Latest 156-315 Real Exam Download 101-110

Ensurepass

QUESTION 101

Which service type does NOT invoke a Security Server?

 

A. HTTP

B. FTP

C. Telnet

D. CIFS

E. SMTP

 

Answer: D

 

 

QUESTION 102

When Load Sharing Multicast mode is defined in a ClusterXL cluster object, how are packets being handled by cluster members?

 

A. All cluster members process all packets, and members synchronize with each other.

B. All members receive all packets. TheSmartCenter Server decides which member will process the packets. Other members simply drop the packets.

C. Only one member at a time is active. The active cluster member processes all packets.

D. All members receive all packets. An algorithm determines which member processes packets, and which member drops packets.

 

Answer: D

 

 

QUESTION 103

Your current VPN-1 NG with Application Intelligence (Al) R55 stanD. alone VPN-1 Pro Gateway and SmartCenter Server run on SecurePlatform. You plan to implement VPN-1 NGX in a distributed environment, where the existing machine will be the SmartCenter Server, and a new machine will be the VPN-1 Pro Gateway only. You need to migrate the NG with Al R55 SmartCenter Server configuration, including such items as Internal Certificate Authority files, databases, and Security Policies.

How do you request a new license for this VPN-1 NGX upgrade?

 

A. Request a VPN-1 NGXSmartCenter Server license, using the new machine’s IP address. Request a new local license forthe NGX VPN-1 Pro Gateway.

B. Request a VPN-1 NGXSmartCenter Server license, using the new machine’s IP address. Request a new central license forthe NGX VPN-1 Pro Gateway.

C. Request a new VPN-1 NGX SmartCenter Server license, using the NG with Al SmartCenter Server IP address. Request a new central license for the NGX VPN-1 Pro Gateway.

D. Request a VPN-1 NGX SmartCenter Server license, using the NG with Al SmartCenter Server IP address. Request a new central license forthe NGX VPN-1 Pro Gateway, licensed forthe existing SmartCenter Server IP address.

 

Answer: D

 

 

QUESTION 104

Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav’s VPN solution must meet the following requirements:

Portability: Standard Key management: Automatic, external PKI Session keys: Changed at configured times during a connection’s lifetime Key length: No less than 128-bit Data integrity: Secure against inversion and brutE. force attacks

What is the most appropriate setting Yoav should choose?

 

A. IKE VPNs: AES encryption for IKE Phase 1, and DES encryption for Phase 2; SHA1 hash

B. IKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for Phase 2; AES hash

C. IKE VPNs: CAST encryption for IKE Phase 1, and SHA1 encryption for Phase 2; DES hash

D. IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash

E. IKE VPNs: DES encryption for IKE Phase 1, and 3DES encryption for Phase 2; MD5 hash

 

Answer: D

 

 

QUESTION 105

Jerry is concerned that a denial-oF. service (DoS) attack may affect his VPN Communities. He decides to implement IKE DoS protection. Jerry needs to minimize the performance impact of implementing this new protection. Which of the following configurations is MOST appropriate for Jerry?

 

A. Set Support IKEDoS protection from identified source to “Puzzles”, and Support IKE DoS protection from unidentified source to “Stateless”.

B. Set Support IKE Dos Protection from identified source, and Support IKEDoS protection from unidentified source to “Puzzles”.

C. Set Support IKE DoS protection from identified source to “Stateless,” and Support IKE DoS protection from unidentified source to “Puzzles”.

D. Set “Support IKE DoS protection” from identified source, and “Support IKE DoS protection” from unidentified source to “Stateless”.

E. Set Support IKEDoS protection from identified source to “Stateless”, and Support IKE DoS protection from unidentified source to “None”.

 

Answer: D

 

 

QUESTION 106

What is a requirement for setting up Management High Availability?

 

A. AllSmartCenter Servers must reside in the same Local Area Network (LAN).

B. AllSmartCenter Servers must have the same amount of memory.

C. You can only have one Secondary SmartCenter Server.

D. All SmartCenter Servers must have the BIOS release.

E. AllSmartCenter Servers must have the same operating system.

 

Answer: E

 

 

QUESTION 107

What is the consequence of clearing the “Log VoIP Connection” box in Global Properties?

 

A. Dropped VoIP traffic is logged, but accepted VoIP traffic is not logged.

B. VoIP protocol-specific log fields are not included inSmartView Tracker entries.

C. The log field setting in rules for VoIP protocols are ignored.

D. IP addresses are used, instead of object names, in log entries that reference VoIP Domain objects.

E. The SmartCenter Server stops importing logs from VoIP servers.

 

Answer: B

 

 

QUESTION 108

Which of the following TCP port numbers is used to connect the VPN-1 Gateway to the Content Vector Protocol (CVP) server?

 

A. 18182

B. 18180

C. 18181

D. 17242

E. 1456

 

Answer: C

 

 

QUESTION 109

Which operating system is NOT supported by VPN-1 SecureClient?

 

A. IPSO 3.9

B. Windows XP SP2

C. Windows 2000 Professional

D. RedHat Linux 8.0

E. MacOSX

 

Answer: A

 

 

QUESTION 110

If you check the box “Use Aggressive Mode”, in the IKE Properties dialog box:

 

A. The standardthreE. packet IKE Phase 1 exchange is replaced by a six-packet exchange.

B. The standard six-packet IKE Phase 2 exchange is replaced by athreE. packet exchange.

C. The standard threE. packet IKE Phase 2 exchange is replaced by a six-packet exchange.

D. The standard six-packet IKE Phase 1 exchange is replaced by a threE. packet exchange.

E. The standard six-packet IKE Phase 1 exchange is replaced by atwelvE. packet exchange.

 

Answer: D

 

Download Latest Checkpoint 156-315 Real Free Tests , help you to pass exam 100%.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.