Q71. John is the MegaCorp Security Administrator, and is using Check Point R70. Malcolm is the Security Administrator of a partner company and is using a different vendor's product and both have to build a VPN tunnel between their companies. Both are using clusters with Load Sharingfor their firewalls and John is using ClusterXL as a Check Point clustering solution. While trying to establish the VPN, they are constantly noticing problems and the tunnel is not stable and then Malcolm notices that there seems to be 2 SPIs with the same IP from the Check Point site. How can they solve this problem and stabilize the tunnel?

A. This can easily be solved by using the Sticky decision function in ClusterXL.

B. This can be solved by running the command "Sticky VPN" on the Check Point CLI. This keeps the VPN Sticky to one member and the problem is resolved.

C. This can be solved when using clusters; they have to use single firewalls.

D. This is surely a problem in the ISPs network and not related to the VPN configuration.

Answer: A

Q72. What information is found in the SmartView Tracker audit log?

A. SIC revoke certificate event

B. Number of concurrent IKE negotiations

C. Destination IP address

D. Most accessed Rule Base rule

Answer: A

Q73. In SmartDashboard, you configure 45 MB as the required free hard-disk space to accommodate logs. What can you do to keep old log files, when free space falls below 45 MB?

A. Do nothing. Old logs are deleted, until free space is restored.

B. Do nothing. The SmartCenter Server automatically copies old logs to a backup server before purging.

C. Use the fwm logexport command to export the old log files to other location.

D. Configure a script to run fw logswitch and SCP the output file to a separate file server.

Answer: D

Q74. URL Filtering Policy can make exceptions for specific sites by being enforced...

A. for all traffic, except blocked sites

B. for all traffic, There are no exceptions

C. for all traffic, except on specific sources and destinations,

D. only for specific sources and destinations.

Answer: C

Q75. Which SmartEvent, what is the Correlation Unit's function?

A. Invoke and define automatic reactions and add events to the database

B. Assign seventy levels to events

C. Display received threats and tune the Events Policy

D. Analyze log entries, looking for Event Policy patterns

Answer: D

Q76. Match the remote-access VPN Connection mode features with their descriptions:

A. A 3,B 4,C 2,D 1

B. A 2,B 3,C 4,D 1

C. A 2,B 4,C 3,D 1

D. A 1. B 3,C 4,D 2

Answer: B

Q77. Which of the following commands will stop acceleration on a Security Gateway running on Secure Platform?

A. splat_accel off

B. fwacceX off

C. perf_pack off

D. fwaceel off

Answer: D

Q78. You have two NOKIA Appliances: one IP530 and one IP380. Both appliances have IPSO 3.9 and NGX R65 VPN-1 Power installed in a distributed deployment. Can they be members of a Gateway Cluster?

A. No, because the appliances must be of the same model (both should be IP530 or IP380)

B. NO, because NOKIA does not have a cluster option.

C. Yes, as long as they have the same IPSO and VPN-1 versions.

D. NO, because the Security Gateways must be installed in a stand-alone installation.

Answer: C

Q79. The command fw fetch causes the:

A. SmartCenter Server to retrieve the debug logs of the target Security Gateway

B. Security Gateway to retrieve the user database information from the tables on the SmartCenter Server.

C. SmartCenter Server to retrieve the IP addresses of the target Security Gateway

D. Security Gateway to retrieve the compiled policy and inspect code from the SmartCenter Server and install it to the kernel

Answer: D

Q80. What access level cannot be assigned to an administrator insmart event?

A. Event database

B. Write only

C. No access

D. Read only

Answer: B

