156-315.81.20 Sample Questions & Answers
Custom threat-prevention solutions make up the largest piece, plus high-availability management, policy optimization, identity-aware access, domain-based site-to-site VPNs, mobile and remote access, SmartEvent monitoring, performance tuning, and upgrade maintenance.
Launch the full 156-315.81.20 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Performance Tuning · Hyperflow
A system administrator is analyzing the output of
fw ctl pstaton an R81.20 Security Gateway experiencing high CPU utilization. They need to understand the relationship between the SecureXL, Medium Path, and Firewall Path (Slow Path). The following ASCII diagram illustrates the packet processing flow:Packet IN | v +---------------+ | SecureXL | --- (Accelerated Path) --> Packet OUT +---------------+ | v +---------------+ | Medium Path | | (Passive Str.)| --- (Inspection) -------> SecureXL Template -> Packet OUT +---------------+ | v +---------------+ | Firewall Path | | (Slow Path) | --- (Full Inspection) ---> Medium Path -> Packet OUT +---------------+Based on the diagram and Check Point's performance tuning architecture, which statement accurately describes the HyperFlow feature's role?
Show answer & explanation
Correct answer: C
HyperFlow is designed to optimize the handling of 'elephant flows'—very long, high-bandwidth connections. Normally, a single connection is processed by a single CoreXL firewall instance (Firewall Path). For an elephant flow, this can create a bottleneck on that one CPU core. HyperFlow detects these flows and dynamically assigns additional CoreXL instances (and thus, more CPU cores) to process the same connection in parallel, significantly increasing throughput for that flow and preventing a single core from being overloaded.
- Question 2Beginner
Advanced Security Maintenance · migrate_server
An administrator is configuring a new R81.20 cluster and wants to use the
migrate_servercommand to export the configuration from an existing R81 Security Management Server. The goal is to perform a clean installation on new hardware and then import the configuration. What is the correct command syntax to initiate the export process on the source Security Management Server?Show answer & explanation
Correct answer: C
The
migrate_servercommand is the correct tool for this task. The proper syntax requires theexportargument followed by the desired path and filename for the output archive. This command packages the entire management database, objects, policies, and settings into a single.tgzfile that can be used withmigrate_server importon the new server. - Question 3Intermediate
Advanced Deployments · External Network Feed
A DevOps team requires the ability to programmatically add and remove IP addresses from a security policy rule that grants access to a staging environment. They want to avoid giving the team SmartConsole access and need a solution that allows for rapid, automated updates without requiring a full policy installation for every change. Which R81.20 object type is best suited to meet these requirements?
Show answer & explanation
Correct answer: B
Network Feed Objects (a type of Updatable Object) are specifically designed for this purpose. They allow a Security Gateway to pull a list of IPs, domains, or other indicators from an external web server. The DevOps team can manage a simple text file on a web server, and the gateway will periodically fetch and enforce it. This process is handled directly on the gateway and does not require a policy installation for updates, enabling rapid and automated changes.
- Question 4Intermediate
Advanced Site-to-Site VPN · VPN Troubleshooting
A security engineer is troubleshooting a site-to-site VPN between an R81.20 Security Gateway and a third-party cloud provider. The cloud provider requires IKEv2 and mandates the use of specific, strong cryptographic algorithms for both IKE and IPsec phases. The engineer observes in the logs that the tunnel fails to establish during Phase 2 negotiations. The error message indicates a 'NO_PROPOSAL_CHOSEN' payload. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: C
The 'NO_PROPOSAL_CHOSEN' error message during IKE Phase 2 (for IPsec SAs) or Phase 1 (for IKE SAs) specifically means that the peers could not agree on a common set of cryptographic algorithms. The initiating peer sends a proposal with a list of supported ciphers (e.g., AES-256 for encryption, SHA-256 for integrity), and the responding peer must find at least one matching set that it is also configured to use. If no match is found, this error is returned. The engineer must verify the VPN community's IPsec and IKE properties to ensure they align with the cloud provider's mandate.
- Question 5AdvancedSelect 3
Advanced Policy Configuration · IoT Security
A retail company is expanding its use of IoT devices, including PoS terminals and inventory scanners. These devices communicate with cloud services over HTTPS. The security team needs to enforce a strict security policy that allows these devices to communicate ONLY with necessary, predefined FQDNs. They also need to apply IPS protections to this traffic. The solution must not rely on maintaining static IP lists for the cloud services and must be efficient.
Which THREE Check Point features should be combined in the policy to achieve this? (Select THREE)
Show answer & explanation
Correct answers: B, C, D
To apply IPS to encrypted HTTPS traffic, the gateway must first decrypt it. HTTPS Inspection is the feature that performs this decryption and re-encryption, making the payload visible to the IPS engine.
Using Domain Objects allows the administrator to specify FQDNs in the policy. The gateway dynamically resolves these FQDNs to IPs and updates the policy accordingly. This is the correct way to control access to services with dynamic IPs without manual intervention.
After the Access Control rule allows the connection and HTTPS Inspection decrypts it, a Threat Prevention rule is required to apply the IPS profile to the decrypted traffic, fulfilling the requirement to inspect for threats.
- Question 6Intermediate
Advanced Deployments · Accelerated Policy Installs
An administrator is managing an R81.20 environment where policy installation times have become unacceptably long. An investigation reveals that the 'Verifying' and 'Generating' stages of the installation process are taking the most time. The security policy contains thousands of rules and objects. Which R81.20 feature is specifically designed to reduce policy installation time by optimizing these stages?
Show answer & explanation
Correct answer: B
The Accelerated Policy Install feature in R81.20 significantly reduces installation times for large policies. It achieves this by compiling and storing objects in a new cache format on the management server. During installation, it only compiles the changes made since the last installation instead of the entire policy. This specifically targets and speeds up the 'Verifying' and 'Generating' phases of the process.
- Question 7Intermediate
Mobile Access VPN · Endpoint Compliance
A university provides remote access to its digital library for students and faculty using the Mobile Access Blade on an R81.20 gateway. The university wants to implement a security policy where users connecting from university-managed laptops are granted access to a wider range of resources than users connecting from personal devices (BYOD). The managed laptops all have a specific client certificate installed. Which Mobile Access feature should be configured to enforce this policy?
Show answer & explanation
Correct answer: C
The Endpoint Compliance feature within the Mobile Access blade is used to scan remote devices for specific attributes and enforce policies based on the results. An administrator can create a compliance rule that checks for the presence of a specific client certificate. Then, in the Mobile Access policy, rules can be created to grant different levels of access based on whether the endpoint is 'Compliant' (certificate found) or 'Non-Compliant' (certificate not found), perfectly addressing the university's requirement.
- Question 8Advanced
Custom Threat Protection · ICS/SCADA Security
Case Study
Company Background:
Global PetroCorp runs a large-scale industrial control system (ICS) network to manage its oil refineries. The network is physically isolated, but a new initiative requires connecting it to the corporate network to pull production data for business analytics. The corporate network is managed by a central R81.20 Security Management Server (SMS) and protected by a cluster of Security Gateways.Technical Challenge:
The ICS network uses legacy devices that are highly sensitive to network latency and jitter. Standard security scanning could cause them to malfunction. The connection to the corporate network is via a single, high-speed link. The primary concern is preventing any threats from the corporate network from pivoting into the critical ICS environment. The solution must provide deep visibility into the specific ICS protocols being used, such as Modbus and DNP3, and enforce a strict least-privilege policy based on these protocols.Requirements:
- Provide robust threat prevention for traffic entering the ICS network.
- Must not introduce any active scanning or traffic that could disrupt sensitive ICS devices.
- Must provide application-layer visibility and control of ICS-specific protocols.
- The solution must be centrally managed from the existing R81.20 SMS.
Diagram of Proposed Architecture:
Corporate Network | v +-----------------------+ | R81.20 Gateway Cluster| +-----------------------+ | v +-----------------------+ +----------------------+ | ICS Security GW |---->| ICS/SCADA Network | | (TAP/Passive Mode) | | (Modbus, DNP3, etc.) | +-----------------------+ +----------------------+Which Check Point solution or feature set should be implemented for the 'ICS Security GW' to meet all of Global PetroCorp's stringent requirements?
Show answer & explanation
Correct answer: C
Check Point's dedicated ICS/SCADA Security solution is designed for this specific environment. It meets all requirements: 1) It provides Threat Prevention tailored for ICS protocols. 2) By deploying it in a passive, out-of-band mode using a network TAP, it inspects a copy of the traffic without being inline, ensuring it cannot disrupt sensitive devices. 3) It includes deep packet inspection for over 60 ICS protocols, providing granular visibility and control. 4) It is fully managed as a gateway object within the standard R81.20 SMS, allowing for centralized policy management.
- Question 9Intermediate
Advanced User Access Management · Identity Awareness
A security administrator needs to configure Identity Awareness on an R81.20 gateway. The goal is to acquire identity information from Active Directory without installing any Check Point components on the Domain Controllers. The solution should also be able to gather identity data from syslog messages sent by a RADIUS server. Which Identity Awareness acquisition source should be configured to meet both requirements?
Show answer & explanation
Correct answer: C
The Identity Collector is the correct solution. It queries Active Directory domain controllers using standard WMI and event log reading, which does not require an agent to be installed on them. Additionally, the Identity Collector can be configured as a syslog receiver (Syslog Parser) to process login/logout messages from third-party devices like a RADIUS server. This makes it the single, versatile tool that can satisfy both of the specified requirements.
- Question 10Beginner
Management High Availability · Failover Mechanisms
True or False: In an R81.20 Management High Availability deployment, the synchronization of the management database between the primary and standby servers is an automatic process, while the failover of the active server role must be initiated manually by an administrator.
Show answer & explanation
Correct answer: A
This statement is true. In a standard Management High Availability (HA) setup, the primary management server automatically synchronizes its entire database, including objects, rules, and user settings, with the standby server at regular intervals. However, the process of promoting the standby server to become the active server (failover) is a manual procedure. This is by design, to prevent unintended failovers and to allow an administrator to verify the state of the system before making the change. This contrasts with Security Gateway ClusterXL HA, where failover is automatic.
Ready for the real thing?
The full 156-315.81.20 simulator has every exam-style question, timed mode, and instant scoring.