Go Back on 156-315.81 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

156-315.81 Practice Test


Page 8 out of 85 Pages

Fill in the blank: The R81 feature _____ permits blocking specific IP addresses for a specified time period.


A. Block Port Overflow


B. Local Interface Spoofing


C. Suspicious Activity Monitoring


D. Adaptive Threat Prevention





C.
  Suspicious Activity Monitoring

During the Check Point Stateful Inspection Process, for packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are:


A. Dropped without sending a negative acknowledgment


B. Dropped without logs and without sending a negative acknowledgment


C. Dropped with negative acknowledgment


D. Dropped with logs and without sending a negative acknowledgment





D.
  Dropped with logs and without sending a negative acknowledgment

Explanation: For packets that do not pass Firewall Kernel Inspection and are rejected by the rule definition, packets are dropped with logs and without sending a negative acknowledgment. Firewall Kernel Inspection is the process of applying security policies and rules to network traffic by the Firewall kernel module. If a packet does not match any rule or matches a rule with an action of Drop or Reject, the packet is dropped by the Firewall kernel module. The difference between Drop and Reject is that Drop silently discards the packet without informing the sender, while Reject discards the packet and sends a negative acknowledgment (such as an ICMP message) to the sender. However, both Drop and Reject actions generate logs that record the details of the dropped packets, such as source, destination, protocol, port, rule number, etc. The other options are either incorrect or describe different scenarios.

CoreXL is supported when one of the following features is enabled:


A. Route-based VPN


B. IPS


C. IPv6


D. Overlapping NAT





B.
  IPS

Explanation: CoreXL is supported when one of the following features is enabled: IPS. CoreXL does not support Check Point Suite with these features: Route-based VPN, IPv6, Overlapping NAT, QoS, Content Awareness, Application Control, URL Filtering, Identity Awareness, HTTPS Inspection, DLP, Anti-Bot, Anti-Virus, Threat Emulation.

Which TCP-port does CPM process listen to?


A. 18191


B. 18190


C. 8983


D. 19009





D.
  19009

Which of the following Check Point processes within the Security Management Server is responsible for the receiving of log records from Security Gateway?


A. logd


B. fwd


C. fwm


D. cpd





B.
  fwd

Explanation: The fwd process within the Security Management Server is responsible for the receiving of log records from Security Gateway. The fwd process handles the communication with the Security Gateways and log servers via TCP port 2571. The other processes have different roles, such as logd for writing logs to the database, fwm for handling GUI clients, and cpd for infrastructure tasks2.


Page 8 out of 85 Pages
Previous