Checkpoint 156-215.81 Exam
Check Point Certified Security Administrator R81 (Page 7 )

Updated On: 9-Feb-2026

In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?

  1. SND is a feature to accelerate multiple SSL VPN connections
  2. SND is an alternative to IPSec Main Mode, using only 3 packets
  3. SND is used to distribute packets among Firewall instances
  4. SND is a feature of fw monitor to capture accelerated packets

Answer(s): C

Explanation:

The Secure Network Distributor (SND) is a feature of the Security Gateway that is used to distribute packets among Firewall instances . It improves the performance and scalability of the Firewall by utilizing multiple CPU cores. The other options are not related to SND.


Reference:

[Check Point Security Gateway Architecture and Packet Flow], [Free Check Point CCSA Sample Questions and Study Guide]



Sticky Decision Function (SDF) is required to prevent which of the following? Assume you set up an Active-Active cluster.

  1. Symmetric routing
  2. Failovers
  3. Asymmetric routing
  4. Anti-Spoofing

Answer(s): B

Explanation:

The Sticky Decision Function (SDF) is required to prevent failovers in an Active-Active cluster. The SDF ensures that the same cluster member handles all connections that belong to a certain session. If the SDF is not enabled, different cluster members may handle different connections of the same session, which may cause a failover or a drop12.


Reference:

ClusterXL Administration Guide R81, Check Point CCSA - R81: Practice Test & Explanation



What are the steps to configure the HTTPS Inspection Policy?

  1. Go to Manage&Settings > Blades > HTTPS Inspection > Configure in SmartDashboard
  2. Go to Application&url filtering blade > Advanced > Https Inspection > Policy
  3. Go to Manage&Settings > Blades > HTTPS Inspection > Policy
  4. Go to Application&url filtering blade > Https Inspection > Policy

Answer(s): C

Explanation:

The steps to configure the HTTPS Inspection Policy are as follows34:

Go to Manage & Settings > Blades > HTTPS Inspection > Policy. Click on New HTTPS Inspection Rule or select an existing rule and click on Edit Rule. Define the Source, Destination, and Action for the rule. The action can be either Inspect, Bypass, or Ask.
Click on OK and then on Install Policy to apply the changes.


Reference:

HTTPS Inspection R81 Administration Guide, Check Point CCSA - R81: Practice Test & Explanation



What is the difference between SSL VPN and IPSec VPN?

  1. IPSec VPN does not require installation of a resident VPN client
  2. SSL VPN requires installation of a resident VPN client
  3. SSL VPN and IPSec VPN are the same
  4. IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed Browser

Answer(s): D

Explanation:

The difference between SSL VPN and IPSec VPN is that IPSec VPN requires installation of a resident VPN client and SSL VPN requires only an installed browser5 . IPSec VPN uses a pre-shared key or certificates to authenticate the endpoints and encrypts the data at the network layer. SSL VPN uses SSL/TLS protocols to authenticate the endpoints and encrypts the data at the application layer.


Reference:

Check Point Remote Access VPN Administration Guide R81, [Free Check Point CCSA Sample Questions and Study Guide]



Which statement is NOT TRUE about Delta synchronization?

  1. Using UDP Multicast or Broadcast on port 8161
  2. Using UDP Multicast or Broadcast on port 8116
  3. Quicker than Full sync
  4. Transfers changes in the Kernel tables between cluster members

Answer(s): A

Explanation:

The statement that is not true about Delta synchronization is that it uses UDP Multicast or Broadcast on port 8161. The correct port number for Delta synchronization is 811612. The other statements are true about Delta synchronization.


Reference:

ClusterXL Administration Guide R81, Check Point CCSA - R81: Practice Test & Explanation






Post your Comments and Discuss Checkpoint 156-215.81 exam prep with other Community members:

Join the 156-215.81 Discussion