
2022年03月15日に更新された最新のGoShiken 156-315.80試験問題リアル156-315.80問題集で
156-315.80別格な問題集で最上級の成績にさせる156-315.80問題
CheckPoint 156-315.80 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
質問 63
SmartEvent does NOT use which of the following procedures to identify events:
- A. Matching a log against local exclusions
- B. Create an event candidate
- C. Matching a log against each event definition
- D. Matching a log against global exclusions
正解: A
解説:
Explanation
Events are detected by the SmartEvent Correlation Unit. The Correlation Unit task is to scan logs for criteria that match an Event Definition. SmartEvent uses these procedures to identify events:
* Matching a Log Against Global Exclusions
* Matching a Log Against Each Event Definition
* Creating an Event Candidate
* When a Candidate Becomes an Event
References:
質問 64
The WebUI offers several methods for downloading hotfixes via CPUSE except:
- A. Automatic
- B. Force override
- C. Manually
- D. Scheduled
正解: B
質問 65
SSL Network Extender (SNX) is a thin SSL VPN on-demand client that is installed on the remote user's machine via the web browser. What are the two modes of SNX?
- A. Network and Layers
- B. Virtual Adapter and Mobile App
- C. Application and Client Service
- D. Network and Application
正解: D
解説:
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk67820
質問 66
You can select the file types that are sent for emulation for all the Threat Prevention profiles. Each profile defines a(n) _____ or ______ action for the file types.
- A. Inspect/Bypass
- B. Detect/Bypass
- C. Prevent/Bypass
- D. Inspect/Prevent
正解: A
解説:
Reference:
https://sc1.checkpoint.com/documents/R77/CP_R77_ThreatPrevention_WebAdmin/101703
.htm
質問 67
In the R80 SmartConsole, on which tab are Permissions and Administrators defined?
- A. Manage and Settings
- B. Security Policies
- C. Gateways and Servers
- D. Logs and Monitor
正解: A
質問 68
There are 4 ways to use the Management API for creating host object with R80 Management API. Which one is NOT correct?
- A. Using Web Services
- B. Events are collected with SmartWorkflow from Trouble Ticket systems
- C. Using Mgmt_cli tool
- D. Using CLISH
- E. Using SmartConsole GUI console
正解: B
解説:
References:
質問 69
The process on the Security Gateway sends logs to the fwd process on the Management Server via which 2 processes?
- A. fwd via cpd
- B. fwm via fwd
- C. fwd via cpm
- D. cpm via cpd
正解: B
質問 70
When installing a dedicated R80 SmartEvent server. What is the recommended size of the root partition?
- A. At least 20GB
- B. More than 10GB and less than 20GB
- C. Less than 20GB
- D. Any size
正解: A
質問 71
What happen when IPS profile is set in Detect Only Mode for troubleshooting?
- A. Automatically uploads debugging logs to Check Point Support Center
- B. It will generate Geo-Protection traffic
- C. Bypass licenses requirement for Geo-Protection control
- D. It will not block malicious traffic
正解: D
解説:
It is recommended to enable Detect-Only for Troubleshooting on the profile during the initial installation of IPS.
This option overrides any protections that are set to Prevent so that they will not block any traffic.
During this time you can analyze the alerts that IPS generates to see how IPS will handle network traffic, while avoiding any impact on the flow of traffic.
Reference:
https://sc1.checkpoint.com/documents/R76/CP_R76_IPS_AdminGuide/12750.htm
質問 72
Installations and upgrades with CPUSE require that the CPUSE agent is up-to-date. Usually the latest build is downloaded automatically. How can you verify the CPUSE agent build?
- A. In the Management Server or Gateway object in SmartConsole or by running the following command in CLISH: show installer status build
- B. In the Management Server or Gateway object in SmartConsole or by running the following command in CLISH: show installer agent
- C. In WebUI Status and Actions page or by running the following command in CLISH: show installer status build
- D. In WebUI Status and Actions page or by running the following command in CLISH: show installer status version
正解: C
質問 73
To fully enable Dynamic Dispatcher with Firewall Priority Queues on a Security Gateway, run the following command in Expert mode then reboot:
- A. fw ctl multik set_mode 1
- B. fw ctl Dynamic_Priority_Queue on
- C. fw ctl multik set_mode 9
- D. fw ctl Dynamic_Priority_Queue enable
正解: C
解説:
Explanation/Reference:
Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk105762
質問 74
You noticed that CPU cores on the Security Gateway are usually 100% utilized and many packets were dropped. You don't have a budget to perform a hardware upgrade at this time. To optimize drops you decide to use Priorities Queues and fully enable Dynamic Dispatcher. How can you enable them?
- A. fw ctl multik pq enable
- B. fw ctl multik set_mode 9
- C. fw ctl multik dynamic_dispatching on
- D. fw ctl multik dynamic_dispatching set_mode 9
正解: B
質問 75
Fill in the blank: The R80 feature _____ permits blocking specific IP addresses for a specified time period.
- A. Block Port Overflow
- B. Adaptive Threat Prevention
- C. Suspicious Activity Monitoring
- D. Local Interface Spoofing
正解: C
解説:
Explanation
Suspicious Activity Rules Solution
Suspicious Activity Rules is a utility integrated into SmartView Monitor that is used to modify access privileges upon detection of any suspicious network activity (for example, several attempts to gain unauthorized access).
The detection of suspicious activity is based on the creation of Suspicious Activity rules. Suspicious Activity rules are Firewall rules that enable the system administrator to instantly block suspicious connections that are not restricted by the currently enforced security policy. These rules, once set (usually with an expiration date), can be applied immediately without the need to perform an Install Policy operation.
質問 76
Which VPN routing option uses VPN routing for every connection a satellite gateway handles?
- A. To center and to other satellites through center
- B. To center only
- C. To satellites through center only
- D. To center, or through the center to other satellites, to Internet and other VPN targets
正解: D
解説:
Explanation/Reference: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk31021
質問 77
Which Check Point daemon monitors the other daemons?
- A. fwm
- B. cpd
- C. cpwd
- D. fwssd
正解: C
解説:
References:
質問 78
What is the command to show SecureXL status?
- A. fwaccel stat
- B. fwaccel -s
- C. fwaccel stats -m
- D. fwaccel status
正解: A
解説:
Explanation
To check overall SecureXL status:
[Expert@HostName]# fwaccel stat
References:
質問 79
Using ClusterXL, what statement is true about the Sticky Decision Function?
- A. Is configured using cpconfig
- B. All connections are processed and synchronized by the pivot
- C. Is only relevant when using SecureXL
- D. Can only be changed for Load Sharing implementations
正解: D
質問 80
As an administrator, you may be required to add the company logo to reports. To do this, you would save the logo as a PNG file with the name 'cover-company-logo.png' and then copy that image file to which directory on the SmartEvent server?
- A. $RTDIR/smartevent/conf
- B. $FWDIR/smartview/conf
- C. SFWDIR/smartevent/conf
- D. $RTDIR/smartview/conf
正解: D
解説:
References:
質問 81
Fill in the blank: The R80 utility fw monitor is used to troubleshoot ______________________.
- A. Traffic issues
- B. User data base corruption
- C. Phase two key negotiations
- D. LDAP conflicts
正解: A
解説:
Check Point's FW Monitor is a powerful built-in tool for capturing network traffic at the packet level. The FW Monitor utility captures network packets at multiple capture points along the FireWall inspection chains. These captured packets can be inspected later using the WireShark.
References:
質問 82
What Factors preclude Secure XL Templating?
- A. Source port Ranges/Encrypted Connections
- B. CoreXL
- C. ClusterXL in load sharing Mode
- D. IPS
正解: A
質問 83
In Advanced Permanent Tunnel Configuration, to set the amount of time the tunnel test runs without a response before the peer host is declared 'down', you would set the_________?
- A. life_sign_timeout
- B. life_sign_polling_interval
- C. life sign timeout
- D. life sign polling interval
正解: A
解説:
Explanation/Reference: https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm?
topic=documents/R77/CP_R77_VPN_AdminGuide/14018
質問 84
Ken wants to obtain a configuration lock from other administrator on R80 Security Management Server. He can do this via WebUI or via CLI.
Which command should he use in CLI? (Choose the correct answer.)
- A. The database feature has one command lock database override.
- B. The database feature has two commands lock database override and unlock database. Both will work.
- C. override database lock
- D. remove database lock
正解: B
質問 85
......
156-315.80試験問題集でベスト156-315.80試験問題を試そう:https://www.goshiken.com/CheckPoint/156-315.80-mondaishu.html