CheckPoint Check Point Security Administration NGX II (156-315.1) Sample Questions:
1. You have an internal FTP server, and you allow uploading, but not downloading. Assume Network Address Translation (NAT) is set up correctly and you want to add an inbound rule with:
Source: Any
Destination: FTP server
Service: an FTP resource object.
How do you configure the FTP resource object and the action column in the rule to achieve this goal?
A) Enable only the "Get" method in the FTP Resource Properties and use this method in the rule, with action accept.
B) Enable only the "Put" method in the FTP Resource Properties and use this method in the rule, with action drop.
C) Enable only "Put" method in the FTP Resource Properties and use this method in the rule, with action accept.
D) Disable "Get" and "Put" methods in the FTP Resource Properties and use them in the rule, with action accept.
E) Enable both "Put" and "Get" methods in the FTP Resource Properties and use them in the rule, with action drop.
2. You want to upgrade a cluster with two members to VPN-1 NGX. The SmartCenter Server and both members are version VPN-1/FireWall-1 NG FP3, with the latest Hotfix. What is the correct upgrade procedure?
1. Change the version, in the General Properties of the gateway-cluster object.
2. Upgrade the SmartCenter Server, and reboot after upgrade.
3. Run cpstop on one member, while leaving the other member running. Upgrade one member at a time, and reboot after upgrade.
4. Reinstall the Security Policy.
A) 2, 4, 3, 1
B) 1, 3, 2, 4
C) 3, 2, 1, 4
D) 1, 2, 3, 4
E) 2, 3, 1, 4
3. Which operating system is NOT supported by VPN-1 SecureClient?
A) Windows 2000 Professional
B) Windows XP SP2
C) RedHat Linux 8.0
D) MacOS X
E) IPSO 3.9
4. What is the consequence of clearing the "Log VoIP Connection" box in Global Properties?
A) Dropped VoIP traffic is logged, but accepted VoIP traffic is not logged.
B) The SmartCenter Server stops importing logs from VoIP servers.
C) IP addresses are used, instead of object names, in log entries that reference VoIP Domain objects.
D) The log field setting in rules for VoIP protocols are ignored.
E) VoIP protocol-specific log fields are not included in SmartView Tracker entries.
5. You configure a Check Point QoS Rule Base with two rules: an H.323 rule with a weight of
10, and the Default Rule with a weight of 10. The H.323 rule includes a per-connection guarantee of 384 Kbps, and a per-connection limit of 512 Kbps. The per-connection guarantee is for four connections, and no additional connections are allowed in the Action properties. If traffic passing through the QoS Module matches both rules, which of the following statements is true?
A) Neither rule will be allocated more than 10% of available bandwidth.
B) 50% of available bandwidth will be allocated to the H.323 rule.
C) Each H.323 connection will receive at least 512 Kbps of bandwidth.
D) 50% of available bandwidth will be allocated to the Default Rule.
E) The H.323 rule will consume no more than 2048 Kbps of available bandwidth.
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: E | Question # 3 Answer: E | Question # 4 Answer: E | Question # 5 Answer: E |
We're so confident of our products that we provide no hassle product exchange.


By Maurice

