Free 156-215.81 Exam Braindumps (page: 33)

Page 33 of 102

Which Identity Source(s) should be selected in Identity Awareness for when there is a requirement for a higher level of security for sensitive servers?

  1. AD Query
  2. Terminal Servers Endpoint Identity Agent
  3. Endpoint Identity Agent and Browser-Based Authentication
  4. RADIUS and Account Logon

Answer(s): C

Explanation:

Endpoint Identity Agent and Browser-Based Authentication are the identity sources that provide the highest level of security for sensitive servers, as they require user authentication and can enforce granular access rules based on user identity. AD Query, Terminal Servers Endpoint Identity Agent, and RADIUS and Account Logon are less secure, as they rely on passive methods of identity acquisition or do not support identity-based access control12.


Reference:

Identity Awareness R81.10 Administration Guide, Identity Awareness AD Query



Which statement describes what Identity Sharing is in Identity Awareness?

  1. Management servers can acquire and share identities with Security Gateways
  2. Users can share identities with other users
  3. Security Gateways can acquire and share identities with other Security Gateways
  4. Administrators can share identifies with other administrators

Answer(s): C

Explanation:

Identity Sharing is a feature that allows Security Gateways to acquire and share identities with other Security Gateways, enabling identity-based access control across different network segments or domains13. Management servers, users, and administrators do not share identities with Security Gateways.


Reference:

Identity Awareness R81.10 Administration Guide, Check Point R81.10



What is the most recommended installation method for Check Point appliances?

  1. SmartUpdate installation
  2. DVD media created with Check Point ISOMorphic
  3. USB media created with Check Point ISOMorphic
  4. Cloud based installation

Answer(s): C

Explanation:

USB media created with Check Point ISOMorphic is the most recommended installation method for

Check Point appliances, as it provides a fast and easy way to install the Gaia operating system and the latest software version4. SmartUpdate installation requires an existing Gaia installation and does not support fresh installations4. DVD media created with Check Point ISOMorphic is less convenient than USB media, as it requires burning the image to a DVD and inserting it into the appliance4. Cloud based installation is not applicable for Check Point appliances, as it is intended for cloud environments such as AWS or Azure4.


Reference:

INSTALLATION AND UPGRADE GUIDE R81.10, Chassis R81 Installation and Upgrade Guide, Check Point R81.10



Which of the following is NOT a role of the SmartCenter:

  1. Status monitoring
  2. Policy configuration
  3. Certificate authority
  4. Address translation

Answer(s): D

Explanation:

Address translation is not a role of the SmartCenter, as it is performed by the Security Gateway based on the NAT policy configured in the SmartConsole5. The other options are roles of the SmartCenter, as it is responsible for status monitoring, policy configuration, and certificate authority for the Security Gateways5.


Reference:

Gaia R81.10 Administration Guide, QUANTUM SECURITY MANAGEMENT R81, Remote Access VPN R81 Administration Guide



Page 33 of 102



Post your Comments and Discuss Checkpoint 156-215.81 exam with other Community members:

Pooja commented on September 08, 2024
Nice info ok I will do the same
Anonymous
upvote

IPR commented on October 05, 2023
q:124 is wrong - the correct answer is b but the syntax is: ip-address
Anonymous
upvote

IPR commented on October 05, 2023
Q:124 is wrong - the correct answer is B but the syntax is: ip-address
Anonymous
upvote