Summer Sale - Limited Time 55% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 5763r953

Welcome To DumpsPedia

156-115.80 Sample Questions Answers

Questions 4

By default, how long does the UDP connection remain on the state table?

Options:

A.

30 Seconds

B.

30 minutes

C.

60 minutes

D.

40 Seconds

Buy Now
Questions 5

What is the purpose of a Management server?

Options:

A.

The sole purpose of the Management server is to store the log files sent by the Security Gateways.

B.

The Management server manages, creates, stores, and distributes the security policy to Security Gateways. It also functions as the Certificate Authority of all managed Check Point products.

C.

The Management server provides the connector for the GUI client and uses exclusively port 257/tcp.

D.

The Management server only functions as the Certificate Authority of all managed Check Point products.

Buy Now
Questions 6

On a production Check Point Gateway that is running Check Point Acceleration features, is it possible to reset SIC without affecting the production machines?

Options:

A.

Yes, use the cp_conf command

B.

No, Reset SIC using cpconfig during a change window

C.

Yes, use the vi utility to edit CP HKLM_registry.data Registry File

D.

No, Reset SIC on the Gateway first and then in SmartConsole

Buy Now
Questions 7

What is the correct command to turn off an IKE debug?

Options:

A.

vpn debug ikeoff

B.

fw ctl debug ikeoff

C.

vpn debug ikeoff 0

D.

fw ctl vpn debug ikeoff

Buy Now
Questions 8

In order to review the IPS statistics to determine if adjustments can be made to improve performance, which command would you use to get the appropriate information?

Options:

A.

fw monitor –e “accept IPS_stats;” >> ips_statistics.xml

B.

fw ctl debug –m ips debug_compilation

C.

fw ctl set int enable_ips_debug_output 1

D.

$FWDIR/scripts/get_ips_statistics.sh 10.1.1.1 60

Buy Now
Questions 9

The clusterXL_monitor_ips script.

Options:

A.

registers the host_monitor device and checks end-to-end connectivity to routes and other network devices.

B.

registers devices with the name of a process specified in the cpha_proc_list file.

C.

registers devices that monitor the IPS blade.

D.

registers the admin_down device and checks the change in the member’s status and provides feedback to the user.

Buy Now
Questions 10

How would an administrator view the routing table on the Security Gateway of production network where IPv6 is being used?

Options:

A.

show route –A inet6

B.

ip -6 addr show

C.

netstat –rn –A inet6

D.

ip -6 neigh show

Buy Now
Questions 11

What is enabled by the command “vpn debug mon”?

Options:

A.

statistics monitoring for vpn encrypted packets

B.

vpn daemon monitor mode

C.

ike monitor

D.

vpn debug mode

Buy Now
Questions 12

Your company plans to start migration on IPv6 protocol. What steps do you need to perform to fully enable IPv6 protocol on the Security Gateway?

Options:

A.

Issue “set ipv6 enable”; Save configuration and reboot

B.

Issue “set ipv6-state on”; Save configuration and reboot

C.

Issue “set ipv6 on”; Save configuration and reboot

D.

Issue “set ipv6-state enable”; Save configuration and reboot

Buy Now
Questions 13

Which kernel debug flag should you use to troubleshoot NAT connections?

Options:

A.

fw ctl debug + xlate xltrc nat table

B.

fw ctl debug + xltrc xlate nat conn

C.

fw ctl debug + xlate xltrc nat conn drop

D.

fw ctl debug + fwx_alloc nat conn drop

Buy Now
Questions 14

Which IPS command debug tool can you use for troubleshooting IPS traffic?

Options:

A.

ips debug traffic –o IPSdebug

B.

ips debug –f /var/log/IPSdebug.txt

C.

debug ips enable –o IPSdebug

D.

ips debug –o IPSdebug

Buy Now
Questions 15

You are working with multiple Security Gateways enforcing an extensive number of rules. To simplify security administration, which action would you choose?

Options:

A.

Eliminate all possible contradictory rules such as the Stealth or Cleanup rules

B.

Create a separate Security Policy package for each remote Security Gateway

C.

Create network objects that restrict all applicable rules to only certain networks

D.

Run separate SmartConsole instances to login and configure each Security Gateway directly

Buy Now
Questions 16

Which command is used to write a kernel debug to a file?

Options:

A.

fw ctl debug –T –f > debug.txt

B.

fw ctl kdebug –T –l > debug.txt

C.

fw ctl debug –S –t > debug.txt

D.

fw ctl kdebug –T –f > debug.txt

Buy Now
Questions 17

What is the default setting and minimum value of the Sync tick timer?

Options:

A.

500ms

B.

1000ms

C.

100ms

D.

1500ms

Buy Now
Questions 18

What is the default and maximum number of entries in the ARP Cache Table in a Check Point appliance?

Options:

A.

1,024 and 4,096

B.

4,096 and 16,384

C.

4,096 and 65,536

D.

1,024 and 16,384

Buy Now
Questions 19

Which daemon would you debug if you have issues acquiring identities via identity sharing and identities with other gateways?

Options:

A.

pdpd

B.

wstlsd

C.

iad

D.

pepd

Buy Now
Questions 20

For organizations with existing IPv4 networks who wish to move to IPv6, which of the following is a Transition Mechanism that can be used?

Options:

A.

ipv4 to ipv6 Triple Stack

B.

Hex to Dec translation

C.

6 in 4 Tunneling

D.

NAT-T to NAT6sec

Buy Now
Questions 21

What is the proper syntax to enter the “central database” that contains all objects within the Postgres database?

Options:

A.

psql_client cpm postgres

B.

psql_client checkpoint postgres

C.

psql_client central_database postgres

D.

In clish: show postgres main

Buy Now
Questions 22

Which of the following is NOT a valid “fwaccel” parameter?

Options:

A.

stat

B.

stats

C.

templates

D.

packets

Buy Now
Questions 23

You run “cat/proc/smt_status” on your security gateway and the output shows ‘Soft Disable’. How is your system configured in reference to hyper-threading?

Options:

A.

Hyper-threading is disabled in BIOS and cpconfig

B.

Hyper-threading is enabled in BIOS but disabled in cpconfig

C.

Hyper-threading is disabled in BIOS but enabled in cpconfig

D.

Your system does not support Hyper-threading

Buy Now
Status:
Expired
Exam Code: 156-115.80
Exam Name: Check Point Certified Security Master - R80
Last Update: Apr 14, 2023
Questions: 159
$72  $159.99
$54  $119.99
$45  $99.99
buy now 156-115.80