New Check Point 156-915.80 Exam Dumps Collection (Question 5 - Question 14)

New Questions 5

Which process should you debug if SmartDashboard login fails?

A. sdm

B. cpd

C. fwd

D. fwm

Answer: D

New Questions 6

Type the full cphaprob command and syntax that will show full synchronization status.


cphaprob -i list

New Questions 7

You just installed a new Web server in the DMZ that must be reachable from the Internet. You create a manual Static NAT rule as follows:

Source: Any || Destination: web_public_IP || Service: Any || Translated Source: original || Translated Destination: web_private_IP || Service: Original

u201cweb_public_IPu201d is the node object that represents the new Web serveru2019s public IP address. u201cweb_private_IPu201d is the node object that represents the new Web siteu2019s private IP address. You enable all settings from Global Properties > NAT.

When you try to browse the Web server from the Internet you see the error u201cpage cannot be displayedu201d. Which of the following is NOT a possible reason?

A. There is no Security Policy defined that allows HTTP traffic to the protected Web server.

B. There is no ARP table entry for the protected Web serveru2019s public IP address.

C. There is no route defined on the Security Gateway for the public IP address to the Web serveru2019s private IP address.

D. There is no NAT rule translating the source IP address of packets coming from the protected Web server.

Answer: D

New Questions 8

Assume you are a Security Administrator for ABCTech. You have allowed authenticated access to users from Mkting_net to Finance_net. But in the useru2019s properties, connections are only permitted within Mkting_net. What is the BEST way to resolve this conflict?

A. Select Ignore Database in the Action Properties window.

B. Permit access to Finance_net.

C. Select Intersect with user database in the Action Properties window.

D. Select Intersect with user database or Ignore Database in the Action Properties window.

Answer: D

New Questions 9

Fill in the blank. The user wants to replace a failed Windows-based firewall with a new server running GAiA.

For the most complete restore of an GAiA configuration, he or she will use the command



New Questions 10

An internal host initiates a session to the Google.com website and is set for Hide NAT behind the Security Gateway. The initiating traffic is an example of .

A. client side NAT

B. source NAT

C. destination NAT

D. None of these

Answer: B

New Questions 11

The technical-support department has a requirement to access an intranet server. When configuring a User Authentication rule to achieve this, which of the following should you remember?

A. You can only use the rule for Telnet, FTP, SMTP, and rlogin services.

B. The Security Gateway first checks if there is any rule that does not require authentication for this type of connection before invoking the Authentication Security Server.

C. Once a user is first authenticated, the user will not be prompted for authentication again until logging


D. You can limit the authentication attempts in the User Propertiesu2019 Authentication tab.

Answer: B

New Questions 12

Your main internal network allows all traffic to the Internet using Hide NAT. You also have a small network behind the internal router. You want to configure the kernel to translate the source address only when network tries to access the Internet for HTTP, SMTP, and FTP services. Which of the following configurations will allow this network to access the Internet?

A. Configure three Manual Static NAT rules for network, one for each service.

B. Configure Automatic Static NAT on network

C. Configure one Manual Hide NAT rule for HTTP, FTP, and SMTP services for network

D. Configure Automatic Hide NAT on network and then edit the Service column in the NAT Rule Base on the automatic rule.

Answer: C

New Questions 13

Which three of the following are ClusterXL member requirements?

1) same operating systems

2) same Check Point version

3) same appliance model

4) same policy

A. 1, 3, and 4

B. 1, 2, and 4

C. 2, 3, and 4

D. 1, 2, and 3

Answer: B

New Questions 14

Before upgrading SecurePlatform to GAiA, you should create a backup. To save time, many administrators use the command backup. This creates a backup of the Check Point configuration as well as the system configuration.

An administrator has installed the latest HFA on the system for fixing traffic problem after creating a backup file. There is a mistake in the very complex static routing configuration. The Check Point configuration has not been changed. Can the administrator use a restore to fix the errors in static routing?

A. The restore is not possible because the backup file does not have the same build number (version).

B. The restore is done by selecting Snapshot Management from the boot menu of GAiA.

C. The restore can be done easily by the command restore and copying netconf.C from the production environment.

D. A backup cannot be restored, because the binary files are missing.

Answer: C

