Checkpoint 156-915.80 Exam Practice Questions (P. 2)
- Full Access (50 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?
- AStateful Mode
- BVPN Routing Mode
- CWire Mode
- DStateless Mode
Correct Answer:
C
Wire Mode is a VPN-1 NGX feature that enables VPN connections to successfully fail over, bypassing Security Gateway enforcement. This improves performance and reduces downtime. Based on a trusted source and destination, Wire Mode uses internal interfaces and VPN Communities to maintain a private and secure
VPN session, without employing Stateful Inspection. Since Stateful Inspection no longer takes place, dynamic-routing protocols that do not survive state verification in non-Wire Mode configurations can now be deployed. The VPN connection is no different from any other connections along a dedicated wire, thus the meaning of "Wire Mode".
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30974
C
Wire Mode is a VPN-1 NGX feature that enables VPN connections to successfully fail over, bypassing Security Gateway enforcement. This improves performance and reduces downtime. Based on a trusted source and destination, Wire Mode uses internal interfaces and VPN Communities to maintain a private and secure
VPN session, without employing Stateful Inspection. Since Stateful Inspection no longer takes place, dynamic-routing protocols that do not survive state verification in non-Wire Mode configurations can now be deployed. The VPN connection is no different from any other connections along a dedicated wire, thus the meaning of "Wire Mode".
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30974
send
light_mode
delete
Question #7
On R80.10 the IPS Blade is managed by:
- AThreat Protection policy
- BAnti-Bot Blade
- CThreat Prevention policy
- DLayers on Firewall policy
Correct Answer:
A
Reference:
https://www.checkpoint.com/downloads/product-related/r80.10-mgmt-architecture-overview.pdf very top of last page.
A
Reference:
https://www.checkpoint.com/downloads/product-related/r80.10-mgmt-architecture-overview.pdf very top of last page.
send
light_mode
delete
Question #8
Which packet info is ignored with Session Rate Acceleration?
- Asource port ranges
- Bsource ip
- Csource port
- Dsame info from Packet Acceleration is used
Correct Answer:
C
Reference: http://trlj.blogspot.com/2015/10/check-point-acceleration.html
C
Reference: http://trlj.blogspot.com/2015/10/check-point-acceleration.html
send
light_mode
delete
Question #9
What is the purpose of Priority Delta in VRRP?
- AWhen a box is up, Effective Priority = Priority + Priority Delta
- BWhen an Interface is up, Effective Priority = Priority + Priority Delta
- CWhen an Interface fail, Effective Priority = Priority – Priority Delta
- DWhen a box fail, Effective Priority = Priority – Priority Delta
Correct Answer:
C
Each instance of VRRP running on a supported interface may monitor the link state of other interfaces. The monitored interfaces do not have to be running VRRP.
If a monitored interface loses its link state, then VRRP will decrement its priority over a VRID by the specified delta value and then will send out a new VRRP
HELLO packet. If the new effective priority is less than the priority a backup platform has, then the backup platform will beging to send out its own HELLO packet.
Once the master sees this packet with a priority greater than its own, then it releases the VIP.
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk38524
C
Each instance of VRRP running on a supported interface may monitor the link state of other interfaces. The monitored interfaces do not have to be running VRRP.
If a monitored interface loses its link state, then VRRP will decrement its priority over a VRID by the specified delta value and then will send out a new VRRP
HELLO packet. If the new effective priority is less than the priority a backup platform has, then the backup platform will beging to send out its own HELLO packet.
Once the master sees this packet with a priority greater than its own, then it releases the VIP.
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk38524
send
light_mode
delete
Question #10
What is the purpose of a SmartEvent Correlation Unit?
- AThe SmartEvent Correlation Unit is designed to check the connection reliability from SmartConsole to the SmartEvent Server
- BThe SmartEvent Correlation Unit’s task it to assign severity levels to the identified events.
- CThe Correlation unit role is to evaluate logs from the log server component to identify patterns/threats and convert them to events.
- DThe SmartEvent Correlation Unit is designed to check the availability of the SmartReporter Server
Correct Answer:
C
C
send
light_mode
delete
All Pages