Latest 156-215 Real Exam Download 151-161

Ensurepass

QUESTION 151

Which of the following are available SmartConsole clients which can be installed from the R65 NGX Windows CD? Read all answers and select the most complete and valid list.

 

A. SmartView Tracker, CPINFO, SmartUpdate

B. Security Policy Editor, Log Viewer, Real Time Monitor GUI

C. SmartView Tracker, SmartDashboard, CPINFO, SmartUpdate, SmartView Status

D. SmartView Tracker, SmartDashboard, SmartLSM, SmartView Monitor

 

Answer: D

 

 

QUESTION 152

Which R65 SmartConsole tool would you use to verify the current installed Security Policy name on a Security Gateway?

 

A. SmartView Status

B. SmartUpdate

C. SmartView Monitor

D. None,SmartConsole applications only communicate with the SmartCenter Server.

 

Answer: C

 

 

QUESTION 153

Which R65 SmartConsole tool would you use to verify the installed Security Policy name on a Security Gateway?

 

A. SmartUpdate

B. None,SmartConsole applications only communicate with the SmartCenter Server.

C. SmartView Server

D. SmartView Tracker

 

Answer: D

 

 

QUESTION 154

Which SmartConsole tool would you use to see the last policy pushed in the audit log?

 

A. SmartView Status

B. SmartView Server

C. SmartView Monitor

D. SmartView Tracker

 

Answer: D

 

 

QUESTION 155

VPN-1 NGX R65’s INSPECT Engine inserts itself into the kernel between which two layers of the OSI model?

 

A. Presentation and Application

B. Session and Transport

C. Data and Network

D. Physical and Data

 

Answer: C

 

 

QUESTION 156

Your current security scenario gives you the option to choose between a stand-alone installation and a distributed installation. Which of the following factors would cause you to decide in favor of the distributed installation?

 

A.      You are forced to use Windows as operating system.

B.      You cannot upgrade software packages on a stand-alone Security Gateway viaSmartUpdate.

C.      Clientless VPN would not work in a stand-alone installation.

D.      TheSmartCenter Server must be a secondary server. You are forced to install a separate primary server.

 

Answer: B

 

 

QUESTION 157

Upon checking SmartView Monitor, you find the following Critical Problem notification.What is the reason?

clip_image002

 

A.      No Security Policy installed on the Security Gateway

B.      Time not synchronized between theSmartCenter Server and Security Gateway

C.      No Secure Internal Communications established between theSmartCenter Server and Security Gateway

D.      Version mismatch between theSmartCenter Server and Security Gateway

 

Answer: A

 

 

QUESTION 158

Your perimeter Security Gateway’s external IP is 200.200.200.3. Your network diagram shows:Required: Allow only network 192.168.10.0 and 192.168.20.0 to go out to Internet, using

200.200.200.5.

The local network 192.168.1.0/24 needs to use 200.200.200.3 to go out to the Internet.

Assuming you enable all the settings in the NAT page of Global Properties, how do you achieve this requirement?

clip_image004

A.      Create two network objects: 192.168.10.0/24 and 192.168.20.0/24. Add the two network objects to a group object. Create a manual NAT rule like the following: Original source – group object; Destination ?any; Service ?any; Translated source – 200.200.200.5; Destination ?original; Service ?original.

B.      Create an Address Range object, starting from 192.168.10.1 to 192.168.20.254. Enable Hide NAT on the NAT page of the Address range object. Enter Hiding IP address 200.200.200.5. Add an ARP entry for 200.200.200.5 for the MAC address of 200.200.200.3.

C.      Create a network object 192.168.0.0/16. Enable Hide NAT on the NAT page. Enter

200.200.200.5 as hiding IP address. Add an ARP entry for 200.200.200.5 for the MAC address of 200.200.200.3.

D.      Create network objects for 192.168.10.0/24 and 192.168.20.0/24. Enable Hide NAT on both network objects, using 200.200.200.5 as hiding IP address. Add an ARP entry for 200.200.200.3 for the MAC address of 200.200.200.5.

 

Answer: B

 

 

 

 

QUESTION 159

Assuming all connections that are allocated bandwidth in your Check Point QoS Rule Base are open, what would be the corresponding bandwidth percentage of the Kazza Rule in the following example?

clip_image006

A. 5%

B. 20%

C. 8%

D. 14%

 

Answer: D

 

 

 

 

QUESTION 160

Assuming all connections that are allocated bandwidth in your Check Point QoS Rule Base are open, what would be the corresponding bandwidth percentage of the Kazza Rule in the following example?

clip_image008

 

A. 8%

B. 5%

C. 14%

D. 20%

 

Answer: C

 

 

QUESTION 161

Review the following rules. Assume domain UDP is enabled in the implied rules:What happens when a user from the internal network tries to browse to the Internet using HTTP? The:

clip_image010

A. user’s connection is dropped by the last implied rule.

B. user can connect to the Internet successfully after being authenticated successfully.

C. user can go to the Internet, without being prompted for authentication.

D. user is prompted three times before connecting to the Internet successfully.

 

Answer: C

 

Download Latest Checkpoint 156-110 Real Free Tests , help you to pass exam 100%.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.