Searching the best new exam braindumps which can guarantee you 100% pass rate, you don't need to run about busily by, our latest pass guide materials will be here waiting for you. With our new exam braindumps, you will pass exam surely.

[Dec 02, 2021] New 2021 CheckPoint 156-315.80 Exam Dumps with PDF from Dumpexams (Updated 457 Questions) [Q95-Q119]

Share

New 2021 156-315.80 exam questions Welcome to download the newest Dumpexams 156-315.80 PDF dumps (457  Q&As)

P.S. Free 2021 CCSE 156-315.80  dumps are available on Google Drive shared by Dumpexams

NEW QUESTION 95
Check Point APIs allow system engineers and developers to make changes to their organization's security policy with CLI tools and Web Services for all the following except:

  • A. Create products that use and enhance 3rd party solutions
  • B. Execute automated scripts to perform common tasks
  • C. Create new dashboards to manage 3rd party task
  • D. Create products that use and enhance the Check Point Solution
    Check Point APIs let system administrators and developers make changes to the security policy with CLI tools and web-services. You can use an API to:
    * Use an automated script to perform common tasks
    * Integrate Check Point products with 3rd party solutions
    * Create products that use and enhance the Check Point solution

Answer: C

 

NEW QUESTION 96
In what way is Secure Distribute (SND) a relevant feature if the security gateway?

  • A. SDN is used to distribute packets firewall instances
  • B. SDN is an alternative to IPSec Main Mode, using only 3 packets
  • C. SDN is a feature to accelerate multiple SSL VPN connections
  • D. SDN is a feature fw monitor to capture accelerated packets

Answer: A

 

NEW QUESTION 97
Which statement is most correct regarding about "CoreXL Dynamic Dispatcher"?

  • A. The CoreXL FW instances assignment mechanism is based on IP Protocol type
  • B. The CoreXl FW instances assignment mechanism is based on Source IP addresses, Destination IP
    addresses, and the IP 'Protocol' type
  • C. The CoreXL FW instances assignment mechanism is based on the utilization of CPU cores
  • D. The CoreXL FW instances assignment mechanism is based on Source MAC addresses, Destination
    MAC addresses

Answer: C

 

NEW QUESTION 98
What information is NOT collected from a Security Gateway in a Cpinfo?

  • A. OS and network statistics
  • B. Configuration and database files
  • C. System message logs
  • D. Firewall logs

Answer: D

Explanation:
References:

 

NEW QUESTION 99
Fill in the blank: The R80 feature _____ permits blocking specific IP addresses for a specified time period.

  • A. Local Interface Spoofing
  • B. Suspicious Activity Monitoring
  • C. Adaptive Threat Prevention
  • D. Block Port Overflow

Answer: B

Explanation:
Suspicious Activity Rules Solution
Suspicious Activity Rules is a utility integrated into SmartView Monitor that is used to modify access privileges upon detection of any suspicious network activity (for example, several attempts to gain unauthorized access).
The detection of suspicious activity is based on the creation of Suspicious Activity rules. Suspicious Activity rules are Firewall rules that enable the system administrator to instantly block suspicious connections that are not restricted by the currently enforced security policy. These rules, once set (usually with an expiration date), can be applied immediately without the need to perform an Install Policy operation.
References:

 

NEW QUESTION 100
True or False: In R80, more than one administrator can login to the Security Management Server with write permission at the same time.

  • A. True, every administrator works in a session that is independent of the other administrators.
  • B. False, only one administrator can login with write permission.
  • C. False, this feature has to be enabled in the Global Properties.
  • D. True, every administrator works on a different database that is independent of the other administrators.

Answer: A

 

NEW QUESTION 101
Which statements below are CORRECT regarding Threat Prevention profiles in SmartDashboard?

  • A. You can assign only one profile per gateway and a profile can be assigned to one or more rules.
  • B. You can assign multiple profiles per gateway and a profile can be assigned to one or more rules.
  • C. You can assign multiple profiles per gateway and a profile can be assigned to one rule only.
  • D. You can assign only one profile per gateway and a profile can be assigned to one rule Only.

Answer: A

 

NEW QUESTION 102
What is the purpose of Priority Delta in VRRP?

  • A. When a box up, Effective Priority = Priority + Priority Delta
  • B. When an Interface fail, Effective Priority = Priority - Priority Delta
  • C. When a box fail, Effective Priority = Priority - Priority Delta
  • D. When an Interface is up, Effective Priority = Priority + Priority Delta

Answer: B

Explanation:
Each instance of VRRP running on a supported interface may monitor the link state of other interfaces. The monitored interfaces do not have to be running VRRP.
If a monitored interface loses its link state, then VRRP will decrement its priority over a VRID by the specified delta value and then will send out a new VRRP HELLO packet. If the new effective priority is less than the priority a backup platform has, then the backup platform will beging to send out its own HELLO packet.
Once the master sees this packet with a priority greater than its own, then it releases the VIP.
References:

 

NEW QUESTION 103
What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?

  • A. VPN Routing Mode
  • B. Stateless Mode
  • C. Stateful Mode
  • D. Wire Mode

Answer: D

 

NEW QUESTION 104
In SmartEvent, what are the different types of automatic reactions that the administrator can configure?

  • A. Mail, Block Source, Block Destination, Block Services, SNMP Trap
  • B. Mail, Block Source, Block Event Activity, External Script, SNMP Trap
  • C. Mail, Block Source, Block Destination, External Script, SNMP Trap
  • D. Mail, Block Source, Block Event Activity, Packet Capture, SNMP Trap

Answer: B

Explanation:
References:

 

NEW QUESTION 105
What is true about VRRP implementations?

  • A. You cannot have a standalone deployment
  • B. VRRP membership is enabled in cpconfig
  • C. You cannot have different VRIDs in the same physical network
  • D. VRRP can be used together with ClusterXL, but with degraded performance

Answer: A

 

NEW QUESTION 106
Which of the following is NOT an attribute of packet acceleration?

  • A. Protocol
  • B. Destination port
  • C. Source address
  • D. VLAN Tag

Answer: D

 

NEW QUESTION 107
Which command is used to add users to or from existing roles?

  • A. Add user <User Name>
  • B. Add user <User Name> roles <List>
  • C. Add rba user <User Name> roles <List>
  • D. Add rba user <User Name>

Answer: C

Explanation:
Explanation/Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Gaia_WebAdmin/73101.htm

 

NEW QUESTION 108
Where you can see and search records of action done by R80 SmartConsole administrators?

  • A. In SmartAuditLog View
  • B. In the Logs & Monitor view, select "Open Audit Log View"
  • C. In Smartlog, all logs
  • D. In SmartView Tracker, open active log

Answer: B

Explanation:
Reference: https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/ CP_R80.10_LoggingAndMonitoring_AdminGuide/html_frameset.htm?topic=documents/R8
0.10/
WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/188029

 

NEW QUESTION 109
What are the blades of Threat Prevention?

  • A. IPS, DLP, AntiVirus, AntiBot, Sandblast Threat Emulation/Extraction
  • B. IPS, AntiVirus, AntiBot
  • C. IPS, AntiVirus, AntiBot, Sandblast Threat Emulation/Extraction
  • D. DLP, AntiVirus, QoS, AntiBot, Sandblast Threat Emulation/Extraction

Answer: A

 

NEW QUESTION 110
You need to change the MAC-address on eth2 interface of the gateway. What is the correct way to change MAC-address in Check Point Gaia?

  • A. In CLISH run set interface eth2 hw-addr 11 11 11:11:11 11
  • B. In expert-mode run ifconfig eth1 hw 11:11:11:11 11 11
  • C. In expert-mode run: ethtool -4 eth2 mac 11 11:11:11:11:11
  • D. In CLISH run: set interface eth2 mac-addr 11:11:11:11:11:11

Answer: D

 

NEW QUESTION 111
What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL Filtering, Anti-Virus, IPS, and Threat Emulation?

  • A. Anti-Bot is the only signature-based method of malware protection.
  • B. Anti-Bot is the only countermeasure against unknown malware
  • C. Anti-Bot is the only protection mechanism which starts a counter-attack against known Command & Control Centers
  • D. Anti-Bot is a post-infection malware protection to prevent a host from establishing a connection to a Command & Control Center.

Answer: D

Explanation:
References:

 

NEW QUESTION 112
How many interfaces can you configure to use the Multi-Queue feature?

  • A. 4 interfaces
  • B. 5 interfaces
  • C. 10 interfaces
  • D. 3 interfaces

Answer: B

Explanation:
Note -

 

NEW QUESTION 113
The Check Point history feature in R80 provides the following:

  • A. View install changes
  • B. Policy Installation Date only
  • C. Policy Installation Date, view install changes and install specific version
  • D. View install changes and install specific version

Answer: C

Explanation:
References:

 

NEW QUESTION 114
Full synchronization between cluster members is handled by Firewall Kernel. Which port is used for this?

  • A. TCP port 256
  • B. UDP port 265
  • C. TCP port 265
  • D. UDP port 256

Answer: A

Explanation:
Explanation
Synchronization works in two modes:
Full Sync transfers all Security Gateway kernel table information from one cluster member to another. It is handled by the fwd daemon using an encrypted TCP connection on port 256.
Delta Sync transfers changes in the kernel tables between cluster members. Delta sync is handled by the Security Gateway kernel using UDP connections on port 8116.
References:

 

NEW QUESTION 115
What does it mean if Deyra sees the gateway status? (Choose the BEST answer.)

  • A. VPN software blade is reporting a malfunction.
  • B. There is a blade reporting a problem.
  • C. Security Gateway's MGNT NIC card is disconnected.
  • D. SmartCenter Server cannot reach this Security Gateway.

Answer: B

Explanation:
References:

 

NEW QUESTION 116
What command would show the API server status?

  • A. show api status
  • B. api status
  • C. api restart
  • D. cpm status

Answer: B

 

NEW QUESTION 117
DLP and Geo Policy are examples of what type of Policy?

  • A. Unified Policies
  • B. Standard Policies
  • C. Inspection Policies
  • D. Shared Policies

Answer: D

Explanation:
References:

 

NEW QUESTION 118
To enable Dynamic Dispatch on Security Gateway without the Firewall Priority Queues, run the following
command in Expert mode and reboot:

  • A. fw ctl multik set_mode 4
  • B. fw ctl multik set_mode 1
  • C. fw ctl Dyn_Dispatch on
  • D. fw ctl Dyn_Dispatch enable

Answer: A

 

NEW QUESTION 119
......

156-315.80 exam questions from Dumpexams dumps: https://pdftorrent.dumpexams.com/156-315.80-vce-torrent.html (457  Q&As)