How many packets does the IKE exchange use for Phase 1 Main Mode?
When using vpn tu, which option must you choose if you only want to clear phase 2 for a specific IP (gateway)?
Exhibit:
Why are certificates preferred over pre-shared keys in an IPsec VPN?
Which of the following commands can be used to remove site-to-site IPsec Security Association (SA)?
Which of the following is an authentication method used by Identity Awareness?
Complete this statement from the options provided. Using Captive Portal, unidentified users may be either; blocked, allowed to enter required credentials, or required to download the _____________.
Which of the following actions take place in IKE Phase 2 with Perfect Forward Secrecy disabled?
A client has created a new Gateway object that will be managed at a remote location. When the client attempts to install the Security Policy to the new Gateway object, the object does not appear in the Install On check box. What should you look for?
Which SmartConsole component can Administrators use to track changes to the Rule Base?
Which of the following are authentication methods that Security Gateway R77 uses to validate connection attempts? Select the response below that includes the MOST complete list of valid authentication methods.
The User Directory Software Blade is used to integrate which of the following with Security Gateway R77?
What is the Manual Client Authentication TELNET port?
Security Gateway R77 supports User Authentication for which of the following services? Select the response below that contains the MOST correct list of supported services.
In the Rule Base displayed, user authentication in Rule 4 is configured as fully automatic. Eric is a member of the LDAP group, MSD_Group.
What happens when Eric tries to connect to a server on the Internet?
Match the terms with their definitions:
Exhibit:
Which of these Security Policy changes optimize Security Gateway performance?
Your R77 primary Security Management Server is installed on GAiA. You plan to schedule the Security Management Server to run fw logswitch automatically every 48 hours.
How do you create this schedule?
SmartView Tracker R77 consists of three different modes. They are:
Many companies have defined more than one administrator. To increase security, only one administrator should be able to install a Rule Base on a specific Firewall.
How do you configure this?
After implementing Static Address Translation to allow Internet traffic to an internal Web Server on your DMZ, you notice that any NATed connections to that machine are being dropped by anti-spoofing protections. Which of the following is the MOST LIKELY cause?
Which utility allows you to configure the DHCP service on GAiA from the command line?
In SmartDashboard, Translate destination on client side is checked in Global Properties. When Network Address Translation is used:
You have configured Automatic Static NAT on an internal host-node object. You clear the box Translate destination on client site from Global Properties > NAT. Assuming all other NAT settings in Global Properties are selected, what else must be configured so that a host on the Internet can initiate an inbound connection to this host?
Which R77 feature or command allows Security Administrators to revert to earlier Security Policy versions without changing object configurations?
Where can an administrator specify the notification action to be taken by the firewall in the event that available disk space drops below 15%?
Which Check Point address translation method allows an administrator to use fewer ISP-assigned IP addresses than the number of internal hosts requiring Internet connectivity?
An internal host initiates a session to the Google.com website and is set for Hide NAT behind the Security Gateway. The initiating traffic is an example of __________.
The third-shift Administrator was updating Security Management Server access settings in Global Properties. He managed to lock all administrators out of their accounts.
How should you unlock these accounts?
Which of the following methods will provide the most complete backup of an R77 configuration?
The third-shift Administrator was updating Security Management Server access settings in Global Properties and testing. He managed to lock himself out of his account.
How can you unlock this account?
You install and deploy GAiA with default settings. You allow Visitor Mode in the Gateway object’s Remote Access properties and install policy. What additional steps are required for this to function correctly?
What does SmartUpdate allow you to do?
You find a suspicious FTP site trying to connect to one of your internal hosts. How do you block it in real time and verify it is successfully blocked? Highlight the suspicious connection in SmartView Tracker:
For remote user authentication, which authentication scheme is NOT supported?
What CLI utility allows an administrator to capture traffic along the firewall inspection chain?
Assume you are a Security Administrator for ABCTech. You have allowed authenticated access to users from Mkting_net to Finance_net. But in the user’s properties, connections are only permitted within Mkting_net. What is the BEST way to resolve this conflict?
Which of the following are available SmartConsole clients which can be installed from the R77 Windows CD? Read all answers and select the most complete and valid list.
Lilly needs to review VPN History counters for the last week.
Where would she do this?
Your company enforces a strict change control policy. Which of the following would be MOST effective for quickly dropping an attacker’s specific active connection?
Is it possible to see user activity in SmartView Tracker?
Which authentication type requires specifying a contact agent in the Rule Base?
What is the difference between Standard and Specific Sign On methods?
Choose the correct statement regarding Implied Rules:
What information is found in the SmartView Tracker Management log?
Which answer below best describes the Administrator Auditing options available in SmartView Tracker?
You are working with multiple Security Gateways that enforce an extensive number of rules. To simplify security administration, which one of the following would you choose to do?
Which of the following options is available with the GAiA cpconfig utility on a Management Server?
You intend to upgrade a Check Point Gateway from R71 to R77. Prior to upgrading, you want to back up the Gateway should there be any problems with the upgrade. Which of the following allows for the Gateway configuration to be completely backed up into a manageable size in the least amount of time?
Which command enables IP forwarding on IPSO?
Which of these components does NOT require a Security Gateway R77 license?
Can you use Captive Portal with HTTPS?
A Cleanup rule:
Installing a policy usually has no impact on currently existing connections. Which statement is TRUE?
The London Security Gateway Administrator has just installed the Security Gateway and Management Server. He has not changed any default settings. As he tries to configure the Gateway, he is unable to connect.
Which troubleshooting suggestion will NOT help him?
The Security Gateway is installed on GAiA R77 The default port for the Web User Interface is _______.
Where do you verify that UserDirectory is enabled?
The Tokyo Security Management Server Administrator cannot connect from his workstation in Osaka.
Which of the following lists the BEST sequence of steps to troubleshoot this issue?
How can you most quickly reset Secure Internal Communications (SIC) between a Security Management Server and Security Gateway?