Free 156-315.81 Exam Braindumps (page: 58)

Page 57 of 158

What is true of the API server on R81.20?

  1. By default the API-server is activated and does not have hardware requirements.
  2. By default the API-server is not active and should be activated from the WebUI.
  3. By default the API server is active on management and stand-alone servers with 16GB of RAM (or more).
  4. By default, the API server is active on management servers with 4 GB of RAM (or more) and on stand-alone servers with 8GB of RAM (or more).

Answer(s): D

Explanation:

The true statement about the API server on R81.20 is: By default, the API server is active on management servers with 4 GB of RAM (or more) and on stand-alone servers with 8GB of RAM (or more). The API server is a web service that allows external applications to interact with the Check Point management server using standard methods such as HTTP(S) requests and JSON objects. The API server is enabled by default on R81.20 management servers that have at least 4 GB of RAM, and on stand-alone servers that have at least 8 GB of RAM. The API server can also be manually enabled or disabled from the WebUI or the CLI.



To ensure that VMAC mode is enabled, which CLI command should you run on all cluster members?

  1. fw ctl set int fwha vmac global param enabled
  2. fw ctl get int vmac global param enabled; result of command should return value 1
  3. cphaprob-a if
  4. fw ctl get int fwha_vmac_global_param_enabled; result of command should return value 1

Answer(s): D

Explanation:

To ensure that VMAC mode is enabled, the CLI command that should be run on all cluster members is fw ctl get int fwha_vmac_global_param_enabled; result of command should return value 1. VMAC

mode is a feature that allows ClusterXL to use virtual MAC addresses for cluster interfaces, instead of physical MAC addresses. This improves the failover performance and compatibility of ClusterXL with switches and routers. To check if VMAC mode is enabled, the command fw ctl get int fwha_vmac_global_param_enabled can be used, which returns 1 if VMAC mode is enabled, and 0 if VMAC mode is disabled.



For best practices, what is the recommended time for automatic unlocking of locked admin accounts?

  1. 20 minutes
  2. 15 minutes
  3. Admin account cannot be unlocked automatically
  4. 30 minutes at least

Answer(s): D

Explanation:

For best practices, the recommended time for automatic unlocking of locked admin accounts is 30 minutes at least. Admin accounts can be locked due to failed login attempts, password expiration, or manual locking by another admin. To prevent unauthorized access or brute force attacks, locked admin accounts should not be unlocked automatically too soon. The recommended minimum time for automatic unlocking is 30 minutes, which can be configured from the SmartConsole under Manage > Permissions and Administrators > Advanced > Unlock locked administrators after.



Which is NOT a SmartEvent component?

  1. SmartEvent Server
  2. Correlation Unit
  3. Log Consolidator
  4. Log Server

Answer(s): C

Explanation:

Log Consolidator is NOT a SmartEvent component. SmartEvent is a unified security event management solution that provides visibility, analysis, and reporting of security events across multiple Check Point products. SmartEvent consists of three main components: SmartEvent Server, Correlation Unit, and Log Server. SmartEvent Server is responsible for storing and displaying security events in SmartConsole and SmartEventWeb. Correlation Unit is responsible for collecting and correlating logs from various sources and generating security events based on predefined or custom scenarios. Log Server is responsible for receiving and indexing logs from Security Gateways and other

Check Point modules. Log Consolidator is not a valid component or blade of SmartEvent.






Post your Comments and Discuss Checkpoint 156-315.81 exam with other Community members:

156-315.81 Exam Discussions & Posts