Issuu on Google+

     

Exam

: Check Point 156-215

Title

: Check Point Security Administration NGX

Version : R6.1

   

www.Prepking.com 

 


Prepking - King of Computer Certification Important Information, Please Read Carefully Other Prepking products A) Offline Testing engine Use the offline Testing engine product to practice the questions in an exam environment. B) Study Guide (not available for all exams) Build a foundation of knowledge which will be useful also after passing the exam. Latest Version We are constantly reviewing our products. New material is added and old material is updated. Free updates are available for 90 days after the purchase. You should check your member zone at Prepking and update 3-4 days before the scheduled exam date. Here is the procedure to get the latest version: 1.Go towww.Prepking.com 2.Click on Member zone/Log in (right side) 3. Then click My Account 4.The latest versions of all purchased products are downloadable from here. Just click the links. For most updates,it is enough just to print the new questions at the end of the new version, not the whole document. Feedback If you spot a possible improvement then please let us know. We always interested in improving product quality. Feedback should be send to feedback@Prepking.com. You should include the following: Exam number, version, page number, question number, and your login ID. Our experts will answer your mail promptly. Copyright Each PDF file contains a unique serial number associated with your particular name and contact information for security purposes. So if we find out that a particular PDF file is being distributed by you, Prepking reserves the right to take legal action against you according to the International Copyright Laws. Explanations This product does not include explanations at the moment. If you are interested in providing explanations for this exam, please contact feedback@Prepking.com.

   

www.Prepking.com 

 


1. You installed SmartCenter Server on a computer running SecurePlatform in the MegaCorp home office. You use IP address 10.1.1.1. You also installed the Security Gateway on a second SecurePlatform computer, which you plan to ship to another Administrator at a MegaCorp hub office. What is the correct order for setting up SIC on the Gateway before shipping it? 1. Run cpconfig on the Gateway, select "Secure Internal Communication", enter the activation key, and reconfirm. 2. Initialize SIC for the Gateway object on the SmartCenter Server. 3. Configure the gateway object with the host name and IP addresses for the remote site. 4. Click the Communication button in the gateway object's general screen, enter the activation key, and click Initialize and OK. 5. Install the Security Policy. Select the best response. A. 1, 3, 2, 4, 5 B. 2, 3, 1, 4, 5 C. 3, 4, 5 D. 1, 2, 4, 3 Answer: C 2. Another Administrator installed a new Nokia-based VPN-1 NGX Security Gateway, using IPSO, over the weekend. You want to confirm communication between the Security Gateway and the SmartCenter Server by installing the Security Policy on the Security Gateway. Assume all implied rules are enabled in Global Properties. What might prevent you from installing the Policy on the Security Gateway? Select the best response. A. You first need to run the fw unloadlocal command on the SmartCenter Server. B. There is no Secure Internal Communications (SIC) established between the Security Gateway and SmartCenter Server. You must initialize SIC on the Security Gateway object in SmartDashboard. C. You first need to run the fw unloadlocal command on the Security Gateway. D. You have not established Secure Internal Communications (SIC) between the Security Gateway and SmartCenter Server. You must initialize SIC on the SmartCenter Server. Answer: B 3. Another Administrator installed a new Nokia-based VPN-1 NGX Security Gateway, using IPSO, over the weekend. You suspect a corrupted Policy on the Gateway. You want to confirm communication between the Security Gateway and the SmartCenter Server by reinstalling the Security Policy on the Security Gateway. What might prevent you from installing the Policy on the Security Gateway? Select the best response. A. You first need to run the fw unloadlocal command on the Security Gateway.    

www.Prepking.com 

 


B. You first need to run the fw unloadlocal command on the SmartCenter Server. C. There is no Secure Internal Communications (SIC) established between the Security Gateway and SmartCenter Server. You must initialize SIC on the Security Gateway. D. You have not established Secure Internal Communications (SIC) between the Security Gateway and SmartCenter Server. You must initialize SIC on the SmartCenter Server. Answer: A 4. Another Administrator installed a new Nokia-based VPN-1 NGX Security Gateway, using IPSO, over the weekend. The administrator deselected "Accept VPN-1 Pro/Express control connections" in SmartDashboard>Global Properties' FireWall tab. He installed the current Policy on the IPSO Gateway. You want to confirm communication between the Security Gateway and the SmartCenter Server by installing the Security Policy on the Security Gateway. What might prevent you from installing the Policy on the Security Gateway? Select the best response. A. You first need to run the fw unloadlocal command on the Security Gateway. B. You first need to run the fw unloadlocal command on the SmartCenter Server. C. You have not established Secure Internal Communications (SIC) between the Security Gateway and SmartCenter Server. You must initialize SIC on the SmartCenter Server. D. There is no Secure Internal Communications (SIC) established between the Security Gateway and SmartCenter Server. You must initialize SIC on the Security Gateway. Answer: A 5. How can you reset Secure Internal Communications (SIC) between a SmartCenter Server and Security Gateway? Select the best response. A. Run the command fwm sic_reset to reinitialize the Internal Certificate Authority (ICA) of the SmartCenter Server. Then retype the activation key on the Security Gateway from SmartDashboard. B. From the SmartCenter Server's command line type fw putkey p <shared key> <IP Address of Security Gateway>. C. From cpconfig on the Security Gateway, choose the Secure Internal Communication option and retype the activation key. Next, retype the same key in the gateway object in SmartDashboard and reinitialize Secure Internal Communications (SIC). D. Use SmartUpdate to retype the activation key of the Security Gateway. Answer: C 6. The third shift Administrator was updating SmartCenter Access settings in Global Properties. He managed to lock himself out of his account. How can you unlock this account? Select the best response.    

www.Prepking.com 

 


A. Type fwm lock_admin u from the command line of the SmartCenter Server. B. Type fwm unlock_admin u from the command line of the Security Gateway. C. Delete the file admin.lock in the $FWDIR/tmp/ directory of the SmartCenter Server. D. Type fwm unlock_admin u from the command line of the SmartCenter Server. Answer: A 7. The third shift Administrator was updating SmartCenter Access settings in Global Properties. He managed to lock all of the administrators out of their accounts. How can you unlock these accounts? Select the best response. A. Type fwm lock_admin ua from the command line of the SmartCenter Server. B. Type fwm unlock_admin ua from the command line of the SmartCenter Server. C. Type fwm unlock_admin ua from the command line of the Security Gateway. D. Clear the "locked" box of the user's General Properties in SmartDashboard. Answer: A 8. Which SmartConsole tool would you use to verify the installed Security Policy name? Select the best response. A. SmartUpdate B. SmartView Monitor C. Eventia Reporter D. SmartView Status Answer: B 9. Which SmartConsole tool would you use to verify the installed Security Policy name? Select the best response. A. Eventia Reporter B. SmartView Status C. SmartView Server D. SmartView Monitor E. SmartUpdate Answer: D 10. Which SmartConsole tool would you use to see the last policy pushed in the audit log? Select the best response. A. SmartView Status B. SmartView Server C. SmartView Tracker D. Eventia Reporter Answer: C    

www.Prepking.com 

 


11. Upon checking SmartView Monitor, you find the following Critical Problem notification. Select the best response.

A. No Security Policy installed on the Security Gateway B. No Secure Internal Communications established between the SmartCenter Server and Security Gateway C. Time not synchronized between the SmartCenter Server and Security Gateway D. Version mismatch between the SmartCenter Server and Security Gateway Answer: A 12. What is the reason? A. No Security Policy installed on the Security Gateway B. No Secure Internal Communications established between the SmartCenter Server and Security Gateway C. Time not synchronized between the SmartCenter Server and Security Gateway D. Version mismatch between the SmartCenter Server and Security Gateway Answer: A 13. The Internal Certificate Authority (ICA) is corrupt on your SmartCenter Server. The server is installed on    

www.Prepking.com 

 


a SecurePlatform machine in the MegaCorp home office. You use IP address 10.1.1.1. You need to have management connectivity restored to a Security Gateway on a second SecurePlatform computer, which plan to ship to another Administrator at a MegaCorp hub office. What is the correct order for restoring management connectivity on the Gateway before shipping it? 1. Run cpconfig on the Gateway, select "Secure Internal Communication", enter the activation key, and reconfirm. 2. Run fwm sic reset on the SmartCenter Server. 3. Configure the gateway object with the host name and IP addresses for the remote site. 4. Click the Communication button in the gateway object's general screen, click Reset button, enter the activation key, and click Initialize and OK. 5. Install the Security Policy. Select the best response. A. 2, 1, 4, 5 B. 2, 3, 1, 4, 5 C. 1, 2, 3, 4 D. 1, 3, 2, 4, 5 Answer: A 14. Your current security scenario gives you the option to choose between a stand-alone installation or a distributed installation. Which of the following factors would cause you to decide in favour of the distributed installation? Select the best response. A. You are required to use Clientless VPN. B. You are required to use Windows as operating system. C. You are required to use as few hardware resources as possible. D. You are required to install HFA's on the Security Gateway via SmartUpdate. Answer: D 15. Your current security scenario gives you the option to choose between a stand-alone installation or a distributed installation. Which of the following factors would cause you to decide in favour of the stand-alone installation? Select the best response. A. You are required to use as few hardware resources as possible. B. You are required to use Clientless VPN. C. You are required to use Windows as operating system. D. You are required to install HFA's on the Security Gateway via SmartUpdate. Answer: A    

www.Prepking.com 

 


16. Your current security scenario gives you the option to choose between a stand-alone installation or a distributed installation. Which of the following statements is TRUE for distributed installation? Select the best response. A. You have the option to install a secondary SmartCenter Server. B. You are forced to use Windows as operating system. C. You cannot install HFA's on the Security Gateway via SmartUpdate. D. Clientless VPN would not work in a distributed installation. Answer: A 17. Your current security scenario gives you the option to choose between a stand-alone installation or a distributed installation. Which of the following statements is TRUE for a stand-alone installation? Select the best response. A. You have the option to install a secondary SmartCenter Server. B. Clientless VPN would not work in a distributed installation. C. You cannot install HFA's on the Security Gateway via SmartUpdate. D. You are forced to use Windows as operating system. Answer: C 18. How can you reset the password of the Security Administrator, which was created during initial installation of the SmartCenter Server on SecurePlatform? Select the best response. A. Export the user database into an ASCII file with fwm dbexport. Open this file with an editor, and delete the "Password" portion of the file. Then log in to the account without password. You will be prompted to assign a new password. B. Type cpm a, and provide the existing administration account name. Reset the Security Administrator's password. C. Launch cpconfig and delete the Administrator's account. Recreate the account with the same name. D. Launch SmartDashboard, click the admin user account, and overwrite the existing Check Point Password. Answer: C 19. How can you reset the password of the Security Administrator, which was created during initial installation of the SmartCenter Server on SecurePlatform? Select the best response. A. Type fwm a, and provide the existing administration account name. Reset the Security Administrator's password. B. Launch SmartDashboard, click the admin user account, and overwrite the existing Check Point Password.    

www.Prepking.com 

 


C. Export the user database into an ASCII file with fwm dbexport. Open this file with an editor, and delete the "Password" portion of the file. Then log in to the account without password. You will be prompted to assign a new password. D. Launch cpunload and delete the Administrator's account. Recreate the account with the same name. Answer: A 20. You are installing a SmartCenter server. Your security plan calls for three administrators for this particular server. How many can you create during installation? Select the best response. A. As many as you want B. Only one with full access and one with read-only access C. Depends on the license installed on the SmartCenter Server D. Only one Answer: D 21. The Check Point Security Gateway's virtual machine (kernel) exists between which two layers of the OSI model? Select the best response. A. Application and Presentation layers B. Network and DataLink layers C. Physical and DataLink layers D. Session and Network layers Answer: B 22. In a "Stand Alone Installation" the functionality of the SmartCenter Server would be installed together with which other Check Point architecture component? Select the best response. A. SmartCenter Server would be installed by itself. B. Security Gateway C. SmartConsole D. SecureClient Answer: B 23. Which specific VPN-1 NGX GUI would you use to add an address translation rule? Select the best response. A. SmartNAT B. SmartConsole C. SmartView Monitor D. SmartDashboard    

www.Prepking.com 

 


Answer: D 24. One of your remote Security Gateways suddenly stops sending logs, and you cannot install the Security Policy on the Gateway. All other remote Security Gateways are logging normally to the SmartCenter Server, and Policy installation is not affected. When you attempt to install policy you receive error message "TCP connectivity failure on port 18191". What is the problem? Select the best response. A. The time on the SmartCenter Server's clock has changed, which invalidates the remote Gateway's Certificate. B. There is no connection between the SmartDashboard and the remote Gateway. Rules or routing may lock the connection. C. There is no connection between the SmartCenter Server and the remote Gateway. Rules or routing may lock the connection. D. The Internal Certificate Authority for the SmartCenter object has been removed from objects_5_0.C. Answer: C 25. VPN-1 NGX uses ___________ to retrieve the Interface Name, IP Address, and Network Mask when an administrator clicks the GET button in the Interfaces tab of an Externally Managed VPN Gateway object. Select the best response. A. ioctl B. Control Connection C. SNMP D. URI Answer: C 26. What command displays the version of an already installed firewall module? Select the best response. A. fw ver B. fw printver C. fw printlic D. fw lic Answer: A 27. The customer has a small Check Point installation which includes one Windows 2003 server working as SmartConsole and SmartCenter with a second server running SPLAT working as Security Gateway.

This

is an example of a: Select the best response. A. StandAlone Installation B. Unsupported configuration    

www.Prepking.com 

 


100% Pass Guaranteed or Full Refund Word to Word Real Exam Questions from Real Test Buy full version of exam from this link below http://www.prepking.com/156-215.htm


Pass4sure 156-215 dumps