156-560 Sample Questions & Answers
AWS, Azure and GCP deployment is the heaviest topic for CloudGuard, with the rest split between baseline threat-prevention concepts, unified policy and traffic-inspection management, CI/CD-driven automation, and Dome9 CSPM covering containers and workload protection.
Launch the full 156-560 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Deploying CloudGuard · Auto Scaling Architecture
True or False: When deploying a CloudGuard Auto Scaling group for AWS, the Security Management Server (SMS) must be deployed in the same AWS region as the auto-scaling gateways to ensure proper functionality.
Show answer & explanation
Correct answer: B
The Security Management Server, especially if it's Smart-1 Cloud, can be located anywhere with network connectivity to the gateways. It does not need to be in the same AWS region. The gateways are configured during bootstrap to connect to the specified management server, regardless of its location.
- Question 2Advanced
Deploying CloudGuard · Troubleshooting Auto Scaling
An e-commerce company uses AWS with an Auto Scaling group of CloudGuard gateways behind a Gateway Load Balancer (GWLB) to inspect traffic. During a sales event, traffic spikes, but the number of active gateways in the Auto Scaling group does not increase, leading to performance degradation. A review of CloudWatch metrics for the Auto Scaling group shows that CPU utilization is consistently below the scaling threshold. What is the MOST likely cause of this issue?
Show answer & explanation
Correct answer: C
A common misconfiguration is to base scaling decisions solely on CPU utilization. Security gateways can become bottlenecks due to high network throughput, a large number of concurrent connections, or high packets per second, even when CPU usage is not high. The most likely cause is that the scaling trigger is not aligned with the actual performance bottleneck. The solution is to use a more relevant metric, such as a network-related metric or a custom Check Point metric, for scaling decisions.
- Question 3Intermediate
Security for IaaS Clouds with Dome9 · Kubernetes Runtime Protection
A security team is implementing CloudGuard Kubernetes runtime protection. They want to prevent a specific malicious behavior: a process inside a container attempting to load a kernel module. Which CloudGuard feature is designed to detect and block this type of activity in real-time?
Show answer & explanation
Correct answer: D
CloudGuard's Kubernetes Runtime Protection uses an agent that monitors system calls (syscalls) made by processes within containers. Attempting to load a kernel module involves specific syscalls (
init_module,finit_module). The Runtime Protection agent can detect these anomalous and potentially malicious syscalls, generating an alert or blocking the action based on the configured policy. Image scanning and admission control are pre-runtime checks, and threat hunting is a post-incident analysis tool. - Question 4Beginner
Introducing CloudGuard Protections · Deployment Modes
A cloud administrator is configuring a CloudGuard Security Gateway in a 'Standalone' deployment mode. What does this deployment mode signify?
Show answer & explanation
Correct answer: B
In Check Point terminology, a 'Standalone' deployment means that both the Security Gateway (which enforces the policy) and the Security Management Server (which manages the policy) are installed and run on the same machine or virtual instance. This is common for small deployments, labs, or proof-of-concept environments.
- Question 5Intermediate
CloudGuard Security Policy · Multi-Cloud Dynamic Objects
An organization is using CloudGuard to secure its multi-cloud environment, which includes AWS and Azure. The security policy needs to allow SSH access to all Linux servers for the IT administration team. The Linux servers in AWS are tagged with
OS:Linuxand in Azure are tagged withOS:Linux. To avoid creating separate rules for each cloud, the administrator wants to use a single dynamic object. What is the correct procedure to create a single policy object that represents all Linux servers across both clouds?Show answer & explanation
Correct answer: C
The correct method to represent assets from multiple, different cloud providers within a single policy object is to use a Group. You would first create a Data Center Query object for AWS filtering on the tag, then a second Data Center Query object for Azure filtering on the tag. Finally, you create a new Group object and add both of the Data Center Query objects to it. This group can then be used as a single entity in the source or destination of a security rule.
- Question 6Beginner
Security for IaaS Clouds with Dome9 · Serverless Security
A company is migrating its applications to a serverless architecture using AWS Lambda. The security team wants to ensure that these functions are protected against vulnerabilities and threats. Which CloudGuard product is specifically designed to provide runtime protection for serverless functions?
Show answer & explanation
Correct answer: C
CloudGuard Workload Protection (part of the CWPP capabilities in the CNAPP suite) is the component designed to secure serverless functions. It provides runtime protection by analyzing the function's behavior, detecting threats, and preventing attacks without needing a network gateway.
- Question 7Beginner
Automating CloudGuard Protections · Management API Authentication
A cloud security architect wants to use the Check Point Management API to automate the creation of a new host object. The API call needs to be authenticated. Which command should be run first to obtain an authentication token (SID)?
Show answer & explanation
Correct answer: B
Before any other API calls can be made to the Check Point Management API, a client must authenticate by sending a
logincommand with valid credentials (username/password or an API key). The successful response to thelogincall contains a session identifier (SID) that must be included in the header of all subsequent API requests. - Question 8Advanced
Deploying CloudGuard · AWS Transit Gateway Integration
A security engineer is analyzing traffic logs from a CloudGuard IaaS gateway and notices that traffic between two EC2 instances in the same VPC is being dropped. The security policy explicitly allows this traffic. The company is using an AWS Transit Gateway architecture. What is a possible reason for this behavior?
Show answer & explanation
Correct answer: C
In a Transit Gateway architecture, it's critical to ensure symmetric routing, meaning both the request and response packets of a connection pass through the same CloudGuard gateway. If the VPC route tables are misconfigured, traffic might go to the gateway on the way to the destination but return directly, bypassing the gateway. The CloudGuard gateway's stateful firewall will see this as an invalid connection and drop the return packet. This is a common issue with complex cloud routing.
- Question 9Intermediate
Security for IaaS Clouds with Dome9 · Kubernetes Admission Controller
What is the primary function of the CloudGuard Admission Controller in a Kubernetes environment?
graph TD A[Developer pushes new Pod manifest] --> B{CI/CD Pipeline} B --> C{Kubernetes API Server} C --> D[CloudGuard Admission Controller] D -- Validation --> C C -->|Policy Pass| E[Pod Scheduled] C -->|Policy Fail| F[Request Rejected]Show answer & explanation
Correct answer: B
The CloudGuard Admission Controller acts as a validating webhook for the Kubernetes API server. Its primary function is to enforce 'shift-left' security by intercepting deployment requests (e.g., creating a Pod or Deployment) and validating them against a defined security policy before they are persisted in the cluster. It can block deployments that use insecure images, have excessive privileges, or violate other configured rules.
- Question 10IntermediateSelect 2
Deploying CloudGuard · AWS Gateway Load Balancer
What are the key benefits of using the AWS Gateway Load Balancer (GWLB) with a fleet of CloudGuard Security Gateways? (Select TWO)
Show answer & explanation
Correct answers: A, C
Ready for the real thing?
The full 156-560 simulator has every exam-style question, timed mode, and instant scoring.