CheckPoint 156-915 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| System Monitoring and Troubleshooting | - Log analysis using SmartView Tracker - Debugging and troubleshooting tools |
| Network Address Translation (NAT) | - NAT troubleshooting - Static and Hide NAT configuration |
| VPN and Secure Connectivity | - Site-to-site VPN and remote access VPN - IPsec VPN configuration |
| Cluster and High Availability | - ClusterXL concepts - Failover mechanisms and redundancy |
| Network Security Enforcement | - Firewall-1 / Security Gateway operations - Stateful inspection and packet flow |
| Security Management Architecture | - Policy management and rule base configuration - SmartConsole / SmartDashboard usage |
CheckPoint Accelerated CCSE NGX (156-915.1) Sample Questions:
1. Your is a Security Administrator preparing to implement a VPN solution for his multisite organization. To comply with industry regulations, Your's VPN solution must meet the following requirements:
Portability: Standard
Key management: Automatic, external PKI
Session Keys: Changed at configured times during a connection's lifetime Key length: No less than 128-bit Data integrity: Secure against inversion and brute-force attacks What is the most appropriate setting You should choose?
A) IKE VPNs: AES encryption for IKE Phase 1, and DES encryption for Phase 2; SHA1 hash
B) IKE VPNs: DES encryption for IKE Phase 1, and 3DES encryption for Phase 2; MD5 hash
C) IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash
D) IKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for Phase 2; AES hash
E) IKE VPNs: CAST encryption for IKE Phase 1, and SHA1 encryption for Phase 2; DES hash
2. A Security Administrator is notified that some long-lasting Telnet connections to a mainframe are dropped every time after an hour. The Administrator suspects that the Security Gateway might be blocking these connections. As she reviews the Smart Tracker the Administrator sees the packet is dropped with the error "Unknown established connection". How can she resolve this problem, without causing other security issues?
Choose the BEST answer. She can:
A) ask the mainframe users to reconnect every time this error occurs.
B) create a new TCP service object on port 23, and increase the session time-out for this object. She only uses this new object in the rule that allows the Telnet connections to the mainframe.
C) increase the session time-out in the Service Properties of the Telnet service.
D) increase the session time-out in the mainframe's Object Properties.
E) increase the session time-out in the Global Properties.
3. How does ClusterXL Unicast mode handle new traffic?
A) Only the pivot machine receives all packets. It runs an algorithm to determine which member should process the packets.
B) All cluster members process all packets, and members synchronize with each other.
C) All members receive all packets. The SmartCenter Server decides which member will process the packets. Other members simply drop the packets.
D) The pivot machine receives and inspects all new packets,and synchronizes the connections with other members.
4. The following diagram illustrates how a VPN-1 SecureClient user tries to establish a VPN with hosts in the external_net and internal_net from the Internet. How is the Security Gateway VPN Domain created?
A) Internal Gateway VPN Domain = internal_net;
External Gateway VPN Domain = internal VPN Domain + internal gateway object + external_net
B) Internal Gateway VPN Domain = internal_net;
External Gateway VPN Domain = internal_net + external_net
C) Internal Gateway VPN Domain = internal_net;
External Gateway VPN Domain = external_net + internal gateway object
D) Internal Gateway VPN Domain = internal_net;
External VPN Domain = external net + external gateway object + internal_net
5. How can you reset Secure Internal Communications (SIC) between a SmartCenter Server and Security Gateway?
A) From cpconfig on the SmartCenter Server, choose the Secure Internal Communication option and retype the activation key.Next, retype the same key in the gateway object in SmartDashboard and reinitialize Secure Internal Communications (SIC).
B) Use SmartUpdate to retype the activation key of the Security Gateway.
C) Run the command fwm sic_reset to reinitialize the Internal Certificate Authority (ICA) of the SmartCenter Server. Then retype the activation key on the Security Gateway from SmartDashboard.
D) From the SmartCenter Server's command line type fw putkey -p <shared key> <IP Address of Security Gateway>.
E) From the SmartCenter Server's command line type fw putkey -p <shared key> <IP Address of SmartCenter Server>.
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: B | Question # 3 Answer: A | Question # 4 Answer: A | Question # 5 Answer: A |














1041 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
