Checkpoint 156-115.77 Exam Practice Questions (P. 1)
- Full Access (46 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
When troubleshooting a VPN site-to-site to a peer, it may be necessary to "down" the tunnel. What is the best method to remove ONLY the tunnel to this peer?
- AChange the vpn tunnel sharing parameters to force the tunnel down.
- BReboot your gateway.
- CRemove the peer from the community and install policy.
- DDelete the IKE and IPsec Security Associations using the command vpn tu.
Correct Answer:
D
D
send
light_mode
delete
Question #2
In Check Point, Domain-based VPN's take precedence over route-based VPN. If implementing a route-based VPN, what is one configuration step you must make on the gateway object taking part in the route-based VPN?
- AYou should remove the gateway from all communities.
- BCheck Point does not support route-based VPN's.
- CYou need to create a new simple group with no objects in it and apply this as the VPN domain under that gateway's topology tab.
- DYou should check the "Use route-based VPN" checkbox in the community properties.
Correct Answer:
C
C
send
light_mode
delete
Question #3
What utility would you use to configure route-based VPNs?
send
light_mode
delete
Question #4
Where do you configure the file user.def to change the encryption domain of the Security Gateway?
- AManagement Server
- BEndpoint Client
- CSecurity Gateway
- Dinteroperable device
Correct Answer:
A
A
send
light_mode
delete
Question #5
Henry is attempting to verify VPN connectivity between two hosts, x and y. Of the following commands, which could be BEST used to verify connectivity of this
VPN?
VPN?
- A[Expert@HostName]# fw monitor -e "((src=x.x.x.x , dst=y.y.y.y) or (src=y.y.y.y, dst=x.x.x.x)), accept;" x-o /var/log/fw_mon.cap
- B[Expert@HostName]# fw monitor -e "host(x.x.x.x) and host(y.y.y.y), accept;" -o /var/log/fw_mon.capw monitor -e "accept;" -o /var/log/fw_mon.cap
- C[Expert@HostName]# fw monitor -e "(ip_p=X) or (ip_p=Y, port(Z)), accept;" -o /var/log/fw_mon.cap
- D[Expert@HostName]# fw monitor -e "ip_p=X, accept;" -o /var/log/fw_mon.cap
Correct Answer:
A
A
send
light_mode
delete
All Pages