Free 156-215.81 Exam Braindumps (page: 35)

Page 35 of 102

Which of the following blades is NOT subscription-based and therefore does not have to be renewed on a regular basis?

  1. Application Control
  2. Threat Emulation
  3. Anti-Virus
  4. Advanced Networking Blade

Answer(s): D

Explanation:

The Advanced Networking Blade is NOT subscription-based and therefore does not have to be renewed on a regular basis1011. The Advanced Networking Blade provides advanced routing capabilities such as BGP, OSPF, VRRP, and multicast routing10. The other blades are subscription- based and require annual renewal to receive updates and support from Check Point1012.


Reference:

Check Point License Guide, IPS Software Blade contracts, Product Catalog



Fill in the blank: Back up and restores can be accomplished through_________.

  1. SmartConsole, WebUI, or CLI
  2. WebUI, CLI, or SmartUpdate
  3. CLI, SmartUpdate, or SmartBackup
  4. SmartUpdate, SmartBackup, or SmartConsole

Answer(s): A

Explanation:

Back up and restores can be accomplished through SmartConsole, WebUI, or CLI12. These are the methods to perform system backup and restore, which save and restore the Gaia OS configuration and the Security Management Server database1. WebUI, CLI, or SmartUpdate are not valid methods, as SmartUpdate is used to install software packages and patches, not to back up or restore the system3. CLI, SmartUpdate, or SmartBackup are not valid methods, as SmartBackup is a feature of SmartProvisioning that allows backing up and restoring the configuration of Security Gateways and VSX clusters4. SmartUpdate, SmartBackup, or SmartConsole are not valid methods, as SmartConsole is used to configure and manage the Security Policy, not to back up or restore the system5.


Reference:

System Backup and Restore feature in Gaia, Check Point R81.10, INSTALLATION AND UPGRADE GUIDE R81.10, SmartProvisioning R81.10 Administration Guide, QUANTUM SECURITY MANAGEMENT R81



What does it mean if Deyra sees the gateway status:



Choose the BEST answer.

  1. SmartCenter Server cannot reach this Security Gateway
  2. There is a blade reporting a problem
  3. VPN software blade is reporting a malfunction
  4. Security Gateway's MGNT NIC card is disconnected.

Answer(s): B

Explanation:

If Deyra sees the gateway status as shown in the image, it means that there is a blade reporting a problem. The red "X" in the status column indicates that one or more blades on the Security Gateway have a problem that requires attention. The other options are not correct, as they do not match the status shown in the image. If the SmartCenter Server cannot reach this Security Gateway, the status column would show a yellow triangle with an exclamation mark. If the VPN software blade is reporting a malfunction, the blades column would show a red "X" on the VPN icon. If the Security Gateway's MGNT NIC card is disconnected, the IP column would show "N/A" instead of the IP address.


Reference:

Remote Access VPN R81 Administration Guide, Check Point R81.10



CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You suspect that the problem might be the Threat Prevention settings.

The following Threat Prevention Profile has been created.



How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.

  1. Set High Confidence to Low and Low Confidence to Inactive.
  2. Set the Performance Impact to Medium or lower.
  3. The problem is not with the Threat Prevention Profile. Consider adding more memory to the appliance.
  4. Set the Performance Impact to Very Low Confidence to Prevent.

Answer(s): B

Explanation:

The BEST way to tune the profile in order to lower the CPU load still maintaining security at good level is to set the Performance Impact to Medium or lower. This will reduce the number of packets that are inspected by the Threat Prevention blades, while still providing a high level of protection . Setting High Confidence to Low and Low Confidence to Inactive will lower the security level, as it will allow more traffic that may be malicious. The problem is likely with the Threat Prevention Profile, as it can have a significant impact on the CPU utilization of the Security Gateway. Adding more memory to the appliance will not solve the problem, as memory is not the bottleneck in this case. Setting the Performance Impact to Very Low Confidence to Prevent will increase the CPU load, as it will inspect more packets and block more traffic that may be false positives.


Reference:

Threat Prevention Administration Guide, Check Point R81.10



Page 35 of 102



Post your Comments and Discuss Checkpoint 156-215.81 exam with other Community members:

Pooja commented on September 08, 2024
Nice info ok I will do the same
Anonymous
upvote

IPR commented on October 05, 2023
q:124 is wrong - the correct answer is b but the syntax is: ip-address
Anonymous
upvote

IPR commented on October 05, 2023
Q:124 is wrong - the correct answer is B but the syntax is: ip-address
Anonymous
upvote