Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Checkpoint CCSA R81 156-215.81 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 156-215.81 Premium Access

View all detail and faqs for the 156-215.81 exam


792 Students Passed

86% Average Score

94% Same Questions
Viewing page 6 out of 13 pages
Viewing questions 51-60 out of questions
Questions # 51:

Which icon in the WebUI indicates that read/write access is enabled?

Options:

A.

Eyeglasses

B.

Pencil

C.

Padlock

D.

Book

Questions # 52:

Identity Awareness lets an administrator easily configure network access and auditing based on three items Choose the correct statement.

Options:

A.

Network location, the identity of a user and the active directory membership.

B.

Network location, the identity of a user and the identity of a machine.

C.

Network location, the telephone number of a user and the UID of a machine

D.

Geographical location, the identity of a user and the identity of a machine

Questions # 53:

True or False: In R80, more than one administrator can login to the Security Management Server with write permission at the same time.

Options:

A.

False, this feature has to be enabled in the Global Properties.

B.

True, every administrator works in a session that is independent of the other administrators.

C.

True, every administrator works on a different database that is independent of the other administrators.

D.

False, only one administrator can login with write permission.

Questions # 54:

What is the purpose of the Stealth Rule?

Options:

A.

To prevent users from directly connecting to a Security Gateway.

B.

To reduce the number of rules in the database.

C.

To reduce the amount of logs for performance issues.

D.

To hide the gateway from the Internet.

Questions # 55:

What is the default shell for the Gaia command line interface?

Options:

A.

Admin

B.

Clish

C.

Expert

D.

Bash

Questions # 56:

If an administrator wants to restrict access to a network resource only allowing certain users to access it, and only when they are on a specific network what is the best way to accomplish this?

Options:

A.

Create an inline layer where the destination is the target network resource Define sub-rules allowing only specific sources to access the target resource

B.

Use a "New Legacy User at Location", specifying the LDAP user group that the users belong to, at the desired location

C.

Create a rule allowing only specific source IP addresses access to the target network resource.

D.

Create an Access Role object, with specific users or user groups specified, and specific networks defined Use this access role as the "Source" of an Access Control rule

Questions # 57:

You are going to perform a major upgrade. Which back up solution should you use to ensure your database can be restored on that device?

Options:

A.

backup

B.

logswitch

C.

Database Revision

D.

snapshot

Questions # 58:

You have discovered suspicious activity in your network. What is the BEST immediate action to take?

Options:

A.

Create a policy rule to block the traffic.

B.

Create a suspicious action rule to block that traffic.

C.

Wait until traffic has been identified before making any changes.

D.

Contact ISP to block the traffic.

Questions # 59:

Which of the following statements about Site-to-Site VPN Domain-based is NOT true?

    Route-based— The Security Gateways will have a Virtual Tunnel Interface (VTI) for each VPN Tunnel with a peer VPN Gateway. The Routing Table can have routes to forward traffic to these VTls. Any traffic routed through a VTI is automatically identified as VPN Traffic and is passed through the VPN Tunnel associated with the VTI.

Options:

A.

Domain-based— VPN domains are pre-defined for all VPN Gateways. A VPN domain is a service or user that can send or receive VPN traffic through a VPN Gateway.

B.

Domain-based— VPN domains are pre-defined for all VPN Gateways. A VPN domain is a host or network that can send or receive VPN traffic through a VPN Gateway.

C.

Domain-based— VPN domains are pre-defined for all VPN Gateways. When the Security Gateway encounters traffic originating from one VPN Domain with the destination to a VPN Domain of another VPN Gateway, that traffic is identified as VPN traffic and is sent through the VPN Tunnel between the two Gateways.

Questions # 60:

For Automatic Hide NAT rules created by the administrator what is a TRUE statement?

Options:

A.

Source Port Address Translation (PAT) is enabled by default

B.

Automate NAT rules are supported for Network objects only.

C.

Automatic NAT rules are supported for Host objects only.

D.

Source Port Address Translation (PAT) is disabled by default

Viewing page 6 out of 13 pages
Viewing questions 51-60 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.