Exit demo 156-915.65 Accelerated CCSE NGX R65 PDF format · free preview

CheckPoint 156-915.65 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/156-91565.html

Question 1
Single choice

In a Management High Availability (HA) configuration, you can configure synchronization to occur automatically, when

(1)The Security Policy is installed.

(2)The Security Policy is saved.

(3)The Security Administrator logs in to the secondary SmartCenter Server, and changes its status to active.

(4)A scheduled event occurs.

(5)The user database is installed.

Select the BEST response for the synchronization sequence. Choose One:

A.

1,2,3,4

B.

1,2,5

C.

1,2,4

D.

1,3,4

Question 2
Single choice

When configuring site-to-site VPN High Availability (HA) with MEP, which of the following is correct?

A.

MEP Gateways cannot be geographically separated machines.

B.

MEP Gateways must be managed by the same SmartCenter Server.

C.

The decision on which MEP Gateway to use is made on the MEP Gateway's side of the tunnel.

D.

If one MEP Security Gateway fails, the connection is lost and the backup Gateway picks up the next connection.

Question 3
Single choice

How do you verify a VPN Tunnel Interface (VTI) is configured properly?

A.

vpn shell display interface detailed <VTI name>

B.

vpn shell show interface detailed <VTI name*

C.

vpn shell display <VTI name> detailed

D.

vpn shell show<VTI name> detailed

Question 4
Single choice

A VPN Tunnel Interface (VTI) is defined on SecurePlatform Pro as: vpn shell interface add numbered 10.10.0.1 10.10.0.2 madrid.cp

What do you know about this VTI?

A.

The VTI name is "madrid.cp".

B.

The peer Security Gateway's name is "madrid.cp"

C.

10.10.0.1 is the local Gateway's internal interface, and 10.10.0.2 is the internal interface of the remote Gateway

D.

The local Gateway's object name is "madrid.cp".

Question 5
Single choice

What physical machine must have access to the User Center public IP when checking for new packages with SmartUpdate?

A.

SmartUpdate installed SmartCenter Server PC

B.

SmartUpdate GUI PC

C.

VPN.1 Security Gateway getting the new upgrade package

D.

SmartUpdate Repository SQL database Server

Question 6
Single choice

Which of the following would NOT be a reason for beginning with a fresh installation of VPN.1 NGX R65, instead of upgrading a previous version to VPN.1 NGX R65?

A.

You see a more logical way to organize your rules and objects.

B.

YOU want to keep your Check Point configuration.

C.

Your Security Policy includes rules and objects whose purpose you do not know.

D.

Objects and rules' naming conventions have changed overtime.

Question 7
Single choice

When configuring VPN High Availability (HA) with MEP, which of the following is correct?

A.

The decision on which MEP Security Gateway to use is made on the remote gateway's side (non-MEP side).

B.

MEP Gateways must be managed by the same SmartCenter Server.

C.

MEP VPN Gateways cannot be geographically separated machines.

D.

If one Gateway fails, the synchronized connection fails over to another Gateway and the connection continues

Question 8
Single choice

What must a public hospital Security Administrator do to comply with new health-care legislation requirements for logging all traffic accepted through the perimeter Security Gateway?

A.

Define two log servers on the VPN-1 NGX R65 Gateway object. Enable "Log Implied Rules" on the first log server. Enable "Log Rule Base" on the second log server. Use Eventia Reporter to merge the two log server records into the same database for HIPPA log audits.

B.

Install the "View Implicit Rules" package using SmartUpdate.

C.

In Global Properties > Reporting Tools check the box "Enable tracking all rules (including rules marked
as 'None' in the Track column). Send these logs to a secondary log server for a complete logging history. Use your normal log server for standard logging for troubleshooting.

D.

Check the "Log Implied Rules Globally" box on the VPN-1 NGX R65 Gateway object.

Question 9
Single choice

A marketing firm's networking team is trying to troubleshoot user complaints regarding access to audio-streaming material from the Internet. The networking team asks you to check the object and rule configuration settings for the perimeter Security Gateway.

Which SmartConsole application should you use to check these objects and rules?

A.

SmartViewTracker

B.

SmartView Status

C.

SmartView Monitor

D.

SmartDashboard

Question 10
Single choice

Which of the following statements about file-type recognition in Content Inspection is TRUE?

A.

A scan failure will only occur if the antivirus engine fails to initialize.

B.

Antivirus status is monitored using SmartView Tracker.

C.

The antivirus engine acts as a proxy, caching the scanned file before delivering it to the client.

D.

All file types are considered "at risk", and are not subject to the whims of the Administrator or the Security Policy

Showing 10 of 204 questions · Unlock the full set