CheckPoint Check Point Certified Security Administrator R81.20 156-215.81 Exam Questions

Page: 1 / 14
Total 411 questions
Question 1

Fill in the blanks: There are ________ types of software containers ________.



Answer : A

There are three types of software containers: security management, Security Gateway, and endpoint security. A software container is a set of software blades that provide specific functionality. A security management container manages the security policy and configuration for one or more Security Gateways. A Security Gateway container enforces the security policy on the network traffic.An endpoint security container protects the data and network access of an endpoint device2. The other options are not valid types of software containers. Reference:Software Containers


Question 2

True or False: In R80, more than one administrator can login to the Security Management Server with write permission at the same time.



Answer : B

The answer is B because in R80 and above, more than one administrator can login to the Security Management Server with write permission at the same time. Every administrator works in a session that is independent of the other administrators.This is called concurrent administration and it allows multiple administrators to work on the same policy package simultaneously34Reference:Check Point R80.10 Concurrent Administration,Check Point R80.40 Security Management Administration Guide


Question 3

Name the pre-defined Roles included in Gaia OS.



Answer : A

The pre-defined Roles included in Gaia OS are AdminRole and MonitorRole. AdminRole is the role that has full access to all Gaia features and commands.MonitorRole is the role that has read-only access to Gaia features and commands1. The other options are not valid pre-defined Roles in Gaia OS.


Question 4

Name the file that is an electronically signed file used by Check Point to translate the features in the license into a code?



Answer : B

The file that is an electronically signed file used by Check Point to translate the features in the license into a code is cp.macro. This file contains a list of macros that define the license features and their values. It is located in the $FWDIR/conf directory on the Security Management Server or Security Gateway. Reference: [Check Point R81 Licensing Guide], [Check Point R80.40 Licensing Guide]


Question 5

Fill in the blanks: Gaia can be configured using the ____ or ____



Answer : C

Check Point Gaia can be configured using:

The Command Line Interface (CLI) -- This includes Clish and Expert mode, accessible via SSH, console access, or direct login.

The GAiA Portal (WebUI) -- A browser-based graphical user interface used to manage Gaia settings.

Option A (incorrect): The CLI is not limited to serial console access. SSH is widely used.

Option B (incorrect): 'Gaia Ultimate Shell' is not an official term.

Option D (incorrect): 'Web Ultimate Interface' is not a valid name.

Thus, the correct answer is C. Command line interface; GAiA Portal.


Check Point official documentation states that Gaia can be managed using the CLI or WebUI (GAiA Portal).

Question 6

What is the purpose of Captive Portal?



Answer : C

Captive Portal is a feature of Identity Awareness that allows you to authenticate users through a web browser before they access the Internet or corporate resources.Captive Portal can be used for various authentication methods, such as user name and password, one-time password (OTP), or certificate3. Captive Portal does not manage user permission in SmartConsole, provide remote access to SmartConsole, or authenticate users to the Gaia OS. Those are different functions that are not related to Captive Portal. Reference:Check Point R81 Identity Awareness Administration Guide


Question 7

Fill in the blank: In Security Gateways R75 and above, SIC uses ______________ for encryption.



Answer : A

In Security Gateways R75 and above, SIC uses AES-128 for encryption. SIC stands for Secure Internal Communication, which is a mechanism that establishes trust between Check Point components, such as Security Gateways, Security Management Servers, Log Servers, etc. SIC uses certificates to authenticate and encrypt the communication between the components. AES-128 is an encryption algorithm that uses a 128-bit key to encrypt and decrypt data. The other options are incorrect. AES-256 is an encryption algorithm that uses a 256-bit key, but it is not used by SIC. DES and 3DES are older encryption algorithms that use 56-bit and 168-bit keys respectively, but they are not used by SIC either. Reference: [Secure Internal Communication (SIC) between Check Point components], AES - Wikipedia, DES - Wikipedia, Triple DES - Wikipedia


Page:    1 / 14   
Total 411 questions