Labour Day Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

156-115.77 Sample Questions Answers

Questions 4

By default, the size of the fwx_alloc table is:

Options:

A.

65535

B.

65536

C.

25000

D.

1024

Buy Now
Questions 5

Since R76 GAiA, what is the method for configuring proxy ARP entries for manual NAT rules?

Options:

A.

WebUI or add proxy ARP ... commands via CLISH

B.

SmartView Tracker

C.

local.arp file

D.

SmartDashboard

Buy Now
Questions 6

Which of the following statements about Full HA support with IPv6 is NOT true?

Options:

A.

There is no Dynamic Routing with IPv6.

B.

Mirrored Interfaces must have IPv4 addresses.

C.

Sync traffic must be IPv4.

D.

IPv6 does not support a Secondary Management Server.

Buy Now
Questions 7

What command would you use to check if CoreXL is enabled?

Options:

A.

fw ctl multik stat

B.

cpconfig

C.

fw ctl affinity -1

D.

fw ctl pstat

Buy Now
Questions 8

Where would you go to adjust the number of Kernels in CoreXL?

Options:

A.

Cpconfig

B.

fw ctl conf

C.

fw ctl affinity

D.

fw ctl multik stat

Buy Now
Questions 9

A firewall administrator knows the details of the packet header for an already established connection going through a firewall. What command will show if SecureXL will accelerate that packet?

Options:

A.

fw ctl zdebug + sxl error warning asm

B.

fwaccel conns

C.

fwaccel templates

D.

fw tab –t connections –f | grep ‘dest. port #’ | grep ‘source port #’ | grep ‘dest. IP address’

Buy Now
Questions 10

Which technology is not supported with route-based VPNs?

Options:

A.

Unnumbered VTI

B.

Numbered VTI

C.

IKEv2

D.

OSPF

Buy Now
Questions 11

What VSX components do not support IPv6 in R77 VSX mode?

Options:

A.

VSX mode does not support IPv6

B.

All devices support IPv6

C.

Virtual Systems

D.

Virtual Routers

Buy Now
Questions 12

A system administrator wants to convert an IPv6 gateway from a standard gateway into a gateway running VSX mode. What does he need to consider?

Options:

A.

It is not possible to convert a gateway with IPv6 enabled to VSX mode.

B.

There needs to be proper IPv6 routing setup.

C.

At least two interfaces need to be configured with IPv6.

D.

Policy needs to be properly applied to the gateway before converting the system to VSX mode.

Buy Now
Questions 13

Which of these commands can be used to display the IPv6 routes?

Options:

A.

show route

B.

show ipv6 route

C.

show routes all

D.

show route ipv6

Buy Now
Questions 14

Under which scenario would you most likely consider the use of Multi-Queue?

Options:

A.

When IPS is heavily used.

B.

When most of the traffic is accelerated.

C.

When most of the processing is done in CoreXL.

D.

When trying to increase session rate.

Buy Now
Questions 15

You are running an inventory process within your corporate environment (R77) and need to find out CPU, memory, disk space, and information regarding the software blades enabled. What command could you use to easily gather this information?

Options:

A.

cpconfig

B.

fw ctl pstat

C.

SmartView Tracker

D.

cpview

Buy Now
Questions 16

How to check the overall SecureXL statistics:

Options:

A.

fwaccel on

B.

fwaccel stat

C.

cat /proc/ppk/statistics

D.

fwaccel conns

Buy Now
Questions 17

SecureXL uses templating to accelerate traffic passing through the gateway. What command should you run to determine if Accept, Drop and NAT templating is enabled?

Options:

A.

fwaccel stat

B.

fw ctl pstat

C.

cphaprob -a if

D.

cpconfig

Buy Now
Questions 18

What does the IP Options Strip represent under the fw chain output?

Options:

A.

IP Options Strip is not a valid fw chain output.

B.

The IP Options Strip removes the IP header of the packet prior to be passed to the other kernel functions.

C.

The IP Options Strip copies the header details to forward the details for further IPS inspections.

D.

IP Options Strip is only used when VPN is involved.

Buy Now
Questions 19

A Rule Base has been improperly configured with a rule which disables templating at the top of the Rule Base. How will this impact traffic acceleration?

Options:

A.

SecureXL is disabled.

B.

Templates are disabled, and throughput acceleration only functions for rules above this one.

C.

Templates are disabled for this rule but it does not impact the rest of the Rule Base.

D.

Templates are disabled but throughput acceleration is still taking place.

Buy Now
Questions 20

What type of connections cannot be templated?

Options:

A.

Any connections that contain Hide NAT

B.

Complex connections such as FTP, H323, SQL, ETC

C.

UDP because it is not connection oriented

D.

TCP

Buy Now
Questions 21

The command fw monitor -p all displays what type of information?

Options:

A.

It captures all points of the chain as the packet goes through the firewall kernel.

B.

This is not a valid command.

C.

The -p is used to resolve MAC address in the firewall capture.

D.

It does a firewall monitor capture on all interfaces.

Buy Now
Questions 22

What flag option(s) must be used to dump the complete table in friendly format, assuming there are more than one hundred connections in the table?

Options:

A.

fw tab -t connections -f

B.

fw tab -t connect -f -u

C.

fw tab -t connections -s

D.

fw tab -t connections -f –u

Buy Now
Questions 23

While troubleshooting a connectivity issue with an internal web server, you know that packets are getting to the upstream router, but when you run a tcpdump on the external interface of the gateway, the only traffic you observe is ARP requests coming from the upstream router. Does the problem lie on the Check Point Gateway?

Options:

A.

Yes – This could be due to a misconfigured route on the firewall.

B.

No – This is a layer 2 connectivity issue and has nothing to do with the firewall.

C.

No – The firewall is not dropping the traffic, therefore the problem does not lie with the firewall.

D.

Yes – This could be due to a misconfigured Static NAT in the firewall policy.

Buy Now
Questions 24

What is the log file that shows the keep alive packets during the debug process?

Options:

A.

$FWDIR/log/ikev2.xmll

B.

$FWDIR/log/ike.xmll

C.

$FWDIR/log/ike.elg

D.

$FWDIR/log/vpnd.elg

Buy Now
Questions 25

What would the following command fw monitor tell you?

Options:

A.

Only OSPF and FTP traffic between 10.10.10.86 and 192.168.10.4

B.

Only traffic between 10.10.10.86 and 192.168.10.4 on port 21 or port 89

C.

Only accepted traffic between 10.10.10.86 and 192.168.10.4, or any accepted FTP traffic, or any accepted OSPF traffic

D.

Any communication between 10.10.10.86 and 192.168.10.4, or any FTP traffic, or any OSPF traffic

Buy Now
Questions 26

What debug file would you check to see what IKE version is being used?

Options:

A.

fwpnd.elg

B.

vpn.txt

C.

debug.txt

D.

vpnd.elg

Buy Now
Questions 27

Of the following answer choices, which best describes a possible effect of expanding the connections table?

Options:

A.

Increased memory consumption

B.

Decreased memory consumption

C.

Increased connection duration

D.

Decreased connection duration

Buy Now
Questions 28

You run the command fw tab -t connections -s on both members in the cluster.  Both members report differing values for "vals" and "peaks".  Which may NOT be a reason for this difference?

Options:

A.

Synchronization is not working between the two members

B.

SGMs in a 61k environment only sync selective parts of the connections table.

C.

Heavily used short-lived services have had synchronization disabled for performance improvement.

D.

Standby member does not synchronize until a failover is needed.

Buy Now
Questions 29

Using the default values in R77 how many kernel instances will there be on a 16-core gateway?

Options:

A.

16

B.

8

C.

12

D.

14

Buy Now
Questions 30

Your customer has an R77 Multi-domain Management Server managing a mix of firewalls of R70 and R77 versions.  A change was made to the file $FWDIR/lib/tables.def on one of the domains.  However, it was found that the change was not applied to the R70 firewalls.  What could be the problem?

Options:

A.

Changes to the table.def can only be applied to firewalls matching the Management Server version.  The customer needs to upgrade the firewalls to the same version as the firewall.

B.

R70 is end of life and is not supported.  Most functions will work, but modifying the table.def will not.

C.

In order to make changes on R70 machines you need work within GuiDBedit

D.

To support R70, the file in the compatibility directory should have been modified.

Buy Now
Questions 31

Look at the follow Rule Base display. Rule 5 contains a TIME object. What is the effect on the following rules?

Options:

A.

Rule 6 will be eligible but Rule 7 will not.

B.

All subsequent rules below Rule 5 will not be templated, regardless of the rule

C.

No effect. Rules 6 and 7 will be eligible for templating.

D.

The restriction on one rule does not affect later rules with regards to templates.

Buy Now
Questions 32

What command displays the Connections Table for a specified CoreXL firewall instance?

Options:

A.

fw tab –t connections –s

B.

fw -i FW_INSTANCE_ID tab -t connections [flags]

C.

fw tab –t connection | grep fw

D.

fw tab –t connections

Buy Now
Questions 33

When configuring a Numbered VPN-Tunnel, what parameters are necessary?

Options:

A.

VPN Tunnel ID, Local Address, Remote Address

B.

Peer, Local Address, Remote Address

C.

VPN Tunnel ID, Peer, Local Address, Remote Address

D.

VPN Tunnel ID, Peer, Physical Device

Buy Now
Questions 34

How can an administrator stay up-to-date on the status of their VPN Tunnels?

Options:

A.

Tracking settings can be configured on the Tunnel Management screen of the Community Properties screen for all VPN tunnels.

B.

Make a change in /proc/net/tun.

C.

Run vpn tu and select the option Live Monitoring.

D.

In Smartview Tracker.

Buy Now
Questions 35

In Wire mode. if a packet reaches the gateway from a trusted source and is destined to a trusted destination, will the firewall do stateful inspection?

Options:

A.

No, but IPS inspection will still be enforced.

B.

Yes, the Firewall always performs stateful inspection.

C.

Yes, but only if SecureXL is disabled.

D.

No

Buy Now
Questions 36

Your Customer would like to enable IPS in his Corporate Cluster, but he is concerned about high CPU usage because if the IPS inspection. What feature would you configure to disable inspection if a high CPU usage develops?

Options:

A.

It is not possible. In this case no enable IPS

B.

Bypass Under Load. (In IPS Option on Gateway Properties)

C.

Bypass Inspection. (In IPS Option on Gateway Properties)

D.

Disable Inspection. (In IPS Option on Gateway Properties)

Buy Now
Questions 37

Which of the following IPS Layers is a set of signatures and/or handlers, where:

?Signature is a malicious pattern that is searched for.

?Handler is the INSPECT code that performs more complex inspection.

Options:

A.

Passive Streaming Library (PSL)

B.

Protections

C.

Context Management Interface layer (CMI)

D.

Protocol Parsers

Buy Now
Questions 38

Where do you run the command get_ips_statistics.sh from?

Options:

A.

$FWDIR/conf on the Management Server

B.

$FWDIR/scripts on the Management Server

C.

$FWDIR/conf on the gateway

D.

$FWDIR/scripts on the gateway

Buy Now
Questions 39

Jerry is a network administrator for ACME Co. Their network contains 5 gateways all managed by a single Management Server. They are currently receiving an exorbitant amount of false positive for traffic traversing their network. Based on this information, what factor do you think is contributing most to the high amount of false positives Jerry is receiving?

Options:

A.

She is performing IPS inspection on all traffic

B.

She has set protections to run in “Detect” mode

C.

She has enabled protections based on the network devices and requirements

D.

She has created a dedicated IPS profile for each Security Gateway

Buy Now
Questions 40

Which directory below contains the URL Filtering engine update info? Here you can also go to see the status of the URL Filtering and Application Control updates.

Options:

A.

$FWDIR/urlf/update

B.

$FWDIR/appi/update

C.

$FWDIR/appi/urlf

D.

$FWDIR/update/appi

Buy Now
Questions 41

If the number of Firewall Workers for CoreXL is set higher on one member of a cluster than the other, the cluster will be in what state?

Options:

A.

Active/Standby

B.

Active/Ready

C.

Active Attention/Down

D.

Active/Down

Buy Now
Questions 42

What is the best way to see how a firewall is performing while processing packets in the firewall path, including resource usage?

Options:

A.

fw getperf

B.

SecureXL stat

C.

fwaccel stats

D.

fw ctl pstat

Buy Now
Questions 43

Misha is working on a stand-by firewall and deletes the connections table in error. He finds that now the table is out of sync with the Active member. to get them completely synced again, Mish should run the command pair ____________ and __________ .

Options:

A.

fw ctl sync stop, fw ctl sync start

B.

fw ctl setsync off, fw ctl setsync start

C.

fw ctl setsync stop, fw ctl setsync on

D.

fw ctl setsync off, fw ctl setsync on

Buy Now
Questions 44

To check what is currently set in the Firewall kernel debug input the command:

Options:

A.

fw ctl multistate

B.

fw ctl debug –x

C.

fw ctl pstat

D.

fw ctl debug

Buy Now
Status:
Expired
Exam Code: 156-115.77
Exam Name: Check Point Certified Security Master
Last Update: Apr 14, 2023
Questions: 295
$64  $159.99
$48  $119.99
$40  $99.99
buy now 156-115.77