ProProfs Quiz Maker

Checkpoint CCSA R70.1

35 Questions  I  28 Attempts  I  Created By mastermind1100 509 days ago
Check Point CCSA Quiz
Name

  


Question Excerpt From Checkpoint CCSA R70.1
Q.1)  If you check the box "Use Agressive Mode" in the IKE Properties dialog box, the standard:
A.
B.
C.
D.
Q.2)  Of the following, what parameters will not be preserved when using Database Revision Control
A.
B.
C.
D.
E.
F.
G.
H.
I.
J.
K.
L.
M.
Q.3)  You believe Phase 2 negotiations are railing while you are attempting to configure a site-to-site VPN with one of your firm's business pastners.  Which SmartConsol application should you use to confirm your suspicions?
A.
B.
C.
D.
Q.4)  You are running a R71 Security Gatewayon  SecurePlatform, in case of a harware failure.  You have a server with the exact same hardware installed.  What backup method should you use to quickly put the secondary firewall into production.
A.
B.
C.
D.
Q.5)  What happens hi relation to the CRL cache after a cpstop and spstart have been Initiated
A.
B.
C.
D.
Q.6)  What physical machine must have access to the User center public IP address when checking for new packages with smartUpdate
A.
B.
C.
D.
Q.7)  In SmartView tracker, which rule shows when a packet is dropped due to anti-spoofing?
A.
B.
C.
D.
Q.8)  The URL Filtering Policy can be configured to monitor URLs in order to:
A.
B.
C.
D.
Q.9)  The Customer has a small Check Point installation which includes one Windows XP workstation as SmartConsole, one Solaris server working as security Management Server, and a third server running SecurePlatform as Security Gateway. This is an Example of a (n):Stand-Alone Installation.
A.
B.
C.
D.
Q.10)  You want to implement Static Destination NAT in order to provide external. Internet users access to an internal Webserver that has a reserved (RFC 1918) IP address You have an unused valid IP address on the network between your Security Gateway and ISP router. You control the router that sits between the external interface of the firewall and the Internet. What is an alternative configuration if proxy ARP cannot be used on your Security Gateway?
A.
B.
C.
D.
Q.11)  The third-shift Administrator was updating Security Management Server access settings in global properties. He managed to lock all of the administrators out of their accounts. How should you unlock these accounts? 
A.
B.
C.
D.
Q.12)  You find a suspicious connection from a problematic host. You decide that you want to block everything from the whole network, not just the problematic host. You want to block this for an hour while you investigate further, but you do not want to add any rules to the rule base. How do you achieve this?
A.
B.
C.
D.
Q.13)  The Check Point Security Gateway's virtual machine (kernel) exists between which two layers of the OSI model? 
A.
B.
C.
D.
Q.14) 
 
Phase 1 uses________. 
A.
B.
C.
D.
Q.15) 
 
An advantage of using central instead of local licensing is: 
A.
B.
C.
D.
Q.16)  Which of the following uses the same key to decrypt as it does to encrypt?
A.
B.
C.
D.
Q.17)  When configuring the network interfaces of a checkpoint Gateway, the direction can be defined as Internal or external. What is meaning of interface leading to DMZ?
A.
B.
C.
D.
Q.18)  Which service is it NOT possible to configure user authentication?
A.
B.
C.
D.
Q.19)  You have created a rule Base Firewall, websydney. Now you are going to create a new policy package with security and address transaction rules for a secured gateway. What is true about the new package’s NAT rules?
A.
B.
C.
D.
Q.20)  You run cpconfig to reset SIC on the Security Gateway. After the SIC reset operation is complete, the policy that will be installed is the
A.
B.
C.
D.
Q.21)  What can NOT be selected for VPN tunnel sharing?
A.
B.
C.
D.
Q.22) 

Which answers are TRUE? Automatic Static NAT CANNOT be used when:

i) NAT decision is based on the destination port ii) Source and Destination IP both have to be translated iii) The NAT rule should only be installed on a dedicated Gateway only iv) NAT should be performed on the server side

A.
B.
C.
D.
Q.23)  Security Gateway R71 supports User Authentication for which of the following services? Select the response below that contains the most complete list of supported services.
A.
B.
C.
D.
Q.24)  Which of these security policy changes optimize Security Gateway performance?
A.
B.
C.
D.
Q.25)  A Web server behind the Security Gateway is set to Automatic Static NAT Client side NAT is not checked in the Global Properties. A client on the Internet initiates a session to the Web Server. Assuming there is a rule allowing this traffic, what other configuration must be done to allow the traffic to reach the Web server?
A.
B.
C.
D.
Q.26)  Latency has lost SIC communication with her Security Gateway and she needs to re establish SIC. What would be the correct order of steps needed to perform this task? 1) Create a new activation key on the Security Gateway, then exit cpconfig. 2) Click the Communication tab on the Security Gateway object, and then click Reset. 3) Run the cpconfig tool, and then select Secure Internal Communication to reset. 4) Input the new activation key in the Security Gateway object, and then click initialize 5) Run the cpconfig tool, then select source Internal Communication to reset.
A.
B.
C.
D.
Q.27)  Which type of resource could a Security Administrator use to control access to specific share on target machines?URI
A.
B.
C.
D.
Q.28)  Which port must be allowed to pass through enforcement points in order to allow packet logging to operate correctly?
A.
B.
C.
D.
Q.29)  While in Smart View Tracker, Brady has noticed some very odd network traffic that he thinks could be an intrusion. He decides to block the traffic for 60 but cannot remember all the steps. What is the correct order of steps needed to perform this? 1) Select the Active Mode tab In Smart view Tracker 2) Select Tools > Block Intruder 3) Select the Log Viewing tab in SmartView Tracker 4) Set the Blocking Time out value to 60 minutes 5) Highlight the connection he wishes to block
A.
B.
C.
D.
Q.30)  A rule _______ is designed to log and drop all other communication that does not match another rule?
A.
B.
C.
D.
Q.31)  Which the following statement is TRUE about management plug-ins?
A.
B.
C.
D.
Q.32)  For normal packet transaction of an accepted communication to a host protocol by a Security Gate Way how many lines per packet are recorded on a packet analyzer like wire Shark using fw monitor?
A.
B.
C.
D.
Q.33)  Your R71 enterprise Security Management Server is running abnormally on Windows 2003 Server. You decide to try reinstalling the Security Management Server, but you want to try keeping the critical Security Management Server configuration settings impact (i.e , all security policies database, SIC, licensing etc). What is the BEST method to reinstall the Server and keep its critical configuration?
A.
B.
C.
D.
Q.34)  Which of the following are authentication methods that Security Gateway R7Tuses to validate connection attempts? Select the response below that includes the MOST complete list of valid authentication methods.
A.
B.
C.
D.
Q.35)  Which Security Servers can perform authentication tasks, but CANNOT perform content security tasks?
A.
B.
C.
D.

Take this quiz by clicking Start button on top.



Please login to post comments.
After login, we will forward you back to this quiz.

Upgrade and get a lot more done!
Upgrade

 Adding Media is not included in your current plan

Upgrade and get a lot more:
  • Upload documents


  • Upload Videos


  • Upload Powerpoints


  • Add training/teaching material



Upgrade