DCompliance Reports, Events Logs and Reports, Best Practices Tests
What is the correct statement about requirement of a JSON configuration file when upgrading a Security Management / Log / SmartEvent Server using CPUSE?
AA JSON configuration file is required to upgrade any Check Point device prior to R80.20 when upgrading to R82 or above release
BThere is no such requirement of a JSON configuration file when using CPUSE. The CPUSE upgrade is completely automatic
CA JSON configuration file is required only if there is a change of IP address on an of the Security Management / Log / SmartEvent servers
DA JSON configuration is always required when upgrading a Security Management / Log / SmartEvent server to R82 or above release
Where does an administrator need to navigate to in the SmartConsole to carry out a Central Deployment upgrade?
ACOMMAND LINE
BGATEWAYS & SERVERS
CMANAGE & SETTINGS
DINFINITY SERVICES
When it comes to manual synchronization, what statement is true?
AYou can only initiate a Full Synchronization via Manual Sync.
BYou can only initiate a Delta Synchronization via Manual Sync.
CYou can choose whether to perform a Full Sync or Delta Sync when it comes to do a Manual Sync.
DManual Sync is only done at the very beginning to force a Cluster Join after having installed the Secondary Management Server.
In Management HA the failover is:
AAlways manual
BAutomatic by default, but can be changed to manual
CManual by default, can be changed to automatic
DAlways automatic
Which Management Server Process receives an install command if it comes to install a policy?
AThe CPM process is involved in installing a policy to the gateway.
BThe CPWD process invokes the install function.
CThe FWM process is involved in installing the policy.
DThe FWD process is involved in installing a policy.
According to the policy installation, the transfer state (CPTA) is invoked by the FWM (Firewall) process which initiates the Transfer/Commit phase. On the Security Gateway side a process receives them and first stores them into a temporary directory. Which process is true for receiving these files?
AFWD
BCPD
CFWM
DRAD
Can a VPN Gateway be a member of more than one VPN community?
ANo, it could be used only in one VPN Community.
BYes, it is possible, but with correct modifications of vpn_route.conf file on each VPN Gateway
CYes, if it doesn’t pair with another VPN Gateway in more than one VPN Community.
DYes, it could be used in more than one VPN Community, if all VPN Gateways are managed with the same Security Management.
Where can Firewall administrator configure VPN routes between Security Gateways?
Avpn_route.conf (on Security Management)
Bvia Gaia Portal or CLI (on Security Gateway)
CVTI_route.conf (on Security Management)
Dvpn_route.conf (on Security Gateway)
How does SmartEvent determine whether events originated internally or externally?
ABy defining the Internal Network under the Initial Settings in SmartEvent GUI Client
BEvents with a non-routable private source IPs are considered to be originating from internal networks
CSmartEvent queries Security Gateway topology to determining the direction of events
DSmartEvent uses AI / ML to determine the direction of events
SmartEvent general settings and event policy is configured using this interface / tool.
ASmartEvent GUI Client
BSmartView in Web Browser
CSmartConsole -> Logs and Monitor
DSmartLog
What is the SMO?
AThe SMO is the name given to the cluster member with the highest priority in the SmartConsole Cluster object. The SMO distributes the policy to the other cluster members defined in the Cluster object.
BThe SMO is a Security Gateway object in SmartConsole that defines the IP address and the security features deployed on the ElasticXL Cluster.
CThe Single Management Object (SMO) is a special object reserved for Quantum Maestro solutions.
DThe SMO is the only cluster member added to the cluster object and it defines the IP address for policy installation.
What is the CLI command to check the Deployment Agent Built Number?
Ashow deployment agent -v
Bshow installer version
Cshow deployment agent --version
Dshow installer status
What is the minimum version required to install an ElasticXL Cluster?
AR81.10 with Jumbo Hot Fix Take 177
BR82.10
CR81.20 with Jumbo Hot Fix Take 105
DR82
Which of these commands will show the availability of a new ElasticXL Cluster member?
Ashow cluster info overview
Bshow elasticxl members
Cshow provision info available
Dshow provision members new
In the Management HA environment how many synchronization methods are supported?
A1
B4
C3
D2
What is true about the magg1 and Sync interfaces on an ElasticXL Cluster?
Amagg1 is a bonded interface, Sync is also a bonded interface
Bmagg1 is a secondary interface of the Mgmt Port, Sync is the Sync port
Cmagg1 is a bonded interface, Sync is an individual Sync Port
Dmagg1 is only available in Maestro and is a disabled and unused port in ElasticXL. Sync is the Sync Port
Network Feed objects are used as a Source or Destination in Access Control, HTTPS Inspection, and Threat Prevention Policies. What file formats are supported for download in Network Feed objects?
AFlat list only
BFlat list and XML
CJSON only
DFlat list or JSON
To which directory does CPTA transfer policy files to the Security Gateway?
A$FWDIR/state/_tmp/FW1
B$FWDIR/state/local/FW1
C$CPDIR/state/tmp/FW1
D$FWDIR/state/_tmp/FW1
To form a tunnel IKEv2 uses two exchange types - IKE_SA_INIT and IKE_AUTH. How many packets are transferred between the VPN peer gateways during the two exchanges?
AEach exchange involves two messages, making a total of 4 packets.
BFor a site-to-site VPN on Check Point using IKEv2, the normal exchange is indeed nine packets
C9 packets unless legacy peers are included in the VPN community, which uses just 6 packets, 3 per exchange.
D6 packets. There are 4 in the SA_INIT exchange because of the Diffie Hellman process.
Which Upgrade method is initiated from SmartConsole?
ACentral Deployment
BCPUSE
CAdvanced Upgrade
DCentral Deployment Tool
Which tool can be used to automate upgrades and hotfixes installation?
ACPUSE
BCDT
CDA
DAPI
What can be upgraded using Central Deployment?
ASecurity Management Servers, Gateways, Cluster Members
BSecurity Management Servers, Dedicated Log Servers, Gateways, Cluster Members
CGateways, Cluster Members
DOnly Gateways (no Clusters)
When the Management Server Database is exported using the migrate_server tool, what is exported?
AThe current database revision and unpublished changes that are saved are all exported
BAll previous and current revisions of the database are exported
CLast 3 revisions of the database are exported
DOnly the current database revision is exported, unpublished changes are not exported
Which command do you need to run before importing the Management Database on a fresh installed Security Management?