Pre-Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

156-315.82 Questions and Answers

Question # 6

To form a tunnel, IKEv2 uses two exchange types: IKE_SA_INIT and IKE_AUTH. How many packets are transferred between the VPN peer gateways during the two exchanges?

A.

Each exchange involves two messages, making a total of 4 packets.

B.

For a Site-to-Site VPN on Check Point using IKEv2, the normal exchange is 9 packets.

C.

9 packets unless legacy peers are included in the VPN community, which uses only 6 packets, 3 per exchange.

D.

6 packets. There are 4 in the SA_INIT exchange because of the Diffie-Hellman process.

Full Access
Question # 7

Alice wants to upgrade the current Security Management machine to R82, and she wants to check the Deployment Agent status over Gaia Clish. Which of the following Gaia Clish commands is correct?

A.

show agent status

B.

show installer packages

C.

show uninstaller status

D.

show installer status

Full Access
Question # 8

In Management HA, the failover is:

A.

Always manual.

B.

Automatic by default, but can be changed to manual.

C.

Manual by default, but can be changed to automatic.

D.

Always automatic.

Full Access
Question # 9

After running the First Time Configuration Wizard for the Secondary Management Server installation, what is the next step to set up a Management High Availability environment?

A.

You have to synchronize the databases manually in SmartConsole.

B.

You have to initiate Secure Internal Communication to the Primary Management Server.

C.

You must specify an administrator with the Superuser access role.

D.

You must specify the corresponding GUI Clients to authorize access to the newly created Secondary Management Server.

Full Access
Question # 10

Which components can be upgraded using Central Deployment Tool, CDT?

A.

Gateways / Cluster Members

B.

Multi-Domain Servers, Management Servers, and Gateways

C.

Gateways, Clusters, and Management Servers

D.

Gateways, Clusters, and Standalone Deployments

Full Access
Question # 11

While working in the Compliance tab, you have identified under Security Best Practices Compliance a score of 25% for Poor. You click on Poor to review the Security Best Practices with status Poor. What should you do next?

A.

Deactivate each Poor Best Practice and add a comment before clicking OK.

B.

Change the status of each Best Practice to Good.

C.

Analyze each Best Practice, review the details, investigate, and take action where possible.

D.

After reviewing, right-click each Active Best Practice and click Correct and deactivate. The Copilot will configure the settings according to Best Practices.

Full Access
Question # 12

Which Management Server process receives an install command when installing a policy?

A.

The CPM process is involved in installing a policy to the gateway.

B.

The CPWD process invokes the install function.

C.

The FWM process is involved in installing the policy.

D.

The FWD process is involved in installing a policy.

Full Access
Question # 13

Choose the correct command to export the Management Database with logs and log indexes.

A.

$FWDIR/scripts/migrate_server export -v < target version > -n < file >

B.

$FWDIR/bin/upgrade_tools/migrate export -l < file >

C.

$FWDIR/scripts/migrate_server export -v < target version > -x < file >

D.

$FWDIR/bin/upgrade_tools/migrate export -x < file >

Full Access
Question # 14

What must be taken into consideration in some scenarios with Manual NAT rules?

A.

You must edit the $FWDIR/conf/local.arp file on the Management Server with vi.

B.

In Global Properties, under NAT, you must activate “Automatic ARP Configuration,” which is not activated by default.

C.

In Global Properties, under NAT, you must activate “Merge Manual Proxy ARP Configuration,” and you must configure Manual Proxy ARP via Gaia Portal.

D.

You must add a manual NAT rule between two automatically created NAT rules.

Full Access
Question # 15

What is true when using the In-place upgrade method?

A.

Only cluster members are allowed to be upgraded with this method.

B.

Only Management Servers are allowed to be upgraded with this method. Security Gateways must be upgraded using Central Deployment or a fresh installation.

C.

Only the Primary and Secondary Management Servers are allowed to be upgraded with this method.

D.

Any of the Management Servers or Gateways are allowed to be upgraded using this method.

Full Access
Question # 16

Which of the following is a trigger for synchronization between Active and Standby servers?

A.

Publishing a session in SmartConsole.

B.

Making a change in a network object and clicking OK.

C.

Running the Save operation from the SmartConsole toolbar or menu.

D.

After 10 seconds of inactivity in SmartConsole.

Full Access
Question # 17

In Management HA, the failover is:

A.

Always manual

B.

Automatic by default, but can be changed to manual

C.

Manual by default, can be changed to automatic

D.

Always automatic

Full Access
Question # 18

The ability to make more than one server Active at the same time in Security Management High Availability is known as:

A.

The statement is not true; only one server can be Active at a time.

B.

Active-Active mode.

C.

Multi-Active Security Management Server mode.

D.

Collision Mode.

Full Access
Question # 19

According to the policy installation flow, the transfer stage, CPTA, is invoked by the FWM process, which initiates the Transfer/Commit phase. On the Security Gateway side, a process receives the policy files and first stores them into a temporary directory. Which directory for the Commit phase is correct for receiving these files?

A.

$FWDIR/state/_tmp/FW1

B.

$CPDIR/state/local/FW-1

C.

$FWDIR/state/local/FW1

D.

$FWDIR/state/local/FW-1

Full Access
Question # 20

Can a VPN Gateway be a member of more than one VPN Community?

A.

No, it can be used only in one VPN.

B.

Yes, it is possible, but with correct modifications of the vpn_route.conf file on each VPN Gateway.

C.

Yes, if it does not pair with another VPN Gateway in more than one VPN Community.

D.

Yes, it can be used in more than one VPN Community if all VPN Gateways are managed with the same Security Management Server.

Full Access
Question # 21

When exporting the database, are the logs and indexes automatically exported?

A.

Indexes are exported, but not logs.

B.

Logs are exported, but not indexes.

C.

No.

D.

Yes.

Full Access
Question # 22

Which process is responsible for the code generation and compilation of Legacy Dump files?

A.

FWM

B.

CPM

C.

Stateful Compiler

D.

Inspect Engine

Full Access
Question # 23

What is true about the magg1 and Sync interfaces on an ElasticXL Cluster?

A.

magg1 is a bonded interface; Sync is also a bonded interface.

B.

magg1 is a secondary interface of the Mgmt port; Sync is the Sync port.

C.

magg1 is a bonded interface; Sync is an individual Sync port.

D.

magg1 is only available in Maestro and is a disabled and unused port in ElasticXL. Sync is the Sync port.

Full Access
Question # 24

After upgrading the Primary Security Management Server from R81.20 to R82, Bob wants to use Central Deployment in SmartConsole R82 for the first time. How many installations, Jumbo Hotfixes, Hotfixes, or Upgrade Packages, can run at the same time?

A.

Up to 3 Gateways

B.

Up to 10 Gateways

C.

Up to 5 Gateways

D.

Only 1 Gateway

Full Access
Question # 25

Bob was tasked by his security team lead to enhance their existing Primary Security Management solution by deploying a Management High Availability solution. What server component is required?

A.

Log Server

B.

Security Gateway

C.

SmartEvent Server

D.

Secondary Management Server

Full Access
Question # 26

What is the default network for ElasticXL sync?

A.

192.0.2.0/24

B.

192.168.2.0/24

C.

192.0.0.0/24

D.

10.0.2.0/24

Full Access
Question # 27

What is the CLI command to check the Deployment Agent Build Number?

A.

show deployment agent -v

B.

show installer version

C.

show deployment agent --version

D.

show installer status

Full Access
Question # 28

Where can a Firewall administrator configure VPN routes between Security Gateways?

A.

vpn_route.conf on the Security Management Server

B.

Via Gaia Portal or CLI on the Security Gateway

C.

VTI_route.conf on the Security Management Server

D.

vpn_route.conf on the Security Gateway

Full Access
Question # 29

What can be upgraded using Central Deployment?

A.

Security Management Servers, Gateways, Cluster Members

B.

Security Management Servers, Dedicated Log Servers, Gateways, Cluster Members

C.

Gateways, Cluster Members

D.

Only Gateways, no Clusters

Full Access
Question # 30

When deploying Hotfixes with SmartConsole, how many concurrent installations can take place?

A.

20

B.

10

C.

5

D.

15

Full Access
Question # 31

When installing policy, which process is responsible for verification/conversion?

A.

CPD

B.

CPM

C.

FWM

D.

FWD

Full Access
Question # 32

What network is automatically assigned to the Sync bonding group in an ElasticXL Cluster?

A.

192.168.2.0/24

B.

192.0.2.0/24

C.

192.20.0.0/24

D.

169.254.0.0/24

Full Access
Question # 33

How many members are supported by an ElasticXL Cluster?

A.

Maximum three members per site with a maximum of three sites.

B.

Three members per site with a maximum of two sites.

C.

Maximum two members per site with a maximum of three sites.

D.

Up to four members per site with a maximum of two sites.

Full Access
Question # 34

When the Management Server Database is exported using the migrate_server tool, what is exported?

A.

The current database revision and unpublished changes that are saved are all exported.

B.

All previous and current revisions of the database are exported.

C.

Last 3 revisions of the database are exported.

D.

Only the current database revision is exported, unpublished changes are not exported.

Full Access
Question # 35

What should be upgraded first in the Advanced Upgrade method?

A.

Dedicated Log Server

B.

Secondary Management Server

C.

Primary Management Server

D.

Security Gateway

Full Access
Question # 36

How many packets are used in IKEv1 Phase 1 Main Mode exchange?

A.

6

B.

5

C.

8

D.

3

Full Access
Question # 37

How does SmartEvent determine whether events originated internally or externally?

A.

By defining the Internal Network under the Initial Settings in the SmartEvent GUI Client.

B.

Events with non-routable private source IPs are considered to be originating from internal networks.

C.

SmartEvent queries Security Gateway topology to determine the direction of events.

D.

SmartEvent uses AI/ML to determine the direction of events.

Full Access
Question # 38

Where does an administrator need to navigate in SmartConsole to carry out a Central Deployment upgrade?

A.

Command Line

B.

Gateways & Servers

C.

Manage & Settings

D.

Infinity Services

Full Access