156-915.80 Sample Questions & Answers
Access-control policy and threat prevention take the top spot, built on the R80 management architecture, NAT rules and methods, site-to-site and remote-access VPNs, ClusterXL high availability, SmartEvent-based monitoring, and performance-tuning techniques.
Launch the full 156-915.80 simulator →Showing 10 of 20 free samples.
- Question 1
Which of the following is a new R80.10 Gateway feature that had not been available in R77.X and older?
Show answer & explanation
Correct answer: B
Policy Layers are a significant R80.10 enhancement that allows rule base organization into multiple layers inspected sequentially. This architecture provides granular control over rule evaluation order, enabling security administrators to prioritize different security functions and improve policy management complexity. Unlike R77.x flat rule bases, layered policies enable more sophisticated security architectures and easier troubleshooting of policy conflicts, essential for enterprise-grade Check Point deployments. Reference: http://slideplayer.com/slide/12183998/
- Question 2
In R80.10, how do you manage your Mobile Access Policy?
Show answer & explanation
Correct answer: C
In R80.10, Mobile Access Policy is managed directly from SmartDashboard within the unified management interface, eliminating the need for separate mobile consoles. This integration simplifies policy administration by centralizing all security policies in one location, enabling administrators to configure mobile access rules, authentication methods, and application controls through the familiar SmartDashboard interface. This unified approach improves troubleshooting efficiency and policy consistency across the entire Check Point security architecture. Reference: http://dl3.checkpoint.com/paid/f7/f78b067c6838c747e1568f139b6e6e8d/CP_R80.10_MobileAcces s_AdminGuide.pdf?HashKey=1522170407_805ae0a295fd6664fa23700cc1482686&xtn=.pdf
- Question 3
You find one of your cluster gateways showing “Down” when you run the “cphaprob stat” command. You then run the “clusterXL_admin up” on the down member but unfortunately the member continues to show down. What command do you run to determine the case?
Show answer & explanation
Correct answer: A
When a cluster member shows "Down" after running clusterXL_admin up, use "cphaprob -a list" to display detailed cluster problem information and failure reasons. This command provides comprehensive diagnostic data including which monitored services failed, interface status, and specific error conditions preventing the member from joining the cluster. This detailed troubleshooting information is essential for identifying root causes such as sync interface failures, monitored process issues, or configuration mismatches in ClusterXL environments. Reference: http://dl3.checkpoint.com/paid/63/6357d81e3b75b5a09a422d715c3b3d79/CP_R80.10_ClusterXL_ AdminGuide.pdf?HashKey=1522170580_c51bd784a86600b5f6141c0f1a6322fd&xtn=.pdf
- Question 4
SandBlast offers flexibility in implementation based on their individual business needs. What is an option for deployment of Check Point SandBlast Zero-Day Protection?
Show answer & explanation
Correct answer: C
Threat Agent Solution is a flexible deployment option for Check Point SandBlast Zero-Day Protection that can be implemented as dedicated appliances, virtual machines, or cloud-based services. This deployment flexibility allows organizations to integrate advanced threat prevention capabilities according to their specific infrastructure requirements and security architecture. The Threat Agent provides real-time file analysis, URL filtering, and zero-day protection while maintaining network performance in enterprise environments. Reference: https://www.checkpoint.com/products/threat-emulation-sandboxing/
- Question 5
Which of the following is NOT a valid way to view interface’s IP address settings in Gaia?
Show answer & explanation
Correct answer: C
The command "sthtool" is NOT a valid Gaia command for viewing interface IP addresses. Valid methods include "show interface" in Gaia CLI, "ifconfig" in Expert mode, the Web UI interface configuration pages, and "ip addr show" commands. The sthtool command does not exist in Gaia operating system - this is a common troubleshooting mistake where administrators attempt to use non-existent commands when diagnosing network interface issues in Check Point environments.
- Question 6
Check Point recommends configuring Disk Space Management parameters to delete old log entities when available disk space is less than or equal to?
Show answer & explanation
Correct answer: A
Check Point recommends configuring Disk Space Management to delete old log entities when available disk space reaches 15% or below. This threshold ensures sufficient disk space for critical system operations while maintaining log retention for security analysis and compliance requirements. Proper disk space management is crucial for preventing system failures and maintaining continuous log collection in enterprise Security Management Server deployments, especially during high-traffic periods or security incidents.
- Question 7
What API command below creates a new host with the name “New Host” and IP address of “192.168.0.10”?
Show answer & explanation
Correct answer: C
The Management API command "add host name "New Host" ip-address "192.168.0.10"" creates a new host object with the specified name and IP address. This RESTful API command structure follows Check Point's standardized syntax for object creation, requiring the publish command to commit changes to the management database. API-based host creation is essential for automation, bulk operations, and integration with external network management systems in enterprise Check Point troubleshooting and deployment scenarios.
- Question 8
What are types of Check Point APIs available currently as part of R80.10 code?
Show answer & explanation
Correct answer: B
R80.10 includes four main API types: Management API for configuration and policy management, Threat Prevention API for security intelligence integration, Identity Awareness Web Services API for user identification and authentication, and OPSEC SDK API for third-party integrations. This comprehensive API ecosystem enables extensive automation, custom integrations, and enterprise security orchestration capabilities essential for large-scale Check Point deployments and advanced troubleshooting scenarios.
- Question 9
Which of the following is NOT an internal/native Check Point command?
Show answer & explanation
Correct answer: B
tcpdump is NOT an internal Check Point command but rather a standard Linux network packet analyzer tool available in Expert mode. While Check Point provides native commands like fw monitor for packet capture with Check Point-specific filtering and cpview for system monitoring, tcpdump is inherited from the underlying Linux operating system. Understanding the distinction between native Check Point tools and standard Linux utilities is crucial for effective troubleshooting and proper diagnostic methodology in Check Point environments.
- Question 10
What is the SandBlast Agent designed to do?
Show answer & explanation
Correct answer: C
SandBlast Agent is designed to prevent malware lateral movement within the network if malware successfully enters an end user's system. The agent provides endpoint protection, behavioral analysis, and network-level containment to stop infected endpoints from spreading threats to other network resources. This endpoint-to-network protection is critical for limiting breach impact and providing time for incident response in enterprise security architectures. Reference: https://www.checkpoint.com/downloads/product-related/datasheets/ds-sandblast- agent.pdf
Ready for the real thing?
The full 156-915.80 simulator has every exam-style question, timed mode, and instant scoring.