Excellent 156-115.80 Updated 2021 Dumps With 100% Exam Passing Guarantee
Best way to practice test for CheckPoint 156-115.80
NEW QUESTION 49
How can you print the session UUID and the UUID of a connection together in fw monitor?
- A. The switches -s and -u are mutually exclusive and cannot be printed together
- B. fw monitor -uids -e "accept <FILTER EXPRESSION>;"
- C. fw monitor -s -u -e "accept <FILLTER EXPRESSION>;"
- D. fw -s monitor -u -e "accept <FILTER EXPRESSION>;"
Answer: A
NEW QUESTION 50
While using IPS, the network performance is being impacted on a load sharing cluster with asymmetric. What is most likely causing the degradation?
- A. A static NAT has been configured and an IPS protection requires the connection be handled on the same cluster member
- B. Secure XL has been disabled
- C. A failure in the sync network protocol
- D. Core XL has been disabled
Answer: C
NEW QUESTION 51
Joey's implementing a new R80.10 firewall cluster into the network. During the implementation he notices that the cluster object is in error state in SmartConsole. He tries to figure out the cause of the problem and runs a ClusterXL kernel debug with command: 'fw ctl debug -m cluster + stat pnote conf ccp' ClusterXL kernel debug shows him following info: fwha_set_new_local_state: Old version HA machines exist around so prevent state change to READY.
How can he solve the problem?
- A. cphaconf cluster_id set <NEW_CLUSTER_ID_VALUE>
- B. cphaprob mmagic
- C. Connect with GuiDBedit Tool to Security Management Server. Go to Table - Network Objects - network_objects. Select the relevant R80.10 Cluster object. Go to Search menu - Find - paste mac_magic. Right-click on the mac_magic the object - select Edit... and change the value to 254.
Save changes and install policy. - D. Connect with GuiDBedit Tool to Security Management Server. Go to Table - Network Objects - network_objects. Select the relevant R80.10 Cluster object. Go to Search menu - Find - paste cluster_magic. Right-click on the cluster_magic the object - select Edit... and change the value between 1 and 253. Save changes and install policy.
Answer: D
Explanation:
Explanation/Reference:
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk25977
NEW QUESTION 52
You issued the command "set ipv6-state on" in order to enable IPv6 protocol on a Security Gateway. The command was executed successfully. After reboot you notice that IPv6 protocol is not enabled. What do you do to permanently enable IPv6 protocol?
- A. You need to install a valid license to use IPv6 protocol
- B. You need to modify Gateway Properties in SmartConsole and install policy in order to enable IPv6
- C. Issue "set ipv6-state on" again; Save configuration and reboot
- D. You need to set "ipv6_state" parameter in $FWDIR/boot/modules/fwkern.conf and reboot
Answer: C
NEW QUESTION 53
What occurs when Bypass Under Load activated?
- A. Packets are forwarded to the destination without performing IPS analysis
- B. To still ensure a minimum level of data integrity, the system revert to the use of MD5 instead of SHA-1, since former produces an output smaller than the latter
- C. Packets are forwarded to the destination without checking the packets against the firewall rule base
- D. The amount of the state table entries is decreased according to the LRU (least recently used) algorithm
Answer: A
Explanation:
Explanation/Reference:
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_IPS_AdminGuide/12750.htm
NEW QUESTION 54
What are some measures you can take to prevent IPS false positives?
- A. Use Recommended IPS profile
- B. Use IPS only in Detect mode
- C. Exclude problematic services from being protected by IPS (sip, H.323, etc.)
- D. Capture packets, Update the IPS database, and Back up custom IPS files
Answer: C
NEW QUESTION 55
Static NAT has been configured and NAT rules were created automatically. The global properties option
"Translate on client side" is not checked. Clients are complaining that they are not able to connect to one of your web servers using its public address. How would you solve the problem without changing the global properties and reinstalling the security policy?
- A. You will have to change the global properties and reinstall the security policy
- B. Configure manual NAT
- C. Rebooting the security gateway will resolve the problem
- D. On the security gateway, add a static route for the web server's public ip address.
Answer: D
NEW QUESTION 56
The CPM process uses what ports?
- A. 18265 and 257
- B. 19009 and 18120
- C. 18265 and 9009
- D. 19009 and 9009
Answer: D
NEW QUESTION 57
Which file would you need to make sure you collect when debugging a VPN that fails to establish that is configured to use IKEv2?
- A. $CPDIR/log/ike.elg
- B. $FWDIR/log/vpnd.xml.v2
- C. $FWDIR/log/ike2.elg
- D. $FWDIR/log/ikev2.xml
Answer: D
NEW QUESTION 58
Which command will register the host_monitor device and checks end-to-end connectivity to routers and other network devices?
- A. clusterXL_monitor_ips
- B. clusterXL_admin
- C. clusterXL_monitor_process
- D. clusterXL_monitor_admin
Answer: A
NEW QUESTION 59
Which layer in the IPS blade is responsible for reassembly of TCP packets as they arrive at the gateway?
- A. Protocol Parsers
- B. Protections
- C. Contexts Management
- D. Passive Streaming Library
Answer: D
NEW QUESTION 60
Of how many packets consists Main in Phase 1?
- A. Three packets
- B. Four packets
- C. Six packets
- D. It depends on the encryption algorithm used 3DES has three times more than DES encryption
Answer: C
NEW QUESTION 61
While using IPS, the network performance is being impacted on a load sharing cluster with asymmetric. What is most likely causing the degradation?
- A. A static NAT has been configured and an IPS protection requires the connection be handled on the same cluster member
- B. Secure XL has been disabled
- C. Core XL has been disabled
- D. A failure in the sync network protocol
Answer: C
NEW QUESTION 62
Which is the correct "fw monitor" syntax for create a capture file for loading it into WireShark?
A)
B)
C)
D)
- A. Option A
- B. Option D
- C. Option B
- D. Option C
Answer: B
NEW QUESTION 63
Consider a Check Point Security Gateway under high load. What mechanism can be used to confirm that important traffic such as control connnections are not dropped?
- A. fgate -d load
- B. fw debug fgd 50 on OPSEC_DEBUG_LEVEL
- C. fw ctl multik priod
- D. fw ctl debug -m fg all
Answer: B
NEW QUESTION 64
Which file would you need to make sure you collect when debugging a VPN that fails to establish that is configured to use IKEv2?
- A. $FWDIR/log/ikev2.xml
- B. $FWDIR/log/vpnd.xml.v2
- C. $SPDIR/log/ike.elg
- D. $FWDIR/log/ike2.elg
Answer: C
NEW QUESTION 65
Which type of SecureXL templates is enabled by default on Security Gateways?
- A. Drop
- B. VPN
- C. NAT
- D. Accept
Answer: D
NEW QUESTION 66
What is the recommended command to manually initiate a failover on a cluster member in HA?
- A. Perform a clusterXL_admin down on the standby member
- B. Perform a clusterXL_admin down on the active member
- C. Perform a cpstop on the standby member
- D. Perform a cpstop on the active member
Answer: B
NEW QUESTION 67
Joey's implementation a new R80.10 firewall cluster into the network. During the implemenation he notices that the cluster object is in error state in SmartConsole. He tries to figure out the cause of the problem and runs a Cluster XL kernel debug with command
'fw ctl debug -m cluster + state priote conf ccp'
Cluster XL kernel debug shown him follwing info: fwha_set_new_local_state: Old version HA machines exist around so prevent state change to READY.
How can be the solve the problem?
- A. Connect with GuiDBedit Tool to Security Management Server. Go to Table - Network Objects - network_objects. Select the relevant R80.10 Cluster object. Go to Search menu
- Find - paste cluster_magic. Right-click on the cluster_magic the object - select Edit...
and change the value between 1 and 253. Save changes and install policy. - B. Cphaprob mmagic
- C. Cphaconf cluster_id set <NEW_CLUSTER_ID_VALUE>
- D. Connect with GuiDBedit Tool to Security Management Server. Go to Table - Network Objects - networks. Select the relevant R80.10. Cluster object. Go to Search menu - Find
- paste mac_magic. Right-click on the mac_magic the object -select Edt... and change the value to 254. Save changes and install policy.
Answer: A
Explanation:
Reference:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolution details=&solutionid=sk25977
NEW QUESTION 68
If cluster members are geographically separated and the time to detect a failover needs to be longer, what timer needs to be adjusted?
- A. fwha_geosync_timer
- B. fwha_timer_cpha_res
- C. fwha_timer_dist_res
- D. fwha_timer_sync_res
Answer: B
Explanation:
Explanation/Reference:
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_ClusterXL_AdminGuide/7298.htm
NEW QUESTION 69
According to the CCSM manual what is the first step in generating vpn debugging information?
- A. Kill all traffic over the VPN and enter "vpn tu" in Expert mode
- B. Enter "vpn debug ikeon"
- C. Turn the firewall of then on again
- D. Enter "vpn debug off" then "vpn debug on"
Answer: D
NEW QUESTION 70
......
Check Point Certified Security Master - R80 Certification Sample Questions and Practice Exam: https://www.examboosts.com/CheckPoint/156-115.80-practice-exam-dumps.html