Join the discussion
Question 100/172
When dealing with rule base layers, what two layer types can be utilized?
Correct Answer: A
When dealing with rule base layers, two layer types can be utilized: Ordered Layers and Inline Layers5. Ordered Layers are executed sequentially according to their order in the policy. Inline Layers are embedded in a parent layer and are executed only if the parent rule matches. Check Point R81 Firewall Administration Guide, [Check Point R81 Security Management Administration Guide]
Add Comments
- Other Question (172q)
- Q1. From SecureXL perspective, what are the tree paths of traffic flow:...
- Q2. Which option in a firewall rule would only match and allow traffic to VPN gateways for one...
- Q3. Which of the following best describes how Access Role objects enhance identity-based polic...
- Q4. Fill in the blank: In Security Gateways R75 and above, SIC uses ______________ for encrypt...
- Q5. In which deployment type is the log indexing disabled by default?...
- Q6. Which command shows the installed licenses?
- Q7. Fill in the blanks: Gaia can be configured using _______ the ________....
- Q8. The ______ software blade package uses CPU-level and OS-level sandboxing in order to detec...
- Q9. Fill in the blank: ____________ is the Gaia command that turns the server off....
- Q10. What are the two main processes of the Identity Awareness blade?...
- Q11. What is one main purpose of URL Filtering?
- Q12. Customer's R80 management server needs to be upgraded to R80.10. What is the best upgrade ...
- Q13. Which of the following is a best practice for URL Filtering?...
- Q14. To view the policy installation history for each gateway, which tool would an administrato...
- Q15. What is the effect of enabling "Shared Layer" in an Inline Layer?...
- Q16. Which single Security Blade can be turned on to block both malicious files from being down...
- Q17. Which of the following is a key advantage of using predefined Autonomous Threat Prevention...
- Q18. When using Automatic Hide NAT, what is enabled by default?...
- Q19. Which of the following situations would not require a new license to be generated and inst...
- Q20. What are the two types of NAT supported by the Security Gateway?...
- Q21. What is the best sync method in the ClusterXL deployment?...
- Q22. Which method below is NOT one of the ways to communicate using the Management API's?...
- Q23. Which feature enhances security by restricting access to the Management Server to only tho...
- Q24. You are the Check Point administrator for Alpha Corp with an R80 Check Point estate. You h...
- Q25. What does URL Filtering primarily focus on?
- Q26. How do you match a user or a computer identity in the security policy?...
- Q27. What are the valid types of Administrator Accounts?...
- Q28. What is NOT an advantage of Stateful Inspection?...
- Q29. A security zone is a group of one or more network interfaces from different centrally mana...
- Q30. Where is the "Hit Count" feature enabled or disabled in SmartConsole?...
- Q31. In Check Point Security Management, what is the term for a logical grouping of one or more...
- Q32. What is the purpose of the Clean-up Rule?
- Q33. Stateful Inspection compiles and registers connections where?...
- Q34. Which process receives identity data from identity sources and organizes the data into tab...
- Q35. When should you enable log indexing on a Standalone Deployment?...
- Q36. What is the purpose of the Security Policies menu in SmartConsole?...
- Q37. A security administrator wants to integrate a third-party system with Check Point to send ...
- Q38. Which Identity Awareness client is used in high-volume environments that use Microsoft Act...
- Q39. What is the recommended service for web browsing in Application Control?...
- Q40. What two ordered layers make up the Access Control Policy Layer?...
- Q41. When configuring Spoof Tracking, which tracking actions can an administrator select to be ...
- Q42. Which of the following is NOT a valid deployment option for R80?...
- Q43. Which of the following is NOT a method used by Identity Awareness for acquiring identity?...
- Q44. When Accounting is enabled what is the time interval the logs are being updated?...
- Q45. When should you generate new licenses?
- Q46. With URL Filtering, what portion of the traffic is sent to the Check Point Online Web Serv...
- Q47. What is a reason for manual creation of a NAT rule?...
- Q48. What type of logs capture security-related events such as firewall activity and VPN connec...
- Q49. By default, alerts about specific security events are sent by which method?...
- Q50. Select the correct description of the SmartView Monitor....
- Q51. What is true of the URL Filtering Software Blade?...
- Q52. What is the primary benefit of Autonomous Threat Prevention?...
- Q53. Which of these is one of the Identity Sources used by the Identity Awareness Blade?...
- Q54. Which authentication method is the simplest for SmartConsole admin accounts?...
- Q55. What best describes the capability of the anti-bot blade?...
- Q56. Which of the following describes how Threat Extraction functions?...
- Q57. What are the different types of Policy Layers supported in an Access Control Policy?...
- Q58. In addition to the ability to add New objects, the Object Explorer lets you:...
- Q59. Which SmartConsole tab shows logs and detects security threats, providing a centralized di...
- Q60. The CDT utility supports which of the following?...
- Q61. Select the correct description of the Explicit Rules....
- Q62. What is a primary benefit of NAT?
- Q63. A network administrator has informed you that they have identified a malicious host on the...
- Q64. What object type would you use to grant network access to an LDAP user group?...
- Q65. Which of the following is NOT supported by Bridge Mode Check Point Security Gateway...
- Q66. Which Check Point software blade provides Application Security and identity control?...
- Q67. An administrator wants to identify which users are generating the most security events. Wh...
- Q68. Which of the following is considered to be the more secure and preferred VPN authenticatio...
- Q69. Which component is the source of the Logs sent to the Log Server?...
- Q70. One of major features in R80.x SmartConsole is concurrent administration. Which of the fol...
- Q71. John is the administrator of a R80 Security Management server managing r R77.30 Check Poin...
- Q72. What is the purpose of the Change Log in SmartConsole?...
- Q73. What is the difference between the Positive Control Model and the Negative Control Model?...
- Q74. Phase 1 of the two-phase negotiation process conducted by IKE operates in ______ mode....
- Q75. What is the purpose of Security Zones in rulebase creation?...
- Q76. Which default Gaia user has full read/write access?...
- Q77. Which of the following is an authentication method used for Identity Awareness?...
- Q78. You noticed that CPU cores on the Security Gateway are usually 100% utilized and many pack...
- Q79. Which of these Autonomous Threat Prevention profiles mainly focuses on providing extensive...
- Q80. R80 is supported by which of the following operating systems:...
- Q81. Select the most correct statement about policy types....
- Q82. You can see the following graphic: (Exhibit) What is presented on it?...
- Q83. Session unique identifiers are passed to the web api using which http header option?...
- Q84. What command from the CLI would be used to view current licensing?...
- Q85. Which of the following is used to initially create trust between a Gateway and Security Ma...
- Q86. True or False: In a Distributed Environment, a Central License can be installed via CLI on...
- Q87. Which of these is one of the components of Check Point's three-tier architecture?...
- Q88. Which of the following is NOT a valid configuration screen of an Access Role Object?...
- Q89. Which key is created during Phase 2 of a site-to-site VPN?...
- Q90. Which firewall daemon is responsible for the FW CLI commands?...
- Q91. When a packet arrives at the Security Gateway, the Security Gateway checks it against the ...
- Q92. What is the advantage of Autonomous Threat Prevention?...
- Q93. What is the SOLR database for?
- Q94. Which option, when applied to a rule, allows traffic to VPN gateways in specific VPN commu...
- Q95. What of the following is NOT an Identity Source supported by the Check Point Identity Awar...
- Q96. Fill in the blank: SmartConsole, SmartEvent GUI client, and ___________ allow viewing of b...
- Q97. Access roles allow the firewall administrator to configure network access according to:...
- Q98. What is the main purpose of objects in SmartConsole?...
- Q99. What is true about the IPS-Blade?
- Q100. When dealing with rule base layers, what two layer types can be utilized?...
- Q101. What is a best practice for managing SmartConsole administrator accounts?...
- Q102. What is the primary function of the 'Trusted Clients' feature in SmartConsole?...
- Q103. Which feature / blade can be used on both Check Point servers; the Security Management ser...
- Q104. What is the purpose of the Objects menu in SmartConsole?...
- Q105. Name one limitation of using Security Zones in the network?...
- Q106. What is the primary purpose of the Access Control Policy?...
- Q107. What is the purpose of a Stealth Rule?
- Q108. What should be added at the end of each Ordered Layer?...
- Q109. Under which file is the proxy arp configuration stored?...
- Q110. Fill in the blank: It is Best Practice to have a _____ rule at the end of each policy laye...
- Q111. Sticky Decision Function (SDF) is required to prevent which of the following? Assume you s...
- Q112. Your internal networks 10.1.1.0/24, 10.2.2.0/24 and 192.168.0.0/16 are behind the Internet...
- Q113. What is the default Implicit Cleanup Action in both Ordered and Inline Layers?...
- Q114. What is a benefit of https inspection?
- Q115. Fill in the blank: In order to install a license, it must first be added to the __________...
- Q116. You have successfully backed up your Check Point configurations without the OS information...
- Q117. Secure Internal Communication (SIC) is handled by what process?...
- Q118. Which message indicates IKE Phase 2 has completed successfully?...
- Q119. You want to verify if there are unsaved changes in GAiA that will be lost with a reboot. W...
- Q120. A company wants to monitor VPN tunnel status and gateway performance in real time. Which t...
- Q121. What is a recommended best practice after deploying Autonomous Threat Prevention?...
- Q122. Which of the following commands is used to verify license installation?...
- Q123. Fill in the blank: Each cluster, at a minimum, should have at least ___________ interfaces...
- Q124. When changes are made to a Rule base, it is important to _______________ to enforce change...
- Q125. Which SmartConsole feature allows to filter logs using predefined or custom queries?...
- Q126. What is the difference between the Access Control policy and NAT policy?...
- Q127. Which of the following blades is NOT subscription-based and therefore does not have to be ...
- Q128. What are the predefined Autonomous Threat Prevention Profiles?...
- Q129. Core Protections are installed as part of what Policy?...
- Q130. Which GUI tool can be used to view and apply Check Point licenses?...
- Q131. What is the command line to verify the backup was created?...
- Q132. What methods could be used with Custom Queries for querying logs?...
- Q133. CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You s...
- Q134. When defining group-based access in an LDAP environment with Identity Awareness, what is t...
- Q135. Which tool is primarily used for managing Quantum Security policies?...
- Q136. View the rule below. What does the pen-symbol in the left column mean? (Exhibit)...
- Q137. When connected to the Check Point R80 Management Server using the SmartConsole the first a...
- Q138. What does URL Filtering primarily focus on?
- Q139. Which type of object represents Office 365?
- Q140. What is the primary purpose of the Security Policy Management solution?...
- Q141. Log query results can be exported to what file format?...
- Q142. Which one of these features is NOT associated with the Check Point URL Filtering and Appli...
- Q143. What does it mean if Deyra sees the gateway status: (Exhibit) Choose the BEST answer....
- Q144. True or False: The destination server for Security Gateway logs depends on a Security Mana...
- Q145. When configuring LDAP with User Directory integration, changes applied to a User Directory...
- Q146. How is an Autonomous Threat Prevention Policy created?...
- Q147. DLP and Geo Policy are examples of what type of Policy?...
- Q148. You have discovered suspicious activity in your network. What is the BEST immediate action...
- Q149. Which of the following technologies extracts detailed information from packets and stores ...
- Q150. What is the purpose of the Policy Enforcement Point (PEP) in Identity Awareness?...
- Q151. Which Check Point software blade prevents malicious files from entering a network using vi...
- Q152. What management solution does Check Point offer as a service to deliver unified management...
- Q153. Which Identity Source(s) should be selected in Identity Awareness for when there is a requ...
- Q154. Which of the following is NOT a valid application navigation tab in the R80 SmartConsole?...
- Q155. A SAM rule Is implemented to provide what function or benefit?...
- Q156. After trust has been established between the Check Point components, what is TRUE about na...
- Q157. What is the Transport layer of the TCP/IP model responsible for?...
- Q158. What are the types of Software Containers?
- Q159. In HTTPS Inspection policy, what actions are available in the "Actions" column of a rule?...
- Q160. Which of the following is NOT supported by Bridge Mode on the Check Point Security Gateway...
- Q161. In Logging and Monitoring, the tracking options are Log, Detailed Log and Extended Log. Wh...
- Q162. Can multiple administrators connect to a Security Management Server at the same time?...
- Q163. The Online Activation method is available for Check Point manufactured appliances. How doe...
- Q164. With Autonomous Threat-Prevention, you can choose a profile that best fits your needs. Wha...
- Q165. Which of the following is used to enforce changes made to a Rule Base?...
- Q166. Traffic from source 192.168.1.1 is going to www.google.com. The Application Control Blade ...
- Q167. What is the purpose of the Stealth Rule?
- Q168. There are 2 ordered layers in a policy with 20 rules each. A connection matches rule numbe...
- Q169. Using ClusterXL, what statement is true about the Sticky Decision Function?...
- Q170. Which option will match a connection regardless of its association with a VPN community?...
- Q171. Which of the following groups represents valid administrator types in the Quantum Security...
- Q172. Select the correct predefined profile of the Autonomous Threat Prevention....
[×]
Download PDF File
Enter your email address to download CheckPoint.156-215.82.v2026-10-12.q172.pdf
