Welcome to CertificationDumps.com !

Are u looking to Pass your Certification Exam? Then you have came to the right place here you will find real exam questions of any exam taken from the testing center and aslo links to sites that sell them. So now passing your certification exam has become much easier than before all you have to do is memorize the questions you will see exactly the same questions in the real exam. In today world time is money so by this not only you save time plus you aslo save yourself the hassale of failing

November 22 2009

CheckPoint 156-315.65 Dumps

Check Point Certified Expert NGX R65

  • Exam Number/Code : 156-315.65
  • Exam Name : Check Point Certified Expert NGX R65
  • Questions and Answers : 193 Q&As

Download Pass4sure 156-315.65 Dumps from the link below
Download CertifyMe 156-315.65 Dumps from the link below
Download Testking 156-315.65 Dumps from the link below


Download CheckPoint 156-315.65 Dumps



PrepKing.com CheckPoint 156-315.65 Sample Questions

Exam : CheckPoint 156-315.65
Title : Check Point Certified Expert NGX R65

1. You are using SmartUpdate to fetch data and perform a remote upgrade of an NGX Security Gateway. Which of the following statements is FALSE?
A. If SmartDashboard is open during package upload and upgrade, the upgrade will fail.
B. A remote installation can be performed without the SVN Foundation package installed on a remote NG with Application Intelligence Security Gateway
C. SmartUpdate can query the SmartCenter Server and VPN-1 Gateway for product information
D. SmartUpdate can query license information running locally on the VPN-1 Gateway
Answer: B

2. What physical machine must have access to the UserCenter public IP when checking for new packages with SmartUpdate?
A. VPN-1 Security Gateway getting the new upgrade package
B. SmartUpdate installed SmartCenter Server PC
C. SmartUpdate Repository SQL database Server
D. SmartUpdate GUI PC
Answer: D

3. What port is used for communication to the UserCenter with SmartUpdate?
A. HTTP
B. HTTPS
C. TCP 8080
D. CPMI
Answer: B

4. You are a Security Administrator preparing to deploy a new HFA (Hotfix Accumulator) to ten Security Gateways at five geographically separated locations. What is the BEST method to implement this HFA?
A. Send a Certified Security Engineer to each site to perform the update
B. Use SmartUpdate to install the packages to each of the Security Gateways remotely
C. Use a SSH connection to SCP the HFA to each Security Gateway. Once copied locally, initiate a remote installation command and monitor the installation progress with SmartView Monitor.
D. Send a CDROM with the HFA to each location and have local personnel install it
Answer: B

5. What action can be run from SmartUpdate NGX R65?
A. remote_uninstall_verifier
B. upgrade_export
C. mds_backup
D. cpinfo
Answer: D

6. Choose all correct statements. SmartUpdate, located on a VPN-1 NGX SmartCenter Server, allows you to:
(1) Remotely perform a first time installation of VPN-1 NGX on a new machine
(2) Determine OS patch levels on remote machines
(3) Update installed Check Point and any OPSEC certified software remotely
(4) Update installed Check Point software remotely
(5) Track installed versions of Check Point and OPSEC products
(6) Centrally manage licenses
A. 4, 5, & 6
B. 2, 4, 5, & 6
C. 1 & 4
D. 1, 3, 4, & 6
Answer: B

7. What tools CANNOT be launched from SmartUpdate NGX R65?
A. cpinfo
B. SecurePlatform Web UI
C. Nokia Voyager
D. snapshot
Answer: D

8. What action CANNOT be run from SmartUpdate NGX R65?
A. Get all Gateway Data
B. Reboot gateway
C. Preinstall verifier…
D. Fetch sync status
Answer: D


Download CheckPoint 156-315.65 Dumps


November 22 2009

CheckPoint 156-915.1 Dumps

Accelerated CCSE 1.1 NGX

  • Exam Number/Code : 156-915.1
  • Exam Name : Accelerated CCSE 1.1 NGX
  • Questions and Answers : 160 Q&As

Download Pass4sure 156-915.1 Dumps from the link below
Download CertifyMe 156-915.1 Dumps from the link below
Download Testking 156-915.1 Dumps from the link below


Download CheckPoint 156-915.1 Dumps



PrepKing.com CheckPoint 156-915.1 Sample Questions

Exam : Check Point 156-915.1
Title : Accelerated CCSE 1.1 NGX

1. When restoring NGX using the upgrade_import command, which of the following items are NOT restored?
A. Security Policies
B. Global properties
C. Licenses
D. User groups
E. Route tables
Answer: E

2. In a Management High Availablility (HA) configuration, you can configure synchronization to occur automatically, when:
1. The Security Policy is installed.
2. The Security Policy is saved.
3. The Security Administrator logs in to the secondary SmartCenter Server, and changes its status to active.
4. A scheduled event occurs.
5. The user database is installed.
Select the BEST response for the synchronization sequence. Choose one.
A. 1,2,3
B. 1,2,3,4
C. 1,3,4
D. 1,2,5
E. 1,2,4
Answer: E

3. Your organization’s security infrastructure separates Security Gateways geographically. You must request a central license for one remote Security Gateway. How would you request and apply the license? Request a central license:
A. using the remote Gateway’s IP address. Apply the license locally with the cplic put command.
B. for the Gateways’ IP address. Apply the license on the SmartCenter Server with the cprlic put command.
C. using the remote Gateway’s IP address. Attach the license to the remote Gateway via SmartUpdate.
D. using your SmartCenter Server’s IP address. Attach the license to the remote Gateway via SmartUpdate.
E. using the SmartCenter Server’s IP address. Apply the license locally on the remote Gateway with the cplic put command.
Answer: D

4. After importing the NGX schema into an LDAP server, what should you enable?
Schema checking
A. Encryption
B. UserAuthority
C. ConnectControl
D. Secure Internal Communications
Answer: A

5. Your organization has many VPN-1 Edge gateways at various branch offices, to allow VPN-1 SecureClient users to access company resources. For security reasons, your organization’s Security Policy requires all Internet traffic initiated behind the VPN-1 Edge gateways first be inspected by your headquarters’ VPN-1 Pro Security Gateway. How do you configure VPN routing in this star VPN Community?
A. To the Internet and other targets only
B. To the center and other satellites, through the center
C. To the center only
D. To the center, or through the center to other satellites, then to the Internet and other VPN targets
Answer: D

6. Your VPN Community includes three Security Gateways. Each Gateway has its own internal network defined as a VPN Domain. You must test the VPN-1 NGX route-based VPN feature, without stopping the VPN. What is the correct order of steps?
A. 1. Add a new interface on each Gateway.
2. Remove the newly added network from the current VPN Domain for each Gateway.
3. Create VTIs on each Gateway, to point to the other two peers
4. Enable advanced routing on all three Gateways.
B. 1. Add a new interface on each Gateway.
2. Remove the newly added network from the current VPN Domain in each gateway object.
3. Create VPN Tunnel Interfaces (VTI) on each gateway object, to point to the other two peers.
4. Add static routes on three Gateways, to route the new network to each peer”s VTI interface.
C. 1. Add a new interface on each Gateway.
2. Add the newly added network into the existing VPN Domain for each Gateway.
3. Create VTIs on each gateway object, to point to the other two peers.
4. Enable advanced routing on all three Gateways.
D. 1. Add a new interface on each Gateway.
2. Add the newly added network into the existing VPN Domain for each gateway object.
3. Create VTIs on each gateway object, to point to the other two peers.
4. Add static routes on three Gateways, to route the new networks to each peer’s VTI interface.
Answer: B

7. Steve tries to configure Directional VPN Rule Match in the Rule Base. But the Match column does not have the option to see the Directional Match. Steve sees the following screen. What is the problem?
A. Steve must enable directional_match(true) in the objectes_5_0.C file on SmartCenter Server.
B. Steve must enable Advanced Routing on each Security Gateway.
C. Steve must enable VPN Directional Match on the VPN Advanced screen, in Global properties.
D. Steve must enable a dynamic-routing protocol, such as OSPF, on the Gateways.
E. Steve must enable VPN Directional Match on the gateway object??s VPN tab.
Answer: C

8. Eric wants to see all URLs’ full destination paths in the SmartView Tracker logs, not just the fully qualified domain name of the Web servers. For example, the information filed of a log entry displays the URL http: //hp.msn.com/css/home/hpcl1012.css. How can Eric best customize SmartView Tracker to see the logs he wants? Configure the URI resource, and select:
A. “transparent” as the connection method
B. “tunneling” as the connection method
C. “optimize URL logging”; use the URI resource in the rule, with action “accept”
D. “Enforce URL capability”; use the URI resource in the rule, with action “accept”
Answer: C


Download CheckPoint 156-915.1 Dumps


November 22 2009

CheckPoint 156-315.1 Dumps

Check Point Certified Security Expert NGX

  • Exam Number/Code : 156-315.1
  • Exam Name : Check Point Certified Security Expert NGX
  • Questions and Answers : 142 Q&As

Download Pass4sure 156-315.1 Dumps from the link below
Download CertifyMe 156-315.1 Dumps from the link below
Download Testking 156-315.1 Dumps from the link below


Download CheckPoint 156-315.1 Dumps



PrepKing.com CheckPoint 156-315.1 Sample Questions

Exam : Check Point 156-315.1
Title : Check Point Certified Security Expert NGX

1. Which of the following QoS rule-action properties is an Advanced action type, only available in Traditional mode?
A. Guarantee Allocation
B. Rule weight
C. Apply rule only to encrypted traffic
D. Rule limit
E. Rule guarantee
Answer: A

2. You are preparing a lab for a ClusterXL environment, with the following topology:
Vip internal cluster IP = 172.16.10.1; Vip external cluster IP = 192.168.10.3
Cluster Member 1: four NICs, three enabled: qfe0: 192.168.10.1/24, qfe1: 10.10.10.1/24, qfe2: 172.16.10.1/24
Cluster Member 2: five NICs, three enabled; hme0: 192.168.10.2/24, eth1: 10.10.10.2/24, eth2: 172.16.10.2/24
Member Network tab on internal-cluster interface: is 10.10.10.0, 255.255.255.0
SmartCenter Pro Server: 172.16.10.3
External interfaces 192.168.10.1 and 192.168.10.2 connect to a Virtual Local Area Network (VLAN) switch. The upstream router connects to the same VLAN switch. Internal interfaces 10.10.10.1 and 10.10.10.2 connect to a hub. There is no other machine in the 10.10.10.0 network. 172.19.10.0 is the synchronization network. What is the problem with this configuration?
A. The SmartCenter Pro Server cannot be in the synchronization network.
B. There is no problem with this configuration. It is correct.
C. Members do not have the same number of NICs.
D. The internal network does not have a third cluster member.
E. Cluster members cannot use the VLAN switch. They must use hubs.
Answer: B

3. Which of the following commands shows full synchronization status?
A. cphaprob -i list
B. cphastop
C. fw ctl pstat
D. cphaprob -a if
E. fw hastat
Answer: A

4. The following rule contains an FTP resource object in the Service field:
Source: local_net
Destination: Any
Service: FTP-resource object
Action: Accept
How do you define the FTP Resource Properties > Match tab to prevent internal users from sending corporate files to external FTP servers, while allowing users to retrieve files?
A. Enable the “Get” method on the match tab.
B. Disable “Get” and “Put” methods on the Match tab.
C. Enable the “Put” and “Get” methods.
D. Enable the “Put” method only on the match tab.
E. Disable the “Put” method globally.
Answer: A

5. Greg is creating rules and objects to control VoIP traffic in his organization, through a VPN-1 NGX Security Gateway. Greg creates VoIP Domain SIP objects to represent each of his organization’s three SIP gateways. Greg then creates a simple group to contain the VoIP Domain SIP objects. When Greg attempts to add the VoIP Domain SIP objects to the group, they are not listed. What is the problem?
A. The related end-points domain specifies an address range.
B. VoIP Domain SIP objects cannot be placed in simple groups.
C. The installed VoIP gateways specify host objects.
D. The VoIP gateway object must be added to the group, before the VoIP Domain SIP object is eligible to be added to the group.
E. The VoIP Domain SIP object’s name contains restricted characters.
Answer: B

6. You want to upgrade a SecurePlatform NG with Application Intelligence (AI) R55 Gateway to SecurePlatform NGX R60 via SmartUpdate. Which package is needed in the repository before upgrading?
A. SVN Foundation and VPN-1 Express/Pro
B. VPN-1 and FireWall-1
C. SecurePlatform NGX R60
D. SVN Foundation
E. VPN-1 Pro/Express NGX R60
Answer: C

7. You are preparing to configure your VoIP Domain Gatekeeper object. Which two other objects should you have created first?
A. An object to represent the IP phone network, AND an object to represent the host on which the proxy is installed
B. An object to represent the PSTN phone network, AND an object to represent the IP phone network
C. An object to represent the IP phone network, AND an object to represent the host on which the gatekeeper is installed
D. An object to represent the Q.931 service origination host, AND an object to represent the H.245 termination host
E. An object to represent the call manager, AND an object to represent the host on which the transmission router is installed
Answer: C

8. Your current VPN-1 NG with Application Intelligence (AI) R55 stand-alone VPN-1 Pro Gateway and SmartCenter Server run on SecurePlatform. You plan to implement VPN-1 NGX in a distributed environment, where the existing machine will be the SmartCenter Server, and a new machine will be the VPN-1 Pro Gateway only. You need to migrate the NG with AI R55 SmartCenter Server configuration, including such items as Internal Certificate Authority files, databases, and Security Policies.
How do you request a new license for this VPN-1 NGX upgrade?
A. Request a VPN-1 NGX SmartCenter Server license, using the new machine’s IP address. Request a new local license for the NGX VPN-1 Pro Gateway.
B. Request a VPN-1 NGX SmartCenter Server license, using the new machine’s IP address. Request a new central license for the NGX VPN-1 Pro Gateway.
C. Request a new VPN-1 NGX SmartCenter Server license, using the NG with AI SmartCenter Server IP address. Request a new central license for the NGX VPN-1 Pro Gateway.
D. Request a VPN-1 NGX SmartCenter Server license, using the NG with AI SmartCenter Server IP address. Request a new central license for the NGX VPN-1 Pro Gateway, licensed for the existing SmartCenter Server IP address.
Answer: D


Download CheckPoint 156-315.1 Dumps


November 22 2009

CheckPoint 156-915.65 Dumps

Accelerated CCSE NGX R65

  • Exam Number/Code : 156-915.65
  • Exam Name : Accelerated CCSE NGX R65
  • Questions and Answers : 200 Q&As

Download Pass4sure CheckPoint 156-915.65 Dumps from the link below
Download CertifyMe CheckPoint 156-915.65 Dumps from the link below
Download Testking CheckPoint 156-915.65 Dumps from the link below


Download CheckPoint 156-915.65 Dumps


November 22 2009

CheckPoint 156-215.65 Dumps

Check Point Security Administration I NGX

  • Exam Number/Code : 156-215.65
  • Exam Name : Check Point Security Administration I NGX
  • Questions and Answers : 329 Q&As

Download Pass4sure 156-215.65 Dumps from the link below
Download CertifyMe 156-215.65 Dumps from the link below
Download Testking 156-215.65 Dumps from the link below


Download CheckPoint 156-215.65 Dumps



PrepKing.com CheckPoint 156-215.65 Sample Questions

Exam : Check Point 156-215.65
Title : Check Point Security Administration I NGX

1. The customer has a small Check Point installation which includes one Linux Enterprise 3.0 server working as SmartConsole and a second server running Windows 2003 working as both SmartCenter server and the Security Gateway. This is an example of:
A. Hybrid Installation
B. Stand-Alone Installation
C. Distributed Installation
D. Unsupported configuration
Answer: D

2. Which of the following statements about Bridge mode are TRUE?
A. Assuming a new installation, bridge mode requires changing the existing IP routing of the network.
B. All ClusterXL modes are supported.
C. When managing a Security Gateway in Bridge mode, it is possible to use a bridge interface for Network Address Translation.
D. A bridge must be configured with a pair of interfaces.
Answer: D

3. Some control operations and user interactions are difficult or impossible to execute at the kernel level. The _________ component provides a mechanism for such operations.
A. encryption
B. daemon
C. management
D. security
Answer: B

4. The customer has a small Check Point installation which includes one Window XP workstation working as SmartConsole , one Solaris server working as SmartCenter, and a third server running SecurePlatform working as Security Gateway. This is an example of:
A. Distributed Installation
B. Hybrid Installation
C. Unsupported configuration
D. Stand-Alone Installation
Answer: A

5. Of the three mechanisms Check Point uses for controlling traffic, which enables firewalls to incorporate layer 4 awareness in packet inspection?
A. Stateful Inspection
B. SmartDefense
C. Application Intelligence
D. Packet filtering
Answer: A

6. The customer has a small Check Point installation which includes one Window 2003 server working as SmartConsole and a second server running SPLAT working as both SmartCenter server and the Security Gateway. This is an example of:
A. Distributed Installation
B. Unsupported configuration
C. Stand-Alone Installation
D. Hybrid Installation
Answer: C

7. Which statement below is TRUE about management plug-ins?
A. The plug-in is a package installed on the Security Gateway.
B. Using a plug-in offers full central management only if special licensing is applied to specific features of the plug-in.
C. A management plug-in interacts with a SmartCenter Server to provide new features and support for new products.
D. Installing a management plug-in is just like an upgrade process. (It overwrites existing components.)
Answer: C

8. Which SmartConsole component can Administrators use to track remote administrative activities?
A. The WebUI
B. SmartView Monitor
C. Eventia Reporter
D. SmartView Tracker
Answer: D


Download CheckPoint 156-215.65 Dumps


November 22 2009

CheckPoint 156-215.1 Dumps

Check Point Certified Security Administrator NGX

  • Exam Number/Code : 156-215.1
  • Exam Name : Check Point Certified Security Administrator NGX
  • Questions and Answers : 254 Q&As

Download Pass4sure 156-215.1 Dumps from the link below
Download CertifyMe 156-215.1 Dumps from the link below
Download Testking 156-215.1 Dumps from the link below


Download CheckPoint 156-215.1 Dumps



PrepKing.com CheckPoint 156-215.1 Sample Questions

Exam : Check Point 156-215.1
Title : Check Point Certified Security Administrator NGX

1. In SmartDashboard, you configure 45 MB as the required free hard-disk space to accommodate logs. What can you do to keep old log files, when free space falls below 45 MB?
A. Define a secondary SmartCenter Server as a log server, to transfer the old logs.
B. Configure a script to archive old logs to another directory, before old log files are deleted.
C. Do nothing. Old logs are deleted, until free space is restored.
D. Use the fwm logexport command to export the old log files to other location.
E. Do nothing. The SmartCenter Server archives old logs to another directory.
Answer: B

2. In NGX, what happens if a Distinguished Name (DN) is NOT found in LDAP?
A. NGX takes the common-name value from the Certificate subject, and searches the LDAP account unit for a matching user id.
B. NGX searches the internal database for the username.
C. The Security Gateway uses the subject of the Certificate as the DN for the initial lookup.
D. If the first request fails or if branches do not match, NGX tries to map the identity to the user id attribute.
E. When users authenticate with valid Certificates, the Security Gateway tries to map the identities with users registered in the external LDAP user database.
Answer: B

3. If a digital signature is used to achieve both data-integrity checking and verification of sender, digital signatures are only used when implementing:
A. A symmetric encryption algorithm.
B. CBL-DES.
C. ESP.
D. An asymmetric encryption algorithm.
E. Triple DES.
Answer: D

4. Frank wants to know why users on the corporate network cannot receive multicast transmissions from the Internet. An NGX Security Gateway protects the corporate network from the Internet. Which of the following is a possible cause for the connection problem?
A. NGX does not support multicast routing protocols and streaming media through the Security Gateway.
B. Frank did not install the necessary multicast license with SmartUpdate, when he upgraded to NGX.
C. The Multicast Rule is below the Stealth Rule. NGX can only pass multicast traffic, if the Multicast Rule is above the Stealth Rule.
D. Multicast restrictions are not configured properly on the corporate internal network interface properties of the Security Gateway object.
E. Anti-spoofing is enabled. NGX cannot pass multicast traffic, if anti-spoofing is enabled.
Answer: D

5. Brianna has three servers located in a DMZ, using private IP addresses. She wants internal users from 10.10.10.x to access the DMZ servers by public IP addresses. Internal_net 10.10.10.x is configured for Hide NAT behind the Security Gateway’s external interface.
What is the best configuration for 10.10.10.x users to access the DMZ servers, using the DMZ servers’ public IP addresses?
A. Configure automatic Static NAT rules for the DMZ servers.
B. Configure manual Static NAT rules to translate the DMZ servers, when connecting to the Internet.
C. Configure manual static NAT rules to translate the DMZ servers, when the source is the internal network 10.10.10.x.
D. Configure Hide NAT for the DMZ network behind the DMZ interface of the Security Gateway, when connecting to internal network 10.10.10.x.
E. Configure Hide NAT for 10.10.10.x behind DMZ’s interface, when trying to access DMZ servers.
Answer: C

6. Larry is the Security Administrator for a software-development company. To isolate the corporate network from the developers’ network, Larry installs an internal Security Gateway. Larry wants to optimize the performance of this Gateway. Which of the following actions is most likely to improve the Gateway’s performance?
A. Remove unused Security Policies from Policy Packages.
B. Clear all Global Properties check boxes, and use explicit rules.
C. Use groups within groups in the manual NAT Rule Base.
D. Put the least-used rules at the top of the Rule Base.
E. Use domain objects in rules, where possible.
Answer: A

7. Gary is a Security Administrator in a small company. He needs to determine if the company’s Web servers are accessed for an excessive number of times from the same host. How would he configure this setting in SmartDefense?
A. Successive multiple connections
B. HTTP protocol inspection
C. Successive alerts
D. General HTTP worm catcher
E. Successive DoS attacks
Answer: A

8. You are setting up a Virtual Private Network, and must select an encryption scheme. Network performance is a critical issue – even more so than the security of the packet. Which encryption scheme would you select?
A. In-place encryption
B. Tunneling mode encryption
C. Either one will work without compromising performance
Answer: A


Download CheckPoint 156-215.1 Dumps


November 22 2009

CheckPoint 156-510 Dumps

VPN-1/FireWall-1 Management III

  • Exam Number/Code : 156-510
  • Exam Name : VPN-1/FireWall-1 Management III
  • Questions and Answers : 168 Q&As

Download Pass4sure 156-510 Dumps from the link below
Download CertifyMe 156-510 Dumps from the link below
Download Testking 156-510 Dumps from the link below


Download CheckPoint 156-510 Dumps



PrepKing.com CheckPoint 156-510 Sample Questions

November 22 2009

CheckPoint 156-315 Dumps

Check Point Certified Security Expert NGX

  • Exam Number/Code : 156-315
  • Exam Name : Check Point Certified Security Expert NGX
  • Questions and Answers : 142 Q&As

Download Pass4sure 156-315 Dumps from the link below
Download CertifyMe 156-315 Dumps from the link below
Download Testking 156-315 Dumps from the link below


Download CheckPoint 156-315 Dumps



PrepKing.com CheckPoint 156-315 Sample Questions

Exam : Check Point 156-315
Title : Check Point Certified Security Expert NGX

1. You are preparing to configure your VoIP Domain Gatekeeper object. Which two other objects should you have created first?
A. An object to represent the IP phone network, AND an object to represent the host on which the proxy is installed
B. An object to represent the PSTN phone network, AND an object to represent the IP phone network
C. An object to represent the IP phone network, AND an object to represent the host on which the gatekeeper is installed
D. An object to represent the Q.931 service origination host, AND an object to represent the H.245 termination host
E. An object to represent the call manager, AND an object to represent the host on which the transmission router is installed
Answer: C

2. The following rule contains an FTP resource object in the Service field:
Source: local_net
Destination: Any
Service: FTP-resource object
Action: Accept
How do you define the FTP Resource Properties > Match tab to prevent internal users from sending corporate files to external FTP servers, while allowing users to retrieve files?
A. Enable the “Get” method on the match tab.
B. Disable “Get” and “Put” methods on the Match tab.
C. Enable the “Put” and “Get” methods.
D. Enable the “Put” method only on the match tab.
E. Disable the “Put” method globally.
Answer: A

3. Greg is creating rules and objects to control VoIP traffic in his organization, through a VPN-1 NGX Security Gateway. Greg creates VoIP Domain SIP objects to represent each of his organization’s three SIP gateways. Greg then creates a simple group to contain the VoIP Domain SIP objects. When Greg attempts to add the VoIP Domain SIP objects to the group, they are not listed. What is the problem?
A. The related end-points domain specifies an address range.
B. VoIP Domain SIP objects cannot be placed in simple groups.
C. The installed VoIP gateways specify host objects.
D. The VoIP gateway object must be added to the group, before the VoIP Domain SIP object is eligible to be added to the group.
E. The VoIP Domain SIP object’s name contains restricted characters.
Answer: B

4. Which of the following commands shows full synchronization status?
A. cphaprob -i list
B. cphastop
C. fw ctl pstat
D. cphaprob -a if
E. fw hastat
Answer: A

5. You want to upgrade a SecurePlatform NG with Application Intelligence (AI) R55 Gateway to SecurePlatform NGX R60 via SmartUpdate. Which package is needed in the repository before upgrading?
A. SVN Foundation and VPN-1 Express/Pro
B. VPN-1 and FireWall-1
C. SecurePlatform NGX R60
D. SVN Foundation
E. VPN-1 Pro/Express NGX R60
Answer: C

6. Your current VPN-1 NG with Application Intelligence (AI) R55 stand-alone VPN-1 Pro Gateway and SmartCenter Server run on SecurePlatform. You plan to implement VPN-1 NGX in a distributed environment, where the existing machine will be the SmartCenter Server, and a new machine will be the VPN-1 Pro Gateway only. You need to migrate the NG with AI R55 SmartCenter Server configuration, including such items as Internal Certificate Authority files, databases, and Security Policies.
How do you request a new license for this VPN-1 NGX upgrade?
A. Request a VPN-1 NGX SmartCenter Server license, using the new machine’s IP address. Request a new local license for the NGX VPN-1 Pro Gateway.
B. Request a VPN-1 NGX SmartCenter Server license, using the new machine’s IP address. Request a new central license for the NGX VPN-1 Pro Gateway.
C. Request a new VPN-1 NGX SmartCenter Server license, using the NG with AI SmartCenter Server IP address. Request a new central license for the NGX VPN-1 Pro Gateway.
D. Request a VPN-1 NGX SmartCenter Server license, using the NG with AI SmartCenter Server IP address. Request a new central license for the NGX VPN-1 Pro Gateway, licensed for the existing SmartCenter Server IP address.
Answer: D

7. You are preparing a lab for a ClusterXL environment, with the following topology:
Vip internal cluster IP = 172.16.10.1; Vip external cluster IP = 192.168.10.3
Cluster Member 1: four NICs, three enabled: qfe0: 192.168.10.1/24, qfe1: 10.10.10.1/24, qfe2: 172.16.10.1/24
Cluster Member 2: five NICs, three enabled; hme0: 192.168.10.2/24, eth1: 10.10.10.2/24, eth2: 172.16.10.2/24
Member Network tab on internal-cluster interface: is 10.10.10.0, 255.255.255.0
SmartCenter Pro Server: 172.16.10.3
External interfaces 192.168.10.1 and 192.168.10.2 connect to a Virtual Local Area Network (VLAN) switch. The upstream router connects to the same VLAN switch. Internal interfaces 10.10.10.1 and 10.10.10.2 connect to a hub. There is no other machine in the 10.10.10.0 network. 172.19.10.0 is the synchronization network. What is the problem with this configuration?
A. The SmartCenter Pro Server cannot be in the synchronization network.
B. There is no problem with this configuration. It is correct.
C. Members do not have the same number of NICs.
D. The internal network does not have a third cluster member.
E. Cluster members cannot use the VLAN switch. They must use hubs.
Answer: B

8. Which of the following QoS rule-action properties is an Advanced action type, only available in Traditional mode?
A. Guarantee Allocation
B. Rule weight
C. Apply rule only to encrypted traffic
D. Rule limit
E. Rule guarantee
Answer: A


Download CheckPoint 156-315 Dumps


November 22 2009

CheckPoint 156-310 Dumps

Check Point CCSE NG

  • Exam Number/Code : 156-310
  • Exam Name : Check Point CCSE NG
  • Questions and Answers : 398 Q&As

Download Pass4sure CheckPoint 156-310 Dumps from the link below
Download CertifyMe CheckPoint 156-310 Dumps from the link below
Download Testking CheckPoint 156-310 Dumps from the link below


Download CheckPoint 156-310 Dumps


November 22 2009

CheckPoint 156-215 Dumps

Check Point Security Administration NGX

  • Exam Number/Code : 156-215
  • Exam Name : Check Point Security Administration NGX
  • Questions and Answers : 255 Q&As

Download Pass4sure 156-215 Dumps from the link below
Download CertifyMe 156-215 Dumps from the link below
Download Testking 156-215 Dumps from the link below


Download CheckPoint 156-215 Dumps



PrepKing.com CheckPoint 156-215 Sample Questions

Exam : Check Point 156-215
Title : Check Point Security Administration NGX

1. Configure the gateway object with the host name and IP addresses for the remote site.
4. Click the Communication button in the gateway object’s general screen, enter the activation key, and click Initialize and OK.
5. Install the Security Policy.
Select the best response.
A. 1, 3, 2, 4, 5
B. 2, 3, 1, 4, 5
C. 3, 4, 5
D. 1, 2, 4, 3
Answer: C

2. Install the Security Policy.
Select the best response.
A. 1, 3, 2, 4, 5
B. 2, 3, 1, 4, 5
C. 3, 4, 5
D. 1, 2, 4, 3
Answer: C

3. Click the Communication button in the gateway object’s general screen, enter the activation key, and click Initialize and OK.
5. Install the Security Policy.
Select the best response.
A. 1, 3, 2, 4, 5
B. 2, 3, 1, 4, 5
C. 3, 4, 5
D. 1, 2, 4, 3
Answer: C

4. Initialize SIC for the Gateway object on the SmartCenter Server.
3. Configure the gateway object with the host name and IP addresses for the remote site.
4. Click the Communication button in the gateway object’s general screen, enter the activation key, and click Initialize and OK.
5. Install the Security Policy.
Select the best response.
A. 1, 3, 2, 4, 5
B. 2, 3, 1, 4, 5
C. 3, 4, 5
D. 1, 2, 4, 3
Answer: C

5. Which SmartConsole tool would you use to verify the installed Security Policy name?
Select the best response.
A. SmartUpdate
B. SmartView Monitor
C. Eventia Reporter
D. SmartView Status
Answer: B

6. The third shift Administrator was updating SmartCenter Access settings in Global Properties. He managed to lock all of the administrators out of their accounts. How can you unlock these accounts?
Select the best response.
A. Type fwm lock_admin ua from the command line of the SmartCenter Server.
B. Type fwm unlock_admin ua from the command line of the SmartCenter Server.
C. Type fwm unlock_admin ua from the command line of the Security Gateway.
D. Clear the “locked” box of the user’s General Properties in SmartDashboard.
Answer: A

7. You installed SmartCenter Server on a computer running SecurePlatform in the MegaCorp home office. You use IP address 10. You also installed the Security Gateway on a second SecurePlatform computer, which you plan to ship to another Administrator at a MegaCorp hub office. What is the correct order for setting up SIC on the Gateway before shipping it?
1. Run cpconfig on the Gateway, select “Secure Internal Communication”, enter the activation key, and reconfirm.
2. Initialize SIC for the Gateway object on the SmartCenter Server.
3. Configure the gateway object with the host name and IP addresses for the remote site.
4. Click the Communication button in the gateway object’s general screen, enter the activation key, and click Initialize and OK.
5. Install the Security Policy.
Select the best response.
A. 1, 3, 2, 4, 5
B. 2, 3, 1, 4, 5
C. 3, 4, 5
D. 1, 2, 4, 3
Answer: C

8. The third shift Administrator was updating SmartCenter Access settings in Global Properties. He managed to lock himself out of his account. How can you unlock this account?
Select the best response.
A. Type fwm lock_admin u from the command line of the SmartCenter Server.
B. Type fwm unlock_admin u from the command line of the Security Gateway.
C. Delete the file admin.lock in the $FWDIR/tmp/ directory of the SmartCenter Server.
D. Type fwm unlock_admin u from the command line of the SmartCenter Server.
Answer: A


Download CheckPoint 156-215 Dumps


prepking

Tag Cloud

Adobe