156-315.81 Sample Questions

156-315.81 Sample Questions & Answers

ClusterXL and advanced gateway high availability take the biggest slice, with management-server redundancy, dynamic-object deployments, remote and site VPN connections, identity-aware access, custom threat prevention, SmartEvent reporting, and performance tuning.

Launch the full 156-315.81 simulator →

Showing 10 of 20 free samples.

  1. Question 1AdvancedSelect 2

    Custom Threat Prevention · HTTPS Inspection Configuration

    A hospital is deploying HTTPS Inspection on its R81.20 gateways to inspect outbound traffic from clinical workstations. To comply with privacy regulations, traffic to specific financial and healthcare domains must not be decrypted. The security team also wants to ensure that if the gateway's CPU utilization for the fwk worker process exceeds 85%, HTTPS Inspection is temporarily bypassed to maintain network performance. Which two configuration steps are required to meet these requirements?

    Show answer & explanation

    Correct answers: B, C

    The HTTPS Inspection policy is the correct place to define bypass rules. Creating rules that match traffic destined for the sensitive financial and healthcare domains and setting their action to 'Bypass' will prevent decryption for compliance purposes.

    This is a specific performance-related feature within the gateway's HTTPS Inspection settings. Enabling it allows the gateway to automatically and temporarily bypass inspection when CPU load on the relevant worker processes (fwk) is high, thus preserving network availability and performance.

  2. Question 2Intermediate

    Performance Tuning · CoreXL Dynamic Dispatcher Monitoring

    A system administrator notices that the Dynamic Dispatcher on a 16-core Security Gateway is assigning most traffic to a small subset of firewall instances, leading to high CPU on those cores while others remain underutilized. They have confirmed that SecureXL is enabled and connection templates are being used. Which CoreXL command should the administrator run to get a detailed, real-time view of the packet distribution per firewall instance (core)?

    Show answer & explanation

    Correct answer: A

    fw ctl multik stat is the correct command to display real-time statistics for CoreXL, including the number of packets being processed by each firewall instance (worker core). This output allows an administrator to immediately identify an imbalanced distribution caused by the Dynamic Dispatcher.

  3. Question 3Beginner

    Advanced VPN Configuration · Route-Based VPN Concepts

    When implementing a route-based VPN (VTIs) on an R81.20 gateway, where is the encryption domain defined?

    Show answer & explanation

    Correct answer: C

    In a route-based VPN, the concept of a statically defined encryption domain is replaced by the routing table. Any traffic that is routed to the VTI by the gateway's routing table (either via static routes or a dynamic routing protocol like BGP) is considered part of the 'encryption domain' and will be encrypted and sent over the tunnel.

  4. Question 4Intermediate

    Advanced Deployments · Updatable Objects Configuration

    A global logistics company uses Updatable Objects to block traffic from Geo-locations known for malicious activity. The Security Management Server is in an isolated network segment with no direct internet access, but it can reach a dedicated proxy server. How must the administrator configure the Security Gateway and Management Server to allow the Updatable Objects to be updated successfully?

    graph TD Internet((Internet)) --> Proxy[Proxy Server] subgraph DMZ Proxy end subgraph MgmtNet [Management Network] SMS[Security Management Server] end subgraph InternalNet [Internal Network] GW[Security Gateway] end SMS --> Proxy GW --> Internet

    Show answer & explanation

    Correct answer: A

    The Security Management Server is responsible for downloading updates for Updatable Objects from Check Point's cloud services. In an environment where the SMS has no direct internet, it must be configured to use a proxy. This is done in the Gaia Portal of the SMS. Once the SMS downloads the updates, it distributes them to the managed Security Gateways during policy installation. The gateways themselves do not need direct internet or proxy access for this specific feature.

  5. Question 5Advanced

    Management High Availability · Geo-Clustered Management HA Design

    Case Study

    A retail corporation, 'GlobalMart', is upgrading its security infrastructure to a distributed R81.20 environment. They have two primary data centers (DC-A and DC-B) which will each host a Security Management Server in a Management High Availability (HA) configuration. The Primary SMS will be in DC-A, and the Secondary SMS will be in DC-B. A dedicated Log Server will also be deployed in each data center, and gateways will be configured to send logs to their local Log Server.

    Current Situation: All management components are currently on a single R80.40 server. The network team has provisioned new appliances for the R81.20 upgrade. The data centers are connected via a high-speed, low-latency WAN link. The primary goal is to ensure management redundancy and localized logging to reduce WAN traffic, with seamless failover in case the primary data center becomes unavailable.

    Requirements:

    1. Establish a resilient Management HA pair between DC-A and DC-B.
    2. Security Gateways in DC-A must log to the Log Server in DC-A. Gateways in DC-B must log to the Log Server in DC-B.
    3. In the event of a failure of the Log Server in DC-A, the DC-A gateways must automatically start sending logs to the Log Server in DC-B.
    4. The solution must be configured following Check Point best practices for performance and redundancy.

    Which configuration approach best satisfies all of GlobalMart's requirements?

    Show answer & explanation

    Correct answer: D

    This is the Check Point best practice for achieving logging redundancy. By creating a Log Server Cluster object and adding both Log Servers to it, the gateways can be configured to send logs to the cluster. This abstraction layer handles the failover automatically. If the primary defined logger (the local one) fails, the gateway will seamlessly redirect its logs to the other member of the cluster (the remote one), fulfilling all requirements without manual intervention.

  6. Question 6Intermediate

    Advanced Troubleshooting · VPN IKE Debugging

    A security engineer is troubleshooting a site-to-site VPN tunnel between an R81.20 gateway and a Cisco ASA. The tunnel fails to establish Phase 1. The engineer runs the command vpn debug trunc and reviews the ike.elg file. They find messages indicating 'NO_PROPOSAL_CHOSEN'. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: B

    The 'NO_PROPOSAL_CHOSEN' error message is a standard IKE notification that indicates the initiating peer sent a set of cryptographic proposals (e.g., AES-256 for encryption, SHA-256 for integrity, Diffie-Hellman group 14 for key exchange) for Phase 1, but the responding peer could not find a matching proposal in its own configuration that it was willing to accept. This points directly to a mismatch in the Phase 1 properties.

  7. Question 7Intermediate

    ClusterXL and Advanced Gateway HA · ClusterXL Synchronization Exclusion

    To optimize performance, an administrator wants to prevent synchronization of high-volume UDP DNS traffic within a ClusterXL cluster. Which is the correct method to create this exclusion?

    Show answer & explanation

    Correct answer: C

    The correct and supported method for excluding specific services from state synchronization is to modify the service object's properties in SmartConsole. By unchecking the 'Synchronize connections on cluster' option within the advanced properties of the UDP/53 service object, you instruct the cluster not to sync state table entries for this traffic, which is a best practice for high-volume, stateless protocols like DNS.

  8. Question 8BeginnerSelect 2

    Identity Awareness and Access Control · Identity Collector Sources

    An administrator is configuring Identity Awareness using an Identity Collector. Which two of the following are valid Identity Sources for the Identity Collector? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    The Identity Collector can be configured to parse syslog messages from various sources, including RADIUS servers, to extract user, IP, and event information for identity mapping.

    The Identity Collector is designed to query Microsoft Active Directory Domain Controllers for security event logs to identify user logins and map them to IP addresses. This is a primary and common identity source.

  9. Question 9Intermediate

    Custom Threat Prevention · IPS False Positive Handling

    A new custom application uses a proprietary TCP protocol on port 31337. The IPS blade is flagging this legitimate traffic as malicious due to a generic protocol anomaly signature. The administrator needs to prevent the IPS from inspecting this specific traffic while continuing to inspect all other traffic. What is the most precise and efficient way to achieve this?

    Show answer & explanation

    Correct answer: B

    Creating an exception within the Threat Prevention Profile is the recommended method. This allows the administrator to specifically exclude the custom application's service (TCP/31337) from IPS inspection. This is more precise than disabling a signature (which might be useful for other traffic) and more secure than bypassing all Threat Prevention for the server.

  10. Question 10Beginner

    ClusterXL and Advanced Gateway HA · VMAC Mode Concept

    True or False: In a ClusterXL High Availability configuration, enabling VMAC (Virtual Media Access Control) mode eliminates the need for hosts on the network to update their ARP cache after a cluster failover.

    Show answer & explanation

    Correct answer: A

    This statement is true. When VMAC mode is enabled, all cluster members use the same virtual MAC address for the cluster virtual IP address. Upon failover, the new active member starts using this same virtual MAC. Because the MAC address associated with the VIP does not change from the perspective of other network devices, there is no need for gratuitous ARPs or for connected switches and hosts to update their ARP tables, resulting in a faster and more seamless failover.

Ready for the real thing?

The full 156-315.81 simulator has every exam-style question, timed mode, and instant scoring.