156-915.80 dumps pdf, 156-915.80 exam, 156-915.80 exam dumps, 156-915.80 practice test, CheckPoint

Want to pass your CheckPoint 156-915.80 exam on the first try? Download Pass4itsure latest CheckPoint 156-915.80 exam dumps https://www.pass4itsure.com/156-915-80.html (156-915.80 exam questions) Pls keep enough time to practice! Looking for the latest 156-915.80 exam questions, 156-915.80 practice exam? Pass4itsure have!

CheckPoint 156-915.80 PDF – free download

[latest google drive pdf] 156-915.80 pdf download https://drive.google.com/file/d/1IEDRQZg8Pw2KtETm7FfNeundvzzCCZq1/view?usp=sharing

CheckPoint 156-915.80 practice test (q1-q13)

QUESTION 1
Which file defines the fields for each object used in the file objects.C (color, num/string, default value…)?
A. $FWDIR/conf/classes.C
B. $FWDIR/conf/scheam.C
C. $FWDIR/conf/fields.C
D. $FWDIR/conf/table.C
Correct Answer: A


QUESTION 2
On R80.10 the IPS Blade is managed by:
A. Threat Protection policy
B. Anti-Bot Blade
C. Threat Prevention policy
D. Layers on Firewall policy
Correct Answer: C


QUESTION 3
CPM process stores objects, policies, users, administrators, licenses and management data in a database. This
database is:
A. MySQL
B. Postgres SQL
C. MarisDB
D. SOLR
Correct Answer: B

QUESTION 4
Using mgmt_cli, what is the correct syntax to import a host object called Server_1 from the CLI?
A. mgmt_cli add-host “Server_1” ip_ address “10.15.123.10” ?format txt
B. mgmt_ cli add host name “Server_ 1” ip-address “10.15.123.10” ?format json
C. mgmt_ cli add object-host “Server_ 1” ip-address “10.15.123.10” ?format json
D. mgmt_cli add object “Server_ 1” ip-address “10.15.123.10” ?format json
Correct Answer: B
mgmt_cli add host name “New Host 1” ip-address “192.0.2.1” –format json “–format json” is optional. By default the
output is presented in plain text. Reference: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/addhost~v1.1%20


QUESTION 5
What scenario indicates that SecureXL is enabled?
A. Dynamic objects are available in the Object Explorer
B. SecureXL can be disabled in cpconfig
C. fwaccel commands can be used in clish
D. Only one packet in a stream is seen in a fw monitor packet capture
Correct Answer: C


QUESTION 6
A snapshot delivers a complete Gaia backup. The resulting file can be stored on servers or as a local file in
/var/CPsnapshot/snapshots. How do you restore a local snapshot named MySnapshot.tgz?
A. Reboot the system and call the start menu. Select the option Snapshot Management, provide the Expert password
and select [L] for a restore from a local file. Then, provide the correct file name.
B. As expert user, type the command snapshot -r MySnapshot.tgz.
C. As expert user, type the command revert –file MySnapshot.tgz.
D. As expert user, type the command snapshot – R to restore from a local file. Then, provide the correct file name.
Correct Answer: C

QUESTION 7
To find records in the logs that shows log records from the Application and URL Filtering Software Blade where traffic
was blocked, what would be the query syntax?
A. blade: application control AND action:block
B. blade; “application control” AND action;block
C. (blade: application control AND action;block)
D. blade: “application control” AND action:block
Correct Answer: D
Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_LoggingAndMonitoring/html_frameset.htm?topic=documents/R80/CP_R80_LoggingAndMonitoring/131914


QUESTION 8
You enable Hide NAT on the network object, 10.1.1.0 behind the Security Gateway\\’s external interface.
You browse to the Google Website from host, 10.1.1.10 successfully. You enable a log on the rule that allows 10.1.1.0
to exit the network.
How many log entries do you see for that connection in SmartView Tracker?
A. Two, one for outbound, one for inbound
B. Only one, outbound
C. Two, both outbound, one for the real IP connection and one for the NAT IP connection
D. Only one, inbound
Correct Answer: B

QUESTION 9
You are a Security Administrator who has installed Security Gateway R80 on your network. You need to allow a specific
IP address range for a partner site to access your intranet Web server. To limit the partner\\’s access for HTTP and
FTP
only, you did the following:
1) Created manual Static NAT rules for the Web server.
2) Cleared the following settings in the Global Properties > Network Address Translation screen:
-Allow bi-directional NAT

Translate destination on client side Do the above settings limit the partner\\’s access?
A.
Yes. This will ensure that traffic only matches the specific rule configured for this traffic, and that the Gateway translates
the traffic after accepting the packet.
B.
No. The first setting is not applicable. The second setting will reduce performance.
C.
Yes. Both of these settings are only applicable to automatic NAT rules.
D.
No. The first setting is only applicable to automatic NAT rules. The second setting will force translation by the kernel on
the interface nearest to the client.
Correct Answer: D


QUESTION 10
What happens when the IPS profile is set in Detect-Only Mode for troubleshooting?
A. It will generate Geo-Protection traffic
B. Automatically uploads debugging logs to Check Point Support Center
C. It will not block malicious traffic
D. Bypass licenses requirement for Geo-Protection control
Correct Answer: C
It is recommended to enable Detect-Only for Troubleshooting on the profile during the initial installation of IPS. This
option overrides any protections that are set to Prevent so that they will not block any traffic. During this time you can
analyze the alerts that IPS generate to see how IPS will handle network traffic while avoiding any impact on the flow of
traffic. Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_IPS_AdminGuide/12750.htm

QUESTION 11
Your main internal network 10.10.10.0/24 allows all traffic to the Internet using Hide NAT. You also have a small
network 10.10.20.0/24 behind the internal router. You want to configure the kernel to translate the source address only
when network 10.10.20.0 tries to access the Internet for HTTP, SMTP, and FTP services. Which of the following
configurations will allow this network to access the Internet?
A. Configure three Manual Static NAT rules for network 10.10.20.0/24, one for each service.
B. Configure Automatic Static NAT on network 10.10.20.0/24.
C. Configure one Manual Hide NAT rule for HTTP, FTP, and SMTP services for network 10.10.20.0/24.
D. Configure Automatic Hide NAT on network 10.10.20.0/24 and then edit the Service column in the NAT Rule Base on
the automatic rule.
Correct Answer: C

QUESTION 11
Your main internal network 10.10.10.0/24 allows all traffic to the Internet using Hide NAT. You also have a small
network 10.10.20.0/24 behind the internal router. You want to configure the kernel to translate the source address only
when network 10.10.20.0 tries to access the Internet for HTTP, SMTP, and FTP services. Which of the following
configurations will allow this network to access the Internet?
A. Configure three Manual Static NAT rules for network 10.10.20.0/24, one for each service.
B. Configure Automatic Static NAT on network 10.10.20.0/24.
C. Configure one Manual Hide NAT rule for HTTP, FTP, and SMTP services for network 10.10.20.0/24.
D. Configure Automatic Hide NAT on network 10.10.20.0/24 and then edit the Service column in the NAT Rule Base on
the automatic rule.
Correct Answer: C

156-915.80 exam questions video

Share CheckPoint dumps Pass4itsure discount code

Conclusion:

This blog collected actual CheckPoint 156-915.80 questions and answers, 156-915.80 pdf, 156-915.80 exam video. Get the latest complete 156-915.80 exam dumps https://www.pass4itsure.com/156-915-80.html (Q&As: 536 156-915.80 dumps). Please allow me enough time to practice.

100% free CheckPoint 156-915.80 pdf https://drive.google.com/file/d/1IEDRQZg8Pw2KtETm7FfNeundvzzCCZq1/view?usp=sharing