156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 451-465

By on November 9, 2013
EnsurepassQUESTION 451 Review the following rules. Assume domain UDP is enabled in the implied rules. What happens when a user from the internal network tries to browse to the Internet using HTTP? The user: A. is prompted three times before connecting to the Internet successfully. B. can go to the Internet after Telnetting to the client auth daemon port 259. C. can connect to the Internet successfully after being authenticated. D. can go to the Internet, without being prompted for authentication. Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 441-450

By on
EnsurepassQUESTION 441 Antivirus protection on a Check Point Gateway is available for all of the following protocols, EXCEPT:   A. FTP B. SMTP C. HTTP D. TELNET   Answer: D     QUESTION 442 Which Security Servers can perform authentication tasks, but CANNOT perform content security tasks?   A. RHV HTTPS B. FTP C. RLOGIN D. HTTP   Answer: C     QUESTION 443 Which Security Servers can perform authentication tasks, but CANNOT perform content security Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 431-440

By on November 6, 2013
EnsurepassLatest 156-215.71 Real Exam Download 431-440  QUESTION 431 Which of the following statements about file-type recognition in Content Inspection is TRUE? A. Antivirus status is monitored using SmartView Tracker. B. A scan failure will only occur if the antivirus engine fails to initialize. C. All file types are considered "at risk", and are not configurable by the Administrator or the Security Policy. D. The antivirus engine acts as a proxy, caching the scanned file before delivering Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 421-430

By on
EnsurepassLatest 156-215.71 Real Exam Download 421-430  QUESTION 421 How can you access the Certificate Revocation List (CRL) on the firewall, if you have configured a Stealth Rule as the first explicit rule? A. You can access the Revocation list by means of a browser using the URL: http://IP-FW:18264/ICA CRL1.crl1 provided the implied rules are activated per default. B. The CRL is encrypted, so it is useless to attempt to access it. C. You cannot access the CRL, since the Stealth Rule Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 411-420

By on
EnsurepassLatest 156-215.71 Real Exam Download 411-420  QUESTION 411 Which of the following is NOT supported with Office Mode? A. SecuRemote B. SSL Network Extender C. SecureClient D. Endpoint Connect Answer: A  QUESTION 412 Which of the following is NOT supported with office mode? A. Transparent mode B. L2TP C. Secure Client D. SSL Network Extender Answer: A  QUESTION 413 Your organization has many Edge Gateways at various branch offices allowing users to access Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 401-410

By on
Ensurepass  QUESTION 401 If you were NOT using IKE aggressive mode for your IPsec tunnel, how many packets would you see for normal Phase 1 exchange? A. 6 B. 2 C. 3 D. 9 Answer: A  QUESTION 402 How many packets does the IKE exchange use for Phase 1 Main Mode? A. 6 B. 1 C. 3 D. 12 Answer: A  QUESTION 403 How many packets does the IKE exchange use for Phase 1 Aggressive Mode? A. 12 B. 3 C. 1 D. 6 Answer: B  QUESTION 404 Which of the following Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 391-400

By on
EnsurepassLatest 156-215.71 Real Exam Download 391-400  QUESTION 391 Which VPN Community object is used to configure Hub Mode VPN routing in SmartDashboard? A. Mesh B. Star C. Routed D. Remote Access Answer: B  QUESTION 392 When a user selects to allow Hot-spot, SecureClient modifies the Desktop Security Policy and/or Hub Mode routing to enable Hot-spot registration. Which of the following is NOT true concerning this modification? A. IP addresses accessed during registration Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 381-390

By on
EnsurepassLatest 156-215.71 Real Exam Download 381-390  QUESTION 381 Your company is still using traditional mode VPN configuration on all Gateways and policies. Your manager now requires you to migrate to a simplified VPN policy to benefit from the new features. This needs to be done with no downtime due to critical applications which must run constantly. How would you start such a migration? A. This cannot be done without downtime as a VPN between a traditional mode Gateway and a simplified Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 371-380

By on
EnsurepassLatest 156-215.71 Real Exam Download 371-380  QUESTION 371 What is used to validate a digital certificate? A. IPsec B. CRL C. S/MIME D. PKCS Answer: B  QUESTION 372 Assume an intruder has compromised your current IKE Phase 1 and Phase 2 keys. Which of the following options will end the intruders access after the next Phase 2 exchange occurs? A. Perfect Forward Secrecy B. SHA1 Hash Completion C. Phase 3 Key Revocation D. M05 Hash Completion Answer: A  QUESTION Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 361-370

By on
EnsurepassLatest 156-215.71 Real Exam Download 361-370  QUESTION 361 For remote user authentication, which authentication scheme is NOT supported? A. SecurlD B. TACACS C. Check Point Password D. RADIUS Answer: B  QUESTION 362 For information to pass securely between a Security Management Server and another Check Point component, what would NOT be required? A. The communication must be authenticated B. The communication must use two-factor or biometric authentication. C. Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 351-360

By on
EnsurepassLatest 156-215.71 Real Exam Download 351-360  QUESTION 352 Your users are defined in a Windows 2003 Active Directory server. You must add LDAP users to a Client Authentication rule. Which kind of user group do you need in the Client Authentication rule in R71? A. LDAP group B. All Users C. A group with a generic user D. External-user group Answer: A  QUESTION 353 Which type of R71 Security Server does not provide User Authentication? A. FTP Security Server B. SMTP Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 341-350

By on
EnsurepassLatest 156-215.71 Real Exam Download 341-350  QUESTION 341 As a Security Administrator, you are required to create users for authentication. When you create a user for user authentication, the data is stored in the ___________. A. SmartUpdate repository B. User Database C. Rules Database D. Objects Database Answer: B  QUESTION 342 Which of the following is a hash algorithm? A. DES B. IDEA C. MD5 D. 3DES Answer: A  QUESTION 343 Which of the following uses Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 331-340

By on
EnsurepassLatest 156-215.71 Real Exam Download 331-340  QUESTION 331 You cannot use SmartDashboard's SmartDirectory features to connect to the LDAP server. What should you investigate? A. 1 and 3 B. 1 and 2 C. 2 and 3 D. 1, 2, and 3 Answer: C  QUESTION 332 Identify the ports to which the Client Authentication daemon listens by default. A. 8080, 529 B. 259,900 C. 80, 256 D. 256,600 Answer: B  QUESTION 333 What is the Manual Client Authentication TELNET Port? A. Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 321-330

By on
EnsurepassLatest 156-215.71 Real Exam Download 321-330  QUESTION 321 What happens to evaluation licenses during the license-upgrade process? A. They are dropped. B. They remain untouched, but may not activate all features of a new version. C. They automatically expire. D. They are upgraded with new available features. Answer: B  QUESTION 322 One of your licenses is set for an IP address no longer in use. What happens to this license during the license-upgrade process? A. It Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 311-320

By on
EnsurepassLatest 156-215.71 Real Exam Download 311-320  QUESTION 311 Which of the following statements about service contracts, i.e., Certificate, software subscription, or support contract, is FALSE? A. A service contract can apply only for a single set of Security Gateways managed by the same Security Management Server. B. The contract file is stored on the Security Management Server and downloaded to all Security Gateways during the upgrade process. C. Most software-subscription contracts Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 301-310

By on
EnsurepassLatest 156-215.71 Real Exam Download 301-310  QUESTION 301 You plan to migrate a Windows NG with Application Intelligence (AI) R55 SmartCenter Server to R71. You also plan to upgrade four VPN-1 Pro Gateways at remote offices, and one local VPN-1 Pro Gateway at your company's headquarters to R71. The Management Server configuration must be migrated. What is the correct procedure to migrate the configuration? A. 1. Upgrade the remote gateway via smartUpdate. 2. upgrade the security Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 291-300

By on
EnsurepassLatest 156-215.71 Real Exam Download 291-300  QUESTION 291 Identify the correct step performed by SmartUpdate to upgrade a remote Security Gateway. After selecting Packages / Distribute and Install Selected Package and choosing the target Gateway, the: A. selected package is copied from the CD-ROM of the SmartUpdate PC directly to the Security Gateway and the installation IS performed. B. selected package is copied from the Package Repository on the Security Management Server to Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 281-290

By on
EnsurepassLatest 156-215.71 Real Exam Download 281-290  QUESTION 281 Your Security Gateways are running near performance capacity and will get upgraded hardware next week. Which of the following would be MOST effective for quickly dropping all connections from a specific attacker's IP at a peak time of day? A. SAM - Block Intruder feature of SmartView Tracker B. Intrusion Detection System (IDS) Policy install C. SAM - Suspicious Activity Rules feature of SmartView Monitor D. Change the Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 271-280

By on
EnsurepassLatest 156-215.71 Real Exam Download 271-280  QUESTION 271 What information is found in the SmartView Tracker Management log? A. Rule author B. TCP handshake average duration C. TCP source port D. Top used QOS rule Answer: A  QUESTION 272 Where do you enable popup alerts for IPS settings that have detected suspicious activity? A. In SmartView Monitor, select Tools / Alerts B. In SmartView Tracker, select Tools / Custom Commands C. In SmartDashboard, edit the Gateway Read more [...]

Continue Reading

156-215.71 Dumps | CheckPoint

Latest 156-215.71 Real Exam Download 261-270

By on
EnsurepassLatest 156-215.71 Real Exam Download 261-270  QUESTION 261 Which R71 SmartConsole tool would you use to verify the installed Security Policy name on a Security Gateway? A. SmartUpdate B. SmartView Server C. SmartView Tracker D. None, SmartConsole applications only communicate with the Security Management Server. Answer: C  QUESTION 262 You have detected a possible intruder listed in SmartView Tracker's active pane. What is the fastest method to block this intruder Read more [...]

Continue Reading