Question 10

Which of the following is NOT a valid Blade bundle?

Options:

A.

Next Generation Firewall

B.

Next Generation Full Protection

C.

Next Generation Threat Prevention

D.

SandBlast

Question 11

What deployment options for SmartEvent exist?

Options:

A.

1. Standalone and 2. Distributed Deployment

B.

1. Integrated/Standalone and 2. Dedicated Server

C.

1. Prevent Mode and 2. Detect Mode

D.

1. High Availability Mode and 2. Load Sharing Mode

Question 12

IPS stands for?

Options:

A.

Invasion Prevention Software

B.

Intrusion Prevention System

C.

Intrusion Prevention Software

D.

Invasion Prevention System

Question 13

What is the name of the default Threat Prevention Profile?

Options:

A.

Basic

B.

Standard

C.

Strict

D.

Optimized

Question 14

What is true concerning the Threat Prevention Policy?

Options:

A.

Multiple Threat Prevention Policies can be assigned to one Security Gateway.

B.

The Threat Prevention Policy can override an Access Control Policy Drop or Reject.

C.

In a case of a conflict, the Threat Prevention Policy takes precedence over an Access Control Policy.

D.

The Threat Prevention Policy is only applied after traffic is accepted by Access Control Policy.

Question 15

You have to issue a Log filter to view IPS logs generated for user John Doe.

Which of the following is the correct filter?

Options:

A.

user:"John-Doe" AND (action:drop OR action:reject OR action:block)

B.

user:John Doe AND (action:drop OR action:reject OR action:block)

C.

user:"John Doe" AND (action:drop OR action:reject OR action:block)

D.

user:'John Doe' AND (action:drop OR action:reject OR action:block)

Question 16

What Track - Settings Forensics does not?

Options:

A.

When enabled, advanced forensics detailed information is included in logs.

B.

Check Point researchers use advanced forensics details for troubleshooting and attack analysis.

C.

Forensics details also include Security Gateway statistics, which are sent to the Check Point Cloud.

D.

Communicate forensics data collected to Government Agencies.

Question 17

Are Cleanup Rules mandatory in a Threat Prevention Policy?

Options:

A.

Cleanup Rules are not required if you are using the Basic Profile.

B.

Cleanup Rules are only required, if the Access Control Policy does not have one.

C.

Cleanup Rules are not strictly required in the Threat Prevention Policy.

D.

A Cleanup Rule is required in a Basic Profile.

Question 18

Which of the following protocols can be scanned by Anti-Virus?

Options:

A.

RemoteDesktop

B.

SNMP

C.

CIFS

D.

Telnet

Question 19

Which DNS Protection mechanism has been introduced with R81.20?

Options:

A.

Propagation of a Bogus IP as a response to a DNS request.

B.

Malware DNS Trap.

C.

ThreatCloud DNS Tunneling Protection.

D.

Synchronization of the /etc/hosts file from Protection servers.

Question 20

What type of layer is the threat Prevention?

Options:

A.

It can be ordered or inline

B.

Inline

C.

Post Access Control follow-up layer

D.

Ordered

Question 21

What kind of information is stored in the Audit Log?

Options:

A.

An audit log is a record of actions taken by administrators.

B.

An audit log is a record of system event logs on the Security Management Server.

C.

An audit log is a portion of the traffic log which has been filtered by filter expression defined by the administrator.

D.

An audit log is a record of system event logs on the Security Gateway.

Question 22

What is the default Anti-Virus protected scope interface settings?

Options:

A.

DMZ

B.

External and DMZ

C.

External

D.

All

Demo: 22 questions
Total 75 questions