156-215.81.20 Sample Questions

156-215.81.20 Sample Questions & Answers

Policy rules and packages make up the largest portion, with Gaia-based security architecture behind it, URL filtering and app control during traffic inspection, NAT rules, site-to-site VPNs, threat prevention, and backup and log maintenance.

Launch the full 156-215.81.20 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Monitoring and Logging · Firewall Debugging

    The command fw ctl zdebug drop is used on a Security Gateway to view real-time packet drops. An administrator runs this command and sees drops related to 'rule 0'. What does 'rule 0' signify in the context of the Check Point firewall policy?

    Show answer & explanation

    Correct answer: B

    'Rule 0' refers to the implicit cleanup rule that exists at the end of every Check Point security policy. If a packet does not match any of the user-defined rules above it, it will be caught and dropped by this rule. Seeing drops on rule 0 indicates that no explicit rule exists to allow that traffic.

  2. Question 2Intermediate

    Traffic Inspection and Control · HTTPS Inspection

    A network security engineer is configuring HTTPS Inspection to decrypt and inspect SSL/TLS traffic. After enabling the feature, users report receiving certificate warnings in their browsers when accessing HTTPS sites. Which of the following is the most critical step the engineer missed during the configuration?

    Show answer & explanation

    Correct answer: C

    For HTTPS Inspection to work, the Security Gateway performs a man-in-the-middle action. It presents its own certificate to the client, signed by its internal Certificate Authority (CA). If the client browsers do not trust this internal CA, they will generate certificate warnings. The solution is to export the gateway's CA certificate and deploy it to the 'Trusted Root Certification Authorities' store on all client machines.

  3. Question 3Beginner

    System Maintenance · CPUSE Command Line Interface

    To upgrade a Security Gateway using the Check Point Upgrade Service Engine (CPUSE) from the Gaia command line, which command should be used to view available packages, including the recommended Jumbo Hotfix Accumulator?

    Show answer & explanation

    Correct answer: D

    Within the Gaia Clish, the command show installer available-packages connects to the Check Point download center and lists all packages available for the specific hardware and software version, including hotfixes, jumbos, and major upgrades.

  4. Question 4Advanced

    Security Policy Management · Policy Layers Design

    A security architect is designing a policy for a large enterprise using R81.20's new Policy Layer capabilities. The goal is to have a baseline security policy for the entire organization, with specific, stricter policies for the PCI and Development environments that can be managed by different teams. The PCI policy must take precedence over the baseline. Which policy structure best achieves this?

    graph TD subgraph "Policy Package" A["Baseline Layer"] B["PCI Ordered Layer"] C["Dev Ordered Layer"] D["Final Cleanup Rule"] end B --> A C --> A A --> D

    Show answer & explanation

    Correct answer: D

    Ordered Layers are the ideal solution. They are evaluated as independent policy sets before the main layer. By placing the PCI Ordered Layer first, its rules are checked first. If a match is found with an action of Accept or Drop, processing stops, ensuring PCI rules take precedence. If no match is found in the PCI layer, processing continues to the next layer (e.g., Development) and then to the main baseline layer. This provides both precedence and delegation of administration.

  5. Question 5Intermediate

    Security Management Architecture · SmartWorkflow

    Case Study:

    A retail company, 'StyleStream', is deploying a new e-commerce platform. The architecture consists of web servers in a DMZ and database servers in a secure internal zone. The Security Management Server (SMS) and Security Gateway are both running R81.20.

    The lead security administrator has defined the following requirements:

    1. All administrative changes to the security policy must be reviewed and approved by a senior manager before they can be published and installed. This is a strict compliance requirement.
    2. The web servers in the DMZ must be accessible from the internet on port 443 (HTTPS). These servers must initiate connections to the database servers on port 1433 (MSSQL).
    3. No other traffic should be allowed from the DMZ to the internal database zone.
    4. Administrators should authenticate to SmartConsole using their corporate Active Directory credentials via SAML 2.0.

    To meet these requirements, the administrator needs to configure several key features. Which Check Point feature directly addresses the first requirement for mandatory change review and approval?

    Show answer & explanation

    Correct answer: B

    SmartWorkflow is a feature specifically designed for change management control. By enabling session approval, an administrator's changes are held in a pending state until a designated approver (like a senior manager) reviews and approves the session. Only after approval can the changes be published and installed, directly fulfilling the compliance requirement.

  6. Question 6Beginner

    Traffic Inspection and Control · CoreXL

    What is the primary function of CoreXL in the Check Point Security Gateway architecture?

    Show answer & explanation

    Correct answer: C

    CoreXL is a performance-enhancing technology that leverages multi-core processors. It creates multiple firewall kernel instances (FW workers) that run in parallel on different CPU cores. This allows the gateway to inspect multiple connections simultaneously, significantly increasing throughput and overall performance.

  7. Question 7Intermediate

    Monitoring and Logging · SmartLog Analysis

    An administrator is troubleshooting an issue where traffic that should be allowed by the Access Control policy is being dropped. They suspect an anti-spoofing issue. Which log field in SmartLog would most clearly indicate that a packet was dropped due to an anti-spoofing violation?

    Show answer & explanation

    Correct answer: C

    When a packet is dropped due to an anti-spoofing check, the log entry will typically have an Action of 'Drop', but the key differentiator is the 'Information' field. This field will contain a message like 'Packet dropped - Spoofing' or 'Packet is spoofed', explicitly stating the reason for the drop, distinguishing it from a drop caused by a policy rule.

  8. Question 8IntermediateSelect 2

    Traffic Inspection and Control · URL Filtering and Application Control

    A security team needs to implement a policy that blocks access to specific high-risk web categories, such as 'Phishing' and 'Malicious Sites', for all users. They also need to ensure that certain file types, like executables (.exe) and scripts (.bat), cannot be downloaded from any website, regardless of its category. Which security blades must be enabled and configured to meet both requirements? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    The URL Filtering blade is required to identify and block access to websites based on their categories, such as 'Phishing' and 'Malicious Sites'.

    The Application Control blade contains the Content Awareness feature. This feature is used to identify and block specific file types (like .exe and .bat) within web traffic, fulfilling the second requirement.

  9. Question 9Beginner

    Access Control and VPN · Site-to-Site VPN

    When creating a Site-to-Site VPN community, what is the purpose of defining the 'Encryption Domain' for a member gateway?

    Show answer & explanation

    Correct answer: C

    The Encryption Domain is a crucial part of a VPN configuration. It is a network object (or group of objects) that defines the IP address space of the networks behind the gateway that are permitted to participate in the VPN. Traffic originating from or destined to an IP within this domain will be encrypted and sent through the tunnel.

  10. Question 10Beginner

    Threat Prevention · Threat Extraction

    The Threat Extraction blade, when configured in 'Active' mode, removes potentially malicious content from files and delivers a sanitized version to the user instantaneously.

    Show answer & explanation

    Correct answer: A

    This statement is true. Threat Extraction is a part of Check Point's SandBlast Zero-Day Protection. It works by reconstructing files, removing active content like macros and embedded scripts, and delivering a clean, safe version to the user immediately. This prevents zero-day attacks without causing the delay associated with sandboxing (Threat Emulation).

Ready for the real thing?

The full 156-215.81.20 simulator has every exam-style question, timed mode, and instant scoring.