156-215.81.20 Sample Questions & Answers
Policy rules and packages make up the largest portion, with Gaia-based security architecture behind it, URL filtering and app control during traffic inspection, NAT rules, site-to-site VPNs, threat prevention, and backup and log maintenance.
Launch the full 156-215.81.20 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Monitoring and Logging · Firewall Debugging
The command
fw ctl zdebug dropis used on a Security Gateway to view real-time packet drops. An administrator runs this command and sees drops related to 'rule 0'. What does 'rule 0' signify in the context of the Check Point firewall policy?Show answer & explanation
Correct answer: B
'Rule 0' refers to the implicit cleanup rule that exists at the end of every Check Point security policy. If a packet does not match any of the user-defined rules above it, it will be caught and dropped by this rule. Seeing drops on rule 0 indicates that no explicit rule exists to allow that traffic.
- Question 2Intermediate
Traffic Inspection and Control · HTTPS Inspection
A network security engineer is configuring HTTPS Inspection to decrypt and inspect SSL/TLS traffic. After enabling the feature, users report receiving certificate warnings in their browsers when accessing HTTPS sites. Which of the following is the most critical step the engineer missed during the configuration?
Show answer & explanation
Correct answer: C
For HTTPS Inspection to work, the Security Gateway performs a man-in-the-middle action. It presents its own certificate to the client, signed by its internal Certificate Authority (CA). If the client browsers do not trust this internal CA, they will generate certificate warnings. The solution is to export the gateway's CA certificate and deploy it to the 'Trusted Root Certification Authorities' store on all client machines.
- Question 3Beginner
System Maintenance · CPUSE Command Line Interface
To upgrade a Security Gateway using the Check Point Upgrade Service Engine (CPUSE) from the Gaia command line, which command should be used to view available packages, including the recommended Jumbo Hotfix Accumulator?
Show answer & explanation
Correct answer: D
Within the Gaia Clish, the command
show installer available-packagesconnects to the Check Point download center and lists all packages available for the specific hardware and software version, including hotfixes, jumbos, and major upgrades. - Question 4Advanced
Security Policy Management · Policy Layers Design
A security architect is designing a policy for a large enterprise using R81.20's new Policy Layer capabilities. The goal is to have a baseline security policy for the entire organization, with specific, stricter policies for the PCI and Development environments that can be managed by different teams. The PCI policy must take precedence over the baseline. Which policy structure best achieves this?
graph TD subgraph "Policy Package" A["Baseline Layer"] B["PCI Ordered Layer"] C["Dev Ordered Layer"] D["Final Cleanup Rule"] end B --> A C --> A A --> DShow answer & explanation
Correct answer: D
Ordered Layers are the ideal solution. They are evaluated as independent policy sets before the main layer. By placing the PCI Ordered Layer first, its rules are checked first. If a match is found with an action of Accept or Drop, processing stops, ensuring PCI rules take precedence. If no match is found in the PCI layer, processing continues to the next layer (e.g., Development) and then to the main baseline layer. This provides both precedence and delegation of administration.
- Question 5Intermediate
Security Management Architecture · SmartWorkflow
Case Study:
A retail company, 'StyleStream', is deploying a new e-commerce platform. The architecture consists of web servers in a DMZ and database servers in a secure internal zone. The Security Management Server (SMS) and Security Gateway are both running R81.20.
The lead security administrator has defined the following requirements:
- All administrative changes to the security policy must be reviewed and approved by a senior manager before they can be published and installed. This is a strict compliance requirement.
- The web servers in the DMZ must be accessible from the internet on port 443 (HTTPS). These servers must initiate connections to the database servers on port 1433 (MSSQL).
- No other traffic should be allowed from the DMZ to the internal database zone.
- Administrators should authenticate to SmartConsole using their corporate Active Directory credentials via SAML 2.0.
To meet these requirements, the administrator needs to configure several key features. Which Check Point feature directly addresses the first requirement for mandatory change review and approval?
Show answer & explanation
Correct answer: B
SmartWorkflow is a feature specifically designed for change management control. By enabling session approval, an administrator's changes are held in a pending state until a designated approver (like a senior manager) reviews and approves the session. Only after approval can the changes be published and installed, directly fulfilling the compliance requirement.
- Question 6Beginner
Traffic Inspection and Control · CoreXL
What is the primary function of CoreXL in the Check Point Security Gateway architecture?
Show answer & explanation
Correct answer: C
CoreXL is a performance-enhancing technology that leverages multi-core processors. It creates multiple firewall kernel instances (FW workers) that run in parallel on different CPU cores. This allows the gateway to inspect multiple connections simultaneously, significantly increasing throughput and overall performance.
- Question 7Intermediate
Monitoring and Logging · SmartLog Analysis
An administrator is troubleshooting an issue where traffic that should be allowed by the Access Control policy is being dropped. They suspect an anti-spoofing issue. Which log field in SmartLog would most clearly indicate that a packet was dropped due to an anti-spoofing violation?
Show answer & explanation
Correct answer: C
When a packet is dropped due to an anti-spoofing check, the log entry will typically have an Action of 'Drop', but the key differentiator is the 'Information' field. This field will contain a message like 'Packet dropped - Spoofing' or 'Packet is spoofed', explicitly stating the reason for the drop, distinguishing it from a drop caused by a policy rule.
- Question 8IntermediateSelect 2
Traffic Inspection and Control · URL Filtering and Application Control
A security team needs to implement a policy that blocks access to specific high-risk web categories, such as 'Phishing' and 'Malicious Sites', for all users. They also need to ensure that certain file types, like executables (.exe) and scripts (.bat), cannot be downloaded from any website, regardless of its category. Which security blades must be enabled and configured to meet both requirements? (Select TWO)
Show answer & explanation
Correct answers: A, C
The URL Filtering blade is required to identify and block access to websites based on their categories, such as 'Phishing' and 'Malicious Sites'.
The Application Control blade contains the Content Awareness feature. This feature is used to identify and block specific file types (like .exe and .bat) within web traffic, fulfilling the second requirement.
- Question 9Beginner
Access Control and VPN · Site-to-Site VPN
When creating a Site-to-Site VPN community, what is the purpose of defining the 'Encryption Domain' for a member gateway?
Show answer & explanation
Correct answer: C
The Encryption Domain is a crucial part of a VPN configuration. It is a network object (or group of objects) that defines the IP address space of the networks behind the gateway that are permitted to participate in the VPN. Traffic originating from or destined to an IP within this domain will be encrypted and sent through the tunnel.
- Question 10Beginner
Threat Prevention · Threat Extraction
The Threat Extraction blade, when configured in 'Active' mode, removes potentially malicious content from files and delivers a sanitized version to the user instantaneously.
Show answer & explanation
Correct answer: A
This statement is true. Threat Extraction is a part of Check Point's SandBlast Zero-Day Protection. It works by reconstructing files, removing active content like macros and embedded scripts, and delivering a clean, safe version to the user immediately. This prevents zero-day attacks without causing the delay associated with sandboxing (Threat Emulation).
Ready for the real thing?
The full 156-215.81.20 simulator has every exam-style question, timed mode, and instant scoring.