Exit demo 156-915.80 Check Point Certified Security Expert Update - R80.10 PDF format · free preview

CheckPoint 156-915.80 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/156-91580.html

Question 1
Single choice

An internal host initiates a session to the Google.com website and is set for Hide NAT behind the Security Gateway. The initiating traffic is an example of __________.

A.

client side NAT

B.

source NAT

C.

destination NAT

D.

None of these

Question 2
Single choice

A host on the Internet initiates traffic to the Static NAT IP of your Web server behind the Security Gateway.
With the default settings in place for NAT, the initiating packet will translate the _________.

A.

destination on server side

B.

source on server side

C.

source on client side

D.

destination on client side

Question 3
Single choice

A Web server behind the Security Gateway is set to Automatic Static NAT. Client side NAT is not checked in the Global Properties. A client on the Internet initiates a session to the Web Server.
Assuming there is a rule allowing this traffic, what other configuration must be done to allow the traffic to reach the Web server?

A.

Automatic ARP must be unchecked in the Global Properties.

B.

Nothing else must be configured.

C.

A static route must be added on the Security Gateway to the internal host.

D.

A static route for the NAT IP must be added to the Gateway's upstream router.

Question 4
Single choice

Looking at the SYN packets in the Wireshark output, select the statement that is true about NAT.

A.

This is an example of Hide NAT.

B.

There is not enough information provided in the Wireshark capture to determine the NAT settings.

C.

This is an example of Static NAT and Translate destination on client side unchecked in Global Properties.

D.

This is an example of Static NAT and Translate destination on client side checked in Global Properties.

Question 5
Single choice

In SmartDashboard, Translate destination on client side is checked in Global Properties. When Network Address Translation is used:

A.

It is not necessary to add a static route to the Gateway's routing table.

B.

It is necessary to add a static route to the Gateway's routing table.

C.

The Security Gateway's ARP file must be modified.

D.

VLAN tagging cannot be defined for any hosts protected by the Gateway.

Question 6
Single choice

You are MegaCorp's Security Administrator. There are various network objects which must be NATed.
Some of them use the Automatic Hide NAT method, while others use the Automatic Static NAT method.

What is the rule order if both methods are used together? Give the BEST answer.

A.

The Administrator decides the rule order by shifting the corresponding rules up and down.

B.

The Static NAT rules have priority over the Hide NAT rules and the NAT on a node has priority over the NAT on a network or an address range.

C.

The Hide NAT rules have priority over the Static NAT rules and the NAT on a node has priority over the NAT on a network or an address range.

D.

The rule position depends on the time of their creation. The rules created first are placed at the top;
rules created later are placed successively below the others.

Question 7
Single choice

After filtering a fw monitor trace by port and IP, a packet is displayed three times; in the i, I, and o inspection points, but not in the O inspection point.

Which is the likely source of the issue?

A.

The packet has been sent out through a VPN tunnel unencrypted.

B.

An IPSO ACL has blocked the packet's outbound passage.

C.

A SmartDefense module has blocked the packet.

D.

It is due to NAT.

Question 8
Single choice

Your internal network is configured to be 10.1.1.0/24. This network is behind your perimeter R80 Gateway, which connects to your ISP provider.

How do you configure the Gateway to allow this network to go out to the Internet?

A.

Use Hide NAT for network 10.1.1.0/24 behind the external IP address of your perimeter Gateway.

B.

Use Hide NAT for network 10.1.1.0/24 behind the internal interface of your perimeter Gateway.

C.

Use automatic Static NAT for network 10.1.1.0/24.

D.

Do nothing, as long as 10.1.1.0 network has the correct default Gateway.

Question 9
Single choice

You are a Security Administrator who has installed Security Gateway R80 on your network. You need to allow a specific IP address range for a partner site to access your intranet Web server. To limit the partner's access for HTTP and FTP only, you did the following:
1. Created manual Static NAT rules for the Web server.
2. Cleared the following settings in the Global Properties > Network Address Translation screen:
- Allow bi-directional NAT
- Translate destination on client side
Do the above settings limit the partner's access?

A.

Yes. This will ensure that traffic only matches the specific rule configured for this traffic, and that the Gateway translates the traffic after accepting the packet.

B.

No. The first setting is not applicable. The second setting will reduce performance.

C.

Yes. Both of these settings are only applicable to automatic NAT rules.

D.

No. The first setting is only applicable to automatic NAT rules. The second setting will force translation by the kernel on the interface nearest to the client.

Question 10
Single choice

You enable Automatic Static NAT on an internal host node object with a private IP address of 10.10.10.5, which is NATed into 216.216.216.5. (You use the default settings in Global Properties / NAT.

) When you run fw monitor on the R80 Security Gateway and then start a new HTTP connection from host 10.10.10.5 to browse the Internet, at what point in the monitor output will you observe the HTTP SYN-ACK packet translated from 216.216.216.5 back into 10.10.10.5?

A.

o=outbound kernel, before the virtual machine

B.

I=inbound kernel, after the virtual machine

C.

O=outbound kernel, after the virtual machine

D.

i=inbound kernel, before the virtual machine

Showing 10 of 495 questions · Unlock the full set