Free 156-315.81 Exam Braindumps (page: 23)

Page 23 of 158

What is the limitation of employing Sticky Decision Function?

  1. With SDF enabled, the involved VPN Gateways only supports IKEv1
  2. Acceleration technologies, such as SecureXL and CoreXL are disabled when activating SDF
  3. With SDF enabled, only ClusterXL in legacy mode is supported
  4. With SDF enabled, you can only have three Sync interfaces at most

Answer(s): B

Explanation:

Sticky Decision Function (SDF) is a feature that ensures that VPN traffic is handled by the same core on a Security Gateway with multiple CPU cores. This improves the performance and stability of VPN tunnels by avoiding out-of-order packets and reducing encryption overhead. However, the limitation of employing SDF is that acceleration technologies, such as SecureXL and CoreXL are disabled when activating SDF. This means that SDF may reduce the overall throughput and scalability of the Security Gateway. Therefore, SDF should be used only when necessary and only on gateways that are dedicated to VPN traffic.


Reference:

R81 Performance Tuning Administration Guide



Which Mobile Access Application allows a secure container on Mobile devices to give users access to internal website, file share and emails?

  1. Check Point Remote User
  2. Check Point Capsule Workspace
  3. Check Point Mobile Web Portal
  4. Check Point Capsule Remote

Answer(s): C

Explanation:

Check Point Mobile Web Portal is a Mobile Access Application that allows a secure container on mobile devices to give users access to internal websites, file shares and emails. The Mobile Web Portal is a web-based application that can be accessed from any browser on any device. It provides a user-friendly interface to access various resources on the corporate network without requiring a VPN client or additional software installation. The Mobile Web Portal supports authentication methods such as user name and password, certificate, one-time password (OTP), etc. The Mobile Web Portal also supports security features such as encryption, data leakage prevention (DLP), threat prevention, etc.


Reference:

R81 Mobile Access Administration Guide



Which of the following process pulls application monitoring status?

  1. fwd
  2. fwm
  3. cpwd
  4. cpd

Answer(s): D

Explanation:

The process that pulls application monitoring status is cpd. cpd is a daemon that runs on Check Point products and performs various tasks related to management communication, policy installation, license verification, logging, etc. cpd also monitors the status of other processes and applications on the system and reports it to the management server. cpd uses SNMP to collect information from various sources, such as blades, gateways, servers, etc. You can view the application monitoring status in SmartConsole by using the Gateways & Servers tab in the Logs & Monitor view.


Reference:

Check Point Processes and Daemons



To fully enable Dynamic Dispatcher on a Security Gateway:

  1. run fw ctl multik set_mode 9 in Expert mode and then Reboot.
  2. Using cpconfig, update the Dynamic Dispatcher value to "full" under the CoreXL menu.
  3. Edit/proc/interrupts to include multik set_mode 1 at the bottom of the file, save, and reboot.
  4. run fw multik set_mode 1 in Expert mode and then reboot.

Answer(s): A

Explanation:

To fully enable Dynamic Dispatcher on a Security Gateway, you need to run the following command in Expert mode then reboot:



This command sets the multi-core mode to 9, which means that Dynamic Dispatcher is enabled without Firewall Priority Queues. Dynamic Dispatcher is a feature that optimizes the performance of Security Gateways with multiple CPU cores by dynamically allocating traffic to different cores based on their load and priority. Dynamic Dispatcher can improve the throughput and scalability of the Security Gateway, especially for traffic that is not accelerated by SecureXL. The other commands are not valid or do not enable Dynamic Dispatcher.


Reference:

R81 Performance Tuning Administration Guide



Page 23 of 158



Post your Comments and Discuss Checkpoint 156-315.81 exam with other Community members:

Fon commented on January 05, 2024
Q40 is wrong, correct reponse is 'Accept' template is enabled by default in R81.20
AUSTRALIA
upvote

Gavin commented on August 24, 2023
Question76 is wrong, Manual NAT ALWAYS comes first
Anonymous
upvote

stephane T commented on July 29, 2023
very usefull
CAMEROON
upvote