CheckPoint 156-215.80 Exam Questions – (March-2018 dumps)

Check Point Certified Security Administrator 156-215.80 exam is possible to pass with excellence without spending a huge amount of time and money by getting help of VCE2Pass’s 156-215.80 Check Point Certified Security Administrator R80 exam questions. Our 156-215.80 exam dumps material consist of practice test software + PDF Q&A booklet. The success is powered by money back guarantee so your investment is safe either you will succeed or will get the money back moreover you can save 25% of total cost by purchasing the both products together.

♥ VALID 156-215.80 Exam Questions 2018 ♥

156-215.80 exam questions, 156-215.80 PDF dumps; 156-215.80 exam dumps:: https://www.dumpsschool.com/156-215.80-exam-dumps.html (265 Q&A) (New Questions Are 100% Available! Also Free Practice Test Software!)

Latest CheckPoint 156-215.80 Dumps Exam Questions and Answers:

Version: 8.0
Question: 21

An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security Management Server. While configuring the VPN community to specify the pre-shared secret the administrator found that the check box to enable pre-shared secret is shared and cannot be enabled. Why does it not allow him to specify the pre-shared secret?

A. IPsec VPN blade should be enabled on both Security Gateway.
B. Pre-shared can only be used while creating a VPN between a third party vendor and Check Point Security Gateway.
C. Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS.
D. The Security Gateways are pre-R75.40.

Answer: C

Question: 22

Alpha Corp., and have recently returned from a training course on Check Point’s new advanced R80 management platform. You are presenting an in-house R80 Management to the other administrators in Alpha Corp.

How will you describe the new “Publish” button in R80 Management Console?

A. The Publish button takes any changes an administrator has made in their management session, publishes a copy to the Check Point of R80, and then saves it to the R80 database.
B. The Publish button takes any changes an administrator has made in their management session and publishes a copy to the Check Point Cloud of R80 and but does not save it to the R80
C. The Publish button makes any changes an administrator has made in their management session visible to all other administrator sessions and saves it to the Database.
D. The Publish button makes any changes an administrator has made in their management session visible to the new Unified Policy session and saves it to the Database.

Answer: C

To make your changes available to other administrators, and to save the database before installing a policy, you must publish the session. When you publish a session, a new database version is created.

Question: 23

Vanessa is firewall administrator in her company; her company is using Check Point firewalls on central and remote locations, which are managed centrally by R80 Security Management Server. One central location has an installed R77.30 Gateway on Open server. Remote location is using Check Point UTM-1 570 series appliance with R71. Which encryption is used in Secure Internal Communication (SIC) between central management and firewall on each location?

A. On central firewall AES128 encryption is used for SIC, on Remote firewall 3DES encryption is used for SIC.
B. On both firewalls, the same encryption is used for SIC. This is AES-GCM-256.
C. The Firewall Administrator can choose which encryption suite will be used by SIC.
D. On central firewall AES256 encryption is used for SIC, on Remote firewall AES128 encryption is used for SIC.

Answer: A

Gateways above R71 use AES128 for SIC. If one of the gateways is R71 or below, the gateways use 3DES.

Question: 24

Review the following screenshot and select the BEST answer.

A. Data Center Layer is an inline layer in the Access Control Policy.
B. By default all layers are shared with all policies.
C. If a connection is dropped in Network Layer, it will not be matched against the rules in Data Center Layer.
D. If a connection is accepted in Network-layer, it will not be matched against the rules in Data Center Layer.

Answer: C

Question: 25

Which of the following is NOT a SecureXL traffic flow?

A. Medium Path
B. Accelerated Path
C. Fast Path
D. Slow Path

Answer: C

SecureXL is an acceleration solution that maximizes performance of the Firewall and does not compromise security. When SecureXL is enabled on a Security Gateway, some CPU intensive operations are processed by virtualized software instead of the Firewall kernel. The Firewall can inspect and process connections more efficiently and accelerate throughput and connection rates. These are the SecureXL traffic flows:
Slow path – Packets and connections that are inspected by the Firewall and are not processed by SecureXL.
Accelerated path – Packets and connections that are offloaded to SecureXL and are not processed by the Firewall.
Medium path – Packets that require deeper inspection cannot use the accelerated path. It is not necessary for the Firewall to inspect these packets, they can be offloaded and do not use the slow path. For example, packets that are inspected by IPS cannot use the accelerated path and can be offloaded to the IPS PSL (Passive Streaming Library). SecureXL processes these packets more quickly than packets on the slow path.

Question: 26

Which of the following Automatically Generated Rules NAT rules have the lowest implementation priority?

A. Machine Hide NAT
B. Address Range Hide NAT
C. Network Hide NAT
D. Machine Static NAT

Answer: B,C

SmartDashboard organizes the automatic NAT rules in this order:

New Updated 156-215.80 Exam Questions 156-215.80 PDF dumps 156-215.80 practice exam dumps: https://www.dumpsschool.com/156-215.80-exam-dumps.html