Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Checkpoint 156-590 - Check Point Certified Threat Prevention Specialist (CTPS)

Page: 2 / 3
Total 75 questions

What are the three Preconfigured Threat Prevention Profiles?

A.

Inbound, Outbound, Etherbound.

B.

Perimeter, Datacenter, East-West Communication.

C.

North-South, East-West, Lateral Movement.

D.

Basic, Optimized, Strict.

What is necessary to activate the exception to all Security Gateways?

A.

Install Database is sufficient.

B.

You have to re-install the Threat Prevention policy.

C.

You have to re-install the Access Control policy.

D.

The changes will be applied immediately, so no need to do anything.

What is the impact of changing the Preconfigured Threat Prevention Profiles?

A.

The best practice for all Check Point delivered profiles and object is to first clone them and work on the clones.

B.

The impact is minimum if you first delete all of them and then build them from scratch.

C.

The impact can be minimized if you use the performance check tool. You can enable it in IPS protections - > actions - > Run Protection performance check tool.

D.

There is no performance or security impact in changing the Preconfigured Profiles.

What is the main purpose of IPS Implied Exceptions?

A.

This defines the handling of traffic if no IPS rule applied to the appropriate packets.

B.

This defines the handling of traffic if you do not have an IPS Policy as part of an ordered layer.

C.

This feature is to prevent IPS Enforcement to interfere with important Security Gateway operations, such as Control Connections.

D.

This defines the handling of traffic if you do not have an IPS Policy as part of an Inline layer.

What are the logical components of a SNORT rule?

A.

Rule Header / rule body

B.

Rule Header and Rule Options

C.

Rule start / rule stop

D.

Rule start / rule options

What is the recommended setting for Anti-Virus and why?

A.

Background because it is Post-infection

B.

Hold because it is Pre-infection and inspects a limited subset of traffic

C.

Hold because it inspects a limited subset of traffic

D.

Background because it inspects a large subset of traffic

What deployment options for SmartEvent exist?

A.

1. Standalone and 2. Distributed Deployment

B.

1. Integrated/Standalone and 2. Dedicated Server

C.

1. Prevent Mode and 2. Detect Mode

D.

1. High Availability Mode and 2. Load Sharing Mode

Which is NOT a rating used in IPS Protection selection/activation?

A.

Severity

B.

CPU Utilization

C.

Confidence Level

D.

Performance Impact

What is the default frequency of IPS updates (in R80.20+)?

A.

Every two hours

B.

Every 24 hours

C.

Every hour

D.

Every four hours

How many Custom Threat Indicators patterns/observables does R81.20 support?

A.

10 million

B.

2 hundred thousand

C.

6 million

D.

2 million