Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

156-115.77 Questions and Answers

Note! Following 156-115.77 Exam is Retired now. Please select the alternative replacement for your Exam Certification.

156-115.77 Questions and Answers

Question # 6

What causes the SIP Early NAT chain module to appear in the chain?

A.

The SIP traffic is trying to pass through the firewall.

B.

SIP is configured in IPS.

C.

A VOIP domain is configured.

D.

The default SIP service is used in the Rule Base.

Full Access
Question # 7

When you perform an install database, the status window is filled with large amounts of text. What could be the cause?

A.

There is an active fw monitor running.

B.

There is an environment variable of TDERROR_ALL_ALL set on the gateway.

C.

There is an active debug on the SmartConsole.

D.

There is an active debug on the FWM process.

Full Access
Question # 8

What command can be used to get the following output?

A.

fw ctl kdebug

B.

fw monitor –e “accept;”

C.

fwaccel conns

D.

netstat -ni

Full Access
Question # 9

When running a SecureXL debug how do you initialize the debug buffer to 32000?

A.

fwaccel debug –buf 32000

B.

fw ctl debug –buf 32000

C.

sim debug –buf 32000

D.

fwaccel dbg –buf 32000

Full Access
Question # 10

Which of the following statements are TRUE about SecureXL?

I. SecureXL is able to accelerate all connections through the firewall.

II. Medium path acceleration will still cause some CPU utilization of CoreXL cores.

III. F2F connections represent “forwarded to firewall” connections that are not accelerated and fully processed through the firewall kernel.

IV. Packets going through SecureXL must be inspected by the firewall kernel before being accelerated.

A.

II and III

B.

I, II, and III

C.

III and IV

D.

I and IV

Full Access
Question # 11

What command show the same information as fwaccel stats –l?

A.

cat /proc/ppk/cpls

B.

cat /proc/ppk/statistics

C.

cphaprob –a hconf

D.

fwaccell stats –s –u -k

Full Access
Question # 12

Which command displays FireWall internal statistics about memory and traffic?

A.

fw getifs

B.

cpstat os –f memory

C.

fw ctl pstat

D.

cpstat os –f cpu

Full Access
Question # 13

What should you do after editing fwkern.conf to enable NAT templates?

A.

Install database

B.

Reboot

C.

Install policy

D.

Make sure the change shows up in Smartview Monitor

Full Access
Question # 14

Which file holds global Kernel values to survive reboot in a Check Point R77 gateway?

A.

$FWDIR/conf/fwkern.conf

B.

$FWDIR/boot/modules/fwkern.conf

C.

$FWDIR/boot/confwkern.conf

D.

$FWDIR/boot/fwkern.conf

Full Access
Question # 15

Which of these commands can be used to display the IPv6 routes?

A.

show route

B.

show ipv6 route

C.

show routes all

D.

show route ipv6

Full Access
Question # 16

ACME Corp has a cluster consisting of two 13500 appliances. As the Firewall Administrator, you notice that on an output of top, you are seeing high CPU usage of the cores assigned as SNDs, but low CPU usage on cores assigned to individual fw_worker_X processes. What command should you run next to performance tune your cluster?

A.

fw ctl debug –m cluster + all – this will show you all the connections being processed by ClusterXL and explain the high CPU usage on your appliance.

B.

fwaccel off – this will turn off SecureXL, which is causing your SNDs to be running high in the first place.

C.

fwaccel stats –s – this will show you the acceleration profile of your connections and potentially why your SNDs are running high while other cores are running low.

D.

fw tab –t connections –s – this will show you a summary of your connections table, and allow you to determine whether there is too much traffic traversing your firewall.

Full Access
Question # 17

Does R77 SmartDashboard support IPv6?

A.

Yes provided the operating system on which Smart Dashboard is installed is configured with IPv6.

B.

SmartDashboard does not support IPv6.

C.

IPv6 needs to be tunneled through IPv4 to support IPv6.

D.

R77.20 and above provides the support for Smart Dashboard and IPv6 support.

Full Access
Question # 18

You enabled IPv6 in your environment and would like to erase all IPv6 connection tables. How can you do it?

A.

fw tab –t connections –x

B.

fw tab –t connections6 –x

C.

clear connections table ipv6

D.

fw6 tab –t connections –x

Full Access
Question # 19

Which of the following is true when IPv6 is enabled on a Security Gateway?

A.

An interface on the Gateway can either have IPv4 or IPv6 IP address or have both.

B.

As of version R77, IPv6 is only supported on Security Management Server.

C.

IPv4 will be completely disabled when IPv6 has been enabled.

D.

An interface on the Gateway can either have IPv4 or IPv6 IP address but cannot have both.

Full Access
Question # 20

Which flag in the fw monitor command is used to print the position of the kernel chain?

A.

-all

B.

-k

C.

-c

D.

-p

Full Access
Question # 21

Where in a fw monitor output would you see destination address translation occur in cases of inbound automatic static NAT?

A.

Static NAT does not adjust the destination IP

B.

Between the “i” and “I”

C.

Between the “I” and “o”

D.

Between the “o” and “O”

Full Access
Question # 22

In Tracker you are troubleshooting a VPN issue between your gateway and a partner site and you get a drop log that states “No proposal chosen” what is the most likely cause?

A.

There is a time mismatch

B.

The peer machine is not accepting multicast packets

C.

A mismatch in the settings between the two peers

D.

Using IKEv1 when peer uses IKEv2

Full Access
Question # 23

Which of the following is NEVER affected by incorrect OS time and date configuration?

A.

VPN PSK authentication

B.

VPN certificate authentication

C.

SIC

D.

Identity Awareness Kerberos authentication

Full Access
Question # 24

While troubleshooting a VPN issue between your gateway and a partner site you see an entry in Smartview Tracker that states “Info: encryption failure: Different community ID: possible NAT problem”. Which of the following is the most likely cause?

A.

You have an encryption method mismatch.

B.

Implied rules in global properties such as ICMP and DNS are set to first instead of before last.

C.

You have not created a specific rule allowing VPN traffic.

D.

You have the wrong encryption domains configured.

Full Access
Question # 25

Which of the following is NOT a cphaprob status?

A.

“Standby”

B.

“Active”

C.

“Backup”

D.

“Down Attention” (or “Down!” in VSX mode)

Full Access
Question # 26

Which command displays compression/decompression statistics?

A.

vpn ver –k

B.

vpn compstat

C.

vpn compreset

D.

vpn crlview

Full Access
Question # 27

Tom is troubleshooting NAT issues using fw monitor and Wireshark. He tries to initiate a connection from the external network to a DMZ server using the public IP which the firewall translates to the actual IP of the server. He analyzes the captured packets using Wireshark and observes that the destination IP is being changed as required by the firewall but does not see the packet leave the external interface. What could be the reason?

A.

The translation might be happening on the client side and the packet is being routed by the OS back to the external interface.

B.

The translation might be happening on the server side and the packet is being routed by OS back to the external interface.

C.

Packet is dropped by the firewall.

D.

After the translation, the packet is dropped by the Anti-Spoofing Protection.

Full Access
Question # 28

Given the screen configuration shown, the failure’s probable cause is:

A.

Packet 1 Proposes SA life Type , Sa Life Duration, Authentication and Encapsulation Algorithm.

B.

Packet 1 proposes a symmetrical key.

C.

Packet 1 proposes a subnet and host ID, an encryption and hash algorithm.

D.

Packet 1 proposes either a subnet or host ID, an encryption and hash algorithm, and ID data.

Full Access
Question # 29

You have just configured HA and find that connections are not being synced. When you have a failover, users complain that they are losing their connections. What command could you run to see the state synchronization statistics?

A.

fw ctl pstat

B.

fw sync stats

C.

cphaprob stat

D.

fw ctl get int fw_state_sync_stats

Full Access
Question # 30

Which command will NOT display information related to memory usage?

A.

free

B.

fw ctl pstat

C.

cat /proc/meminfo

D.

memoryinfo.conf

Full Access
Question # 31

Where would you find CPU information like model, number of cores, vendor and architecture?

A.

In the file cpuinfo in the directory /proc.

B.

Right click the gateway object in Smart Dashboard and view properties

C.

WebUI

D.

sysconfig

Full Access
Question # 32

What is the difference between “connection establishment acceleration” (templating) and “traffic acceleration”?

A.

These are the same technologies with different names.

B.

“Connection establishment acceleration” only accelerates a single connection, while “traffic acceleration” accelerates similar traffic.

C.

“Traffic acceleration” is accelerated through hardware, and “connection establishment acceleration” is accelerated in software.

D.

“Traffic acceleration” only accelerates a single connection, while “connection establishment acceleration” accelerates similar traffic.

Full Access
Question # 33

What command displays the Connections Table for a specified CoreXL firewall instance?

A.

fw tab –t connections –s

B.

fw -i FW_INSTANCE_ID tab -t connections [flags]

C.

fw tab –t connection | grep fw

D.

fw tab –t connections

Full Access
Question # 34

What does the output of the commands fw ctl multik stat and fw6ctl multik stat show?

A.

Only the number of total connections currently being handled by all Kernels on a CoreXL enabled firewalls.

B.

Information for each kernel instance. The output displays state and processing core number of each instance.

C.

Which CPU cores are Kernel and SND bound cores.

D.

The number of Firewall Kernels that are installed.

Full Access
Question # 35

You are at a customer site, and when you run cphaprob stat you are not seeing a normal ClusterXL Health. What command could you run verify the number of cores are not matched on both cluster members?

A.

cpconfig

B.

cphaprob -a if

C.

fw ctl multik stat

D.

cphaprob stat

Full Access
Question # 36

Your customer has a well optimized Rule Base with most traffic accelerated by SecureXL.  They are still seeing slow performance.   They are using an 8 core machine.  They see the following output from fw ctl affinity -l. What could be done to improve performance with this deployment?

A.

Increase the number of cores dedicated to logging.

B.

Increase the number of Secure Network Dispatchers as the accelerated traffic is not passed to a worker core.

C.

Add more CPU resources to the hardware.

D.

Upgrade to SAM hardware.

Full Access
Question # 37

When troubleshooting a VPN site-to-site to a peer, it may be necessary to "down" the tunnel. What is the best method to remove ONLY the tunnel to this peer?

A.

Change the vpn tunnel sharing parameters to force the tunnel down.

B.

Reboot your gateway.

C.

Remove the peer from the community and install policy.

D.

Delete the IKE and IPsec Security Associations using the command vpn tu.

Full Access
Question # 38

You are configuring OSPF on your Secure Platform firewall. You are in expert mode and run the commands:

interface vt-Gateway_C

IP ospf 1 area 0.0.0.0

exit

When you run show running-config you do not see your OSPF configuration listed Why?

A.

You did not run command save running config before you exited.

B.

You should not have moved to expert mode to make these configurations.

C.

You did not run command save configuration before you exited.

D.

You did not run command enable before you exited.

Full Access
Question # 39

Jane wants to create a VPN using OSPF. Which VPN configuration would you recommend she use?

A.

Site-to-site VPN

B.

Domain-based VPN

C.

Route-based VPN

D.

Remote-access VPN

Full Access
Question # 40

Where would an administrator set an email alert for a specific permanent VPN tunnel?

A.

Edit the file vpnconf.

B.

Run sysconfig.

C.

In the Tunnel Properties select Mail Alert.

D.

You can only enable logging or SNMP traps.

Full Access
Question # 41

Where do you run the command get_ips_statistics.sh from?

A.

$FWDIR/conf on the Management Server

B.

$FWDIR/scripts on the Management Server

C.

$FWDIR/conf on the gateway

D.

$FWDIR/scripts on the gateway

Full Access
Question # 42

One of IPS Layers’ main functions are to ensure compliance to well-defined protocol standards, detect anomalies if any exist, and assemble the data for further inspection by other components of the IPS engine. Which component is responsible for these functions?

A.

Context Management Interface layer (CMI)

B.

Protections

C.

Protocol Parsers

D.

Passive Streaming Library (PSL)

Full Access
Question # 43

You have created a number of profiles and activated the relevant protections. Afterwards, you decide that the ‘Enterprise gateway’ should allow instant messaging. The current profile enabled for Enterprise gateway blocks instant messaging. The profile for the Enterprise gateway is currently being used on the Voyager gateway and the Bird of Prey gateway. What is the best process for making this change on the Enterprise gateway only?

A.

Create an exception for the Enterprise gateway

B.

Create a rule allowing that traffic and install it on the Enterprise gateway

C.

Create a new profile and apply to the Enterprise gateway

D.

Edit the existing profile

Full Access
Question # 44

You are troubleshooting an issue for your HR team. One of the users is using IP 10.10.10.24. They having been trying to access the vacation servers but all connections are failing. You have checked the logs and do not see any dropped traffic. You have a suspicion that the drop is not being logged. What command could you use to confirm this?

A.

fw -t connections -s

B.

fw ctl zdebug + log dynlog

C.

You cannot run a command for this; you must enable logging on all rules

D.

fw ctl pstat host 10.10.10.24

Full Access