Free 156-215.81 Exam Braindumps (page: 31)

Page 31 of 102

What is the purpose of a Clean-up Rule?

  1. Clean-up Rules do not server any purpose.
  2. Provide a metric for determining unnecessary rules.
  3. To drop any traffic that is not explicitly allowed.
  4. Used to better optimize a policy.

Answer(s): C

Explanation:

A clean-up rule is a rule that is placed at the end of the security policy to drop any traffic that is not explicitly allowed by the previous rules. It is a best practice to have a clean-up rule to prevent unauthorized access and log the dropped packets for analysis12. The other options are not the purpose of a clean-up rule.


Reference:

Clean-up Rule, Check Point CCSA - R81: Practice Test & Explanation



What are the two types of NAT supported by the Security Gateway?

  1. Destination and Hide
  2. Hide and Static
  3. Static and Source
  4. Source and Destination

Answer(s): B

Explanation:

The two types of NAT supported by the Security Gateway are hide NAT and static NAT. Hide NAT translates many source IP addresses into one IP address, usually the external interface of the gateway. Static NAT translates one source IP address into another IP address, usually a public IP address34. The other options are not valid types of NAT.


Reference:

Network Address Translation (NAT), Check Point CCSA - R81: Practice Test & Explanation



Vanessa is attempting to log into the Gaia Web Portal. She is able to login successfully. Then she tries the same username and password for SmartConsole but gets the message in the screenshot image below. She has checked that the IP address of the Server is correct and the username and password she used to login into Gaia is also correct.



What is the most likely reason?

  1. Check Point R80 SmartConsole authentication is more secure than in previous versions and
    Vanessa requires a special authentication key for R80 SmartConsole. Check that the correct key details are used.
  2. Check Point Management software authentication details are not automatically the same as the Operating System authentication details. Check that she is using the correct details.
  3. SmartConsole Authentication is not allowed for Vanessa until a Super administrator has logged in first and cleared any other administrator sessions.
  4. Authentication failed because Vanessa's username is not allowed in the new Threat Prevention console update checks even though these checks passed with Gaia.

Answer(s): B

Explanation:

The most likely reason for Vanessa's authentication failure is that she is using the wrong details for SmartConsole. Check Point Management software authentication details are not automatically the same as the Operating System authentication details. She needs to use the credentials that were defined during the initial configuration of the Security Management Server, or the ones that were assigned to her by the administrator12. The other options are not valid reasons for this error.


Reference:

SmartConsole Login, Check Point CCSA - R81: Practice Test & Explanation



What is the most complete definition of the difference between the Install Policy button on the SmartConsole's tab, and the Install Policy within a specific policy?

  1. The Global one also saves and published the session before installation.
  2. The Global one can install multiple selected policies at the same time.
  3. The local one does not install the Anti-Malware policy along with the Network policy.
  4. The second one pre-select the installation for only the current policy and for the applicable gateways.

Answer(s): D

Explanation:

The difference between the Install Policy button on the SmartConsole's tab and the Install Policy within a specific policy is that the former installs all the policies that are selected in the Install Policy window, while the latter pre-selects the installation for only the current policy and for the applicable gateways5 . The other options are not accurate differences.


Reference:

Installing Policies, [Check Point CCSA - R81: Practice Test & Explanation]



Page 31 of 102



Post your Comments and Discuss Checkpoint 156-215.81 exam with other Community members:

Pooja commented on September 08, 2024
Nice info ok I will do the same
Anonymous
upvote

IPR commented on October 05, 2023
q:124 is wrong - the correct answer is b but the syntax is: ip-address
Anonymous
upvote

IPR commented on October 05, 2023
Q:124 is wrong - the correct answer is B but the syntax is: ip-address
Anonymous
upvote