New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Checkpoint 156-582 Check Point Certified Troubleshooting Administrator - R81.20 (CCTA) Exam Practice Test

Demo: 22 questions
Total 75 questions

Check Point Certified Troubleshooting Administrator - R81.20 (CCTA) Questions and Answers

Question 1

SmartConsole closes immediately, what is the most likely reason?

Options:

A.

The process crashed in kernel space

B.

The process crashed in user space

C.

The user idle time expired and SmartConsole disconnected the user

D.

The Security Management server rejected the client connection

Question 2

After manipulating the rulebase and objects with SmartConsole the application crashes and closes immediately. To troubleshoot, you will need to review the crash report. In which directory on the host PC will you find this report?

Options:

A.

\data\crash_report\

B.

\data\crash_report\

C.

\data\crash_report

D.

\crash_report\data\

Question 3

Which type of NAT allows both incoming and outgoing connections?

Options:

A.

Both Static and Hide NAT

B.

Hide NAT

C.

Static NAT

D.

Port NAT

Question 4

What Check Point process controls logging?

Options:

A.

CPWD

B.

FWD

C.

CPD

D.

CPM

Question 5

Services with expired licenses and contracts have,

Options:

A.

full functionality for 90 days after they expire

B.

full functionality for 45 days after they expire

C.

no functionality

D.

limited functionality

Question 6

How many captures does the command "fw monitor -p all" take?

Options:

A.

All 15 of the inbound and outbound modules

B.

The -p option takes the same number of captures, but gathers all of the data packet

C.

1 from every inbound and outbound module of the chain

D.

All 4 points of the fw VM modules

Question 7

Running tcpdump causes a significant increase on CPU usage, what other option should you use?

Options:

A.

fw monitor

B.

Wait for out of business hours to do a packet capture

C.

cppcap

D.

You need to use tcpdump with -e option to decrease the length of packet in captures and it will utilize the less CPU

Question 8

The URL filtering cache limit exceeded. What issues can this cause?

Options:

A.

When URL filtering cache exceeds the limit, it will be disabled temporarily to overcome instability of the system

B.

RAD process will spawn multiple times to help populate the cache

C.

Resource Advisor (RAD) process on the Security Gateway consumes close to 100 percent of the CPU

D.

Nothing, the Security Gateway dynamically raises the cache when needed

Question 9

Customer wants to use autonomous threat prevention. How do you enable it?

Options:

A.

Enable Autonomous Threat Prevention on the Security Gateway from the SmartConsole: Gateway and Servers view and enable IPS on the Security Gateway by the command: ips on.

B.

Enable Autonomous Threat Prevention on the Security Gateway from the SmartConsole:Gateway and Servers view, the default profile Strict Security will be selected.

C.

Enable Autonomous Threat Prevention on the Security Gateway from the SmartConsole: Gateway and Servers view, inspection profile is not needed, the Security Gateway will automatically select the best profile according to deployment.

D.

Enable Autonomous Threat Prevention on the Security Gateway from the SmartConsole: Gateway and Servers view, then select inspection profile.

Question 10

Application Control and URL Filtering update files are located in which directory?

Options:

A.

SCPDIR/appi/update

B.

SFWDIR/conf/update

C.

SCPDIR/apci/update

D.

SFWDIR/appi/update/

Question 11

What are some measures you can take to prevent IPS false positives?

Options:

A.

Capture packets, Update the IPS database, and Back up custom IPS files

B.

Use Recommended IPS profile

C.

Use IPS only in Detect mode

D.

Exclude problematic services from being protected by IPS (sip, H.323, etc.)

Question 12

What is the difference between the “Super User" and “Read Write All" SmartConsole permission profiles?

Options:

A.

“Read Write All" has the extra ability to make changes within the Gaia operating system

B.

“Super User” has the extra ability to administer other administrative accounts

C.

“Super User” has the extra ability to make changes within the Gaia operating system

D.

“Super User" had the extra ability of being able to use the Management API

Question 13

You want to work with a license for your gateway in User Center portal, but all options are greyed out. What is the reason?

Options:

A.

Your account has classification permission to Viewer

B.

Your account has classification permission to Licenser

C.

You are not defined as Support Contact

D.

Your account does not have any rights

Question 14

What are the commands to verify the Smart Contracts on the Security Gateway?

Options:

A.

cpconfig and contracts_mgmt

B.

cpconfig and cpcontract

C.

cpinfo and cplic

D.

contractjtil and cplic

Question 15

You need to switch the active log file on the Security Gateway. What is the correct command?

Options:

A.

fw -p -o switch

B.

fw logswitch

C.

Install security policy

D.

fw switchlog

Question 16

As a security administrator/engineer in your company, you have noticed that your HQ Check Point Security Management Server is not receiving logs from your HQ Check Point Gateway/Cluster. To investigate this issue in the command line, you will need to verify which process is running?

Options:

A.

cpm

B.

cpd

C.

fwd

D.

fwm

Question 17

For Threat Prevention, which process is enabled when the Policy Conversion process has debug turned on using the INTERNAL_POLICY_LOADING=1 command?

Options:

A.

fwm

B.

cpm

C.

solr

D.

dlpd

Question 18

You need to capture NAT information into packet capture, what tool is the best suitable for this task?

Options:

A.

tcpdump

B.

fw monitor

C.

cppcap

D.

fw ctl zdebug + xlate xltrc nat

Question 19

What is the most efficient way to view large fw monitor captures and run filters on the file?

Options:

A.

snoop

B.

CLI

C.

CLISH

D.

Wireshark

Question 20

To verify that communication is working between the Security Management Server and the Security Gateway, which service port should be checked?

Options:

A.

257

B.

18209

C.

259

D.

19009

Question 21

Where can a Check Point customer find information about product licenses they own, download product manuals, and get information about product support expiration?

Options:

A.

Smart Console

B.

PartnerMAP portal

C.

UserCenter portal

D.

In security management server via CLI and executing command cplic print

Question 22

Which of the following is NOT an account user classification?

Options:

A.

Licensers

B.

Manager

C.

Viewer

D.

Administrator

Demo: 22 questions
Total 75 questions