Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Checkpoint 156-215.82 - Check Point Certified Security Administrator R82

Page: 5 / 6
Total 180 questions

Which of these is one of the components of Check Point's three-tier architecture?

A.

Security Gateway

B.

Gaia Portal

C.

Firewall Router

D.

CloudGuard Controller

A company wants to monitor VPN tunnel status and gateway performance in real time.

Which tool should they use?

A.

SmartConsole Logs View

B.

SmartUpdate

C.

SmartView Monitor

D.

SmartEvent

What is the difference between the Positive Control Model and the Negative Control Model?

A.

The Positive Control Model allows is what routers use and simply route traffic with no security rules. The Negative Control Model is what firewalls use and they require explicit rules to allow and route traffic.

B.

The Positive Control Model allows specific, approved actions or traffic and blocks everything else. The Negative Control Model begins by blocking specific, known threats, or unwanted actions and allows everything else.

C.

The Positive Control Model begins by blocking specific, known threats, or unwanted actions and allows everything else. The Negative Control Model allows specific, approved actions or traffic and blocks everything else.

D.

The Positive Control Model aims to keep administrators in a positive mind set. The Negative Control Model results in administrators having a negative mind set.

What is the role of real-time updates in Application Control and URL Filtering?

A.

They ensure accurate categorization of applications and websites

B.

They encrypt traffic between gateways

C.

They manage user authentication

D.

They reduce the need for HTTPS Inspection

What is a primary benefit of NAT?

A.

Changing your source IP address hitting internet web servers randomly to hide your real identity for security reasons.

B.

Security - Hides internal IP addresses behind a public IP address which prevents the internal hosts from being exposed to the internet.

C.

Business Continuity - If only a small amount of IP addresses were allowed to access a particular resource, you can change your source IP address to overcome this limitation.

D.

Accessibility - In a IPSec VPN environment, you can access resources with private IP addresses by assigning respective public IP addresses.

Which type of administrator account is used to log in to the Gaia Portal or Gaia Clish command line?

A.

Primary Security Management Server admin account

B.

Gaia admin account

C.

API admin account

D.

SmartConsole admin account

Application Control and URL Filtering can be combined with which of the Security measures?

A.

HTTPS Inspection and Content Awareness.

B.

Integration with an OPSEC-certified AAA Server

C.

HTTPS Inspection and Data Integrity Checking.

D.

OPSEC-certified Reporting Server using LEA and ELA interfaces for bidirectional communication with the Management Server.

You are using a rule to block traffic to a specific https site. However, traffic is not blocked as expected during the first attempts to the site. It will be blocked later.

What is the most likely reason?

A.

Categorization is in fail close mode and the requests are not allowed until the categorization is complete.

B.

Categorization is in hold mode and the requests are not allowed until the categorization is complete.

C.

Categorization is in Background mode and the requests are allowed until the categorization is complete.

D.

Categorization is in fail open mode and the requests are allowed until the categorization is complete.

In HTTPS Inspection, what is the role of Categorization Mode?

A.

It disables inspection for trusted sites

B.

It decrypts all HTTPS traffic by default

C.

It blocks all encrypted traffic

D.

It categorizes traffic based on domain and certificate without decryption

What is the purpose of the Gaia Clish shell?

A.

To manage objects and policies

B.

To inspect inbound and outbound traffic

C.

To provide a graphical interface

D.

For initial system configuration and ongoing management