[2025年08月08日]156-215.81.20試験問題集で100%合格率156-215.81.20試験! [Q125-Q146]

Share

[2025年08月08日]156-215.81.20試験問題集で100%合格率156-215.81.20試験!

試験問題集リアルCCSA問題集400解答を試そう!

質問 # 125
CPU-level of your Security gateway is peaking to 100% causing problems with traffic. You suspect that the problem might be the Threat Prevention settings.
The following Threat Prevention Profile has been created.

How could you tune the profile in order to lower the CPU load still maintaining security at good level? Select the BEST answer.

  • A. Set High Confidence to Low and Low Confidence to Inactive.
  • B. The problem is not with the Threat Prevention Profile. Consider adding more memory to the appliance.
  • C. Set the Performance Impact to Medium or lower.
  • D. Set the Performance Impact to Very Low Confidence to Prevent.

正解:C


質問 # 126
Which repositories are installed on the Security Management Server by SmartUpdate?

  • A. Package Repository and Licenses
  • B. Update and License & Contract
  • C. License and Update
  • D. License & Contract and Package Repository

正解:D


質問 # 127
When doing a Stand-Alone Installation, you would install the Security Management Server with which other Check Point architecture component?

  • A. None, Security Management Server would be installed by itself.
  • B. SecureClient
  • C. SmartEvent
  • D. SmartConsole

正解:A


質問 # 128
What is NOT an advantage of Stateful Inspection?

  • A. High Performance
  • B. Transparency
  • C. Good Security
  • D. No Screening above Network layer

正解:D


質問 # 129
Due to high CPU workload on the Security Gateway, the security administrator decided to purchase a new multicore CPU to replace the existing single core CPU.
After installation, is the administrator required to perform any additional tasks?

  • A. Go to clash-Run cpstop | Run cpstart
  • B. Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway | Install Security Policy
  • C. Go to clash-Run cpconfig | Configure CoreXL to make use of the additional Cores | Exit cpconfig | Reboot Security Gateway
  • D. Administrator does not need to perform any task. Check Point will make use of the newly installed CPU and Cores

正解:C


質問 # 130
Which of the following is NOT an authentication scheme used for accounts created through SmartConsole?

  • A. Security questions
  • B. SecurID
  • C. Check Point password
  • D. RADIUS

正解:A


質問 # 131
Check Point ClusterXL Active/Active deployment is used when:

  • A. There is Load Sharing solution set up
  • B. Only when there is Multicast solution set up
  • C. Only when there is Unicast solution set up
  • D. There is High Availability solution set up

正解:A


質問 # 132
Which type of Check Point license ties the package license to the IP address of the Security Management Server?

  • A. Corporate
  • B. Central
  • C. Local
  • D. Formal

正解:B


質問 # 133
Of all the Check Point components in your network, which one changes most often and should be backed up most frequently?

  • A. SmartManager
  • B. Security Gateway
  • C. Security Management Server
  • D. SmartConsole

正解:C


質問 # 134
Which of the following is NOT a valid deployment option for R80?

  • A. Bridge Mode
  • B. Distributed
  • C. All-in-one (stand-alone)
  • D. CloudGuard

正解:D


質問 # 135
Which of the following is NOT a valid configuration screen of an Access Role Object?

  • A. Machines
  • B. Time
  • C. Users
  • D. Networks

正解:B


質問 # 136
Which is a suitable command to check whether Drop Templates are activated or not?

  • A. fwaccel stat
  • B. fw ctl get int activate_drop_templates
  • C. fwaccel stats
  • D. fw ctl templates -d

正解:A


質問 # 137
Fill in the blanks: Gaia can be configured using _______ the ________.

  • A. Command line interface; WebUI
  • B. GaiaUI; command line interface
  • C. Gaia Interface; GaiaUI
  • D. WebUI; Gaia Interface

正解:A


質問 # 138
Fill in the blank Backup and restores can be accomplished through

  • A. WebUI. CLI. or SmartUpdate
  • B. SmartUpdate, SmartBackup. or SmartConsole
  • C. CLI. SmartUpdate, or SmartBackup
  • D. SmartConsole, WebUI. or CLI

正解:D


質問 # 139
Name one limitation of using Security Zones in the network?

  • A. Security zones will not work in Automatic NAT rules
  • B. Security zones cannot be used in network topology
  • C. Security zones will not work in firewall policy layer
  • D. Security zone will not work in Manual NAT rules

正解:D


質問 # 140
Which statement is TRUE of anti-spoofing?

  • A. With dynamic routing enabled, anti-spoofing groups are updated automatically whenever there is a routing change
  • B. Anti-spoofing is not needed when IPS software blade is enabled
  • C. It is more secure to create anti-spoofing groups manually
  • D. It is BEST Practice to have anti-spoofing groups in sync with the routing table

正解:D


質問 # 141
What is a role of Publishing?

  • A. The Publish operation sends the modifications made via SmartConsole in the private session and makes them public
  • B. Modifies network objects, such as servers, users, services, or IPS profiles, but not the Rule Base
  • C. The Security Management Server installs the updated session and the entire Rule Base on Security Gateways
  • D. The Security Management Server installs the updated policy and the entire database on Security Gateways

正解:A


質問 # 142
To increase security, the administrator has modified the Core protection 'Host Port Scan' from
'Medium' to 'High' Predefined Sensitivity.
Which Policy should the administrator install after Publishing the changes?

  • A. The Access Control Policy.
  • B. The Access Control & HTTPS Inspection Policy.
  • C. The Threat Prevention Policy.
  • D. The Access Control and Threat Prevention Policies.

正解:C


質問 # 143
Which command shows detailed information about VPN tunnels?

  • A. vpn tu tlist
  • B. cpview
  • C. cat $FWDlR/conf/vpn.conf
  • D. vpn tu

正解:D


質問 # 144
Fill in the blank: Service blades must be attached to a ______________.

  • A. Management server
  • B. Security Gateway container
  • C. Security Gateway
  • D. Management container

正解:C


質問 # 145
What are the advantages of a "shared policy" in R80?

  • A. Allows the administrator to install a policy on one Security Gateway and it gets installed on another managed Security Gateway
  • B. Allows the administrator to share a policy between all the users identified by the Security Gateway
  • C. Allows the administrator to share a policy between all the administrators managing the Security Management Server
  • D. Allows the administrator to share a policy so that it is available to use in another Policy Package

正解:D


質問 # 146
......

あなたを余裕で156-215.81.20試験合格させます!100%高合格率保証:https://www.passtest.jp/CheckPoint/156-215.81.20-shiken.html

156-215.81.20問題集本日限定!無料アクセス可能に!:https://drive.google.com/open?id=1BwVb9J3Yg_T2uTXNvm8WkwdEkcFBGVL9