Free 156-215.81 Exam Braindumps (page: 28)

Page 28 of 102

Your internal networks 10.1.1.0/24, 10.2.2.0/24 and 192.168.0.0/16 are behind the Internet Security Gateway. Considering that Layer 2 and Layer 3 setup is correct, what are the steps you will need to do in SmartConsole in order to get the connection working?

  1. 1. Define an accept rule in Security Policy.2. Define Security Gateway to hide all internal networks behind the gateway's external IP.3. Publish and install the policy.
  2. 1. Define an accept rule in Security Policy.2. Define automatic NAT for each network to NAT the networks behind a public IP.3. Publish the policy.
  3. 1. Define an accept rule in Security Policy.2. Define automatic NAT for each network to NAT the networks behind a public IP.3. Publish and install the policy.
  4. 1. Define an accept rule in Security Policy.2. Define Security Gateway to hide all internal networks behind the gateway's external IP.3. Publish the policy.

Answer(s): C

Explanation:

The steps you will need to do in SmartConsole in order to get the connection working behind the Internet Security Gateway are:
Define an accept rule in Security Policy. This rule allows the traffic from your internal networks to pass through the Security Gateway.
Define automatic NAT for each network to NAT the networks behind a public IP. This option translates the private IP addresses of your internal networks to a public IP address assigned by your ISP router. This way, your internal networks can communicate with the Internet using a valid IP address. Publish and install the policy. This step applies the changes you made to the Security Gateway and activates the security and NAT rules.


Reference:

Check Point R81 Quantum Security Gateway Guide



True or False: The destination server for Security Gateway logs depends on a Security Management

Server configuration.

  1. False, log servers are configured on the Log Server General Properties
  2. True, all Security Gateways will only forward logs with a SmartCenter Server configuration
  3. True, all Security Gateways forward logs automatically to the Security Management Server
  4. False, log servers are enabled on the Security Gateway General Properties

Answer(s): B

Explanation:

The destination server for Security Gateway logs depends on a Security Management Server configuration. This is true because the Security Management Server defines the log servers that receive logs from the Security Gateways. The log servers can be either the Security Management Server itself or a dedicated Log Server12.


Reference:

Check Point R81 Logging and Monitoring Administration Guide, Check Point R81 Quantum Security Gateway Guide



Consider the Global Properties following settings:

The selected option "Accept Domain Name over UDP (Queries)" means:

  1. UDP Queries will be accepted by the traffic allowed only through interfaces with external anti- spoofing topology and this will be done before first explicit rule written by Administrator in a Security Policy.
  2. All UDP Queries will be accepted by the traffic allowed through all interfaces and this will be done before first explicit rule written by Administrator in a Security Policy.
  3. No UDP Queries will be accepted by the traffic allowed through all interfaces and this will be done before first explicit rule written by Administrator in a Security Policy.
  4. All UDP Queries will be accepted by the traffic allowed by first explicit rule written by Administrator in a Security Policy.

Answer(s): A

Explanation:

The selected option "Accept Domain Name over UDP (Queries)" means that UDP Queries will be accepted by the traffic allowed only through interfaces with external anti-spoofing topology and this will be done before first explicit rule written by Administrator in a Security Policy. This option enables the Security Gateway to accept DNS queries from external hosts and forward them to internal DNS servers. The queries are accepted by an implied rule that is applied before the explicit rules in the Security Policy. The implied rule only allows queries from interfaces that have external anti-spoofing groups defined .


Reference:

Check Point R81 Quantum Security Gateway Guide, Implied Rules



How is communication between different Check Point components secured in R80? As with all questions, select the best answer.

  1. By using IPSEC
  2. By using SIC
  3. By using ICA
  4. By using 3DES

Answer(s): B

Explanation:

The communication between different Check Point components is secured in R80 by using SIC. SIC stands for Secure Internal Communication and it is a mechanism that ensures the authenticity and confidentiality of communication between Check Point components, such as Security Gateways, Security Management Servers, Log Servers, etc. SIC uses certificates issued by the Internal CA (ICA) and encryption algorithms such as AES-25634.


Reference:

Check Point R81 Quantum Security

Gateway Guide, Check Point R81 Quantum Security Management Administration Guide



Page 28 of 102



Post your Comments and Discuss Checkpoint 156-215.81 exam with other Community members:

Pooja commented on September 08, 2024
Nice info ok I will do the same
Anonymous
upvote

IPR commented on October 05, 2023
q:124 is wrong - the correct answer is b but the syntax is: ip-address
Anonymous
upvote

IPR commented on October 05, 2023
Q:124 is wrong - the correct answer is B but the syntax is: ip-address
Anonymous
upvote