Go Back on 156-315.81 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

156-315.81 Practice Test


Page 16 out of 85 Pages

Which of the following is NOT a method used by Identity Awareness for acquiring identity?


A. Remote Access


B. Active Directory Query


C. Cloud IdP (IdentityProvider)


D. RADIUS





A.
  Remote Access

Which of the following is true regarding the Proxy ARP feature for Manual NAT?


A. The local.arp file must always be configured


B. Automatic proxy ARP configuration can be enabled


C. fw ctl proxy should be configured


D. Translate Destination on Client Side should be configured





B.
  Automatic proxy ARP configuration can be enabled

Explanation: The verified answer is B. Automatic proxy ARP configuration can be enabled.
Proxy ARP is a feature that allows a gateway to respond to ARP requests on behalf of another IP address that is not on the same network segment. Proxy ARP is required for manual NAT rules when the NATed IP addresses are not routed to the gateway1.
By default, proxy ARP for manual NAT rules has to be configured manually by editing the local.arp file or using the CLISH commands on the gateway2. However, since R80.10, there is an option to enable automatic proxy ARP configuration for manual NAT rules by modifying the files $CPDIR/tmp/.CPprofile.sh and $CPDIR/tmp/.CPprofile.csh on the gateway3.
fw ctl proxy is a command that displays the proxy ARP table on the gateway, but it does not configure proxy ARP4.
Translate Destination on Client Side is a NAT option that determines whether the destination IP address is translated before or after the routing decision. It does not affect proxy ARP.

What are valid authentication methods for mutual authenticating the VPN gateways?


A. PKI Certificates and Kerberos Tickets


B. PKI Certificates and DynamicID OTP


C. Pre-Shared Secrets and Kerberos Ticket


D. Pre-shared Secret and PKI Certificates





D.
  Pre-shared Secret and PKI Certificates

Explanation: The valid authentication methods for mutual authenticating the VPN gateways are Pre-shared Secret and PKI Certificates. Pre-shared Secret is a method that uses a secret key that is known only to the two VPN gateways. PKI Certificates is a method that uses digital certificates that are issued by a trusted Certificate Authority (CA) and contain the public key of each VPN gateway. Both methods ensure that the VPN gateways can verify each other’s identity before establishing a secure VPN tunnel.

Which of the following is NOT a valid type of SecureXL template?


A. Accept Template


B. Deny template


C. Drop Template


D. NAT Template





B.
  Deny template

Which Check Point software blade provides protection from zero-day and undiscovered threats?


A. Firewall


B. Threat Emulation


C. Application Control


D. Threat Extraction





B.
  Threat Emulation


Page 16 out of 85 Pages
Previous