156-560 Sample Questions

156-560 Sample Questions & Answers

AWS, Azure and GCP deployment is the heaviest topic for CloudGuard, with the rest split between baseline threat-prevention concepts, unified policy and traffic-inspection management, CI/CD-driven automation, and Dome9 CSPM covering containers and workload protection.

Launch the full 156-560 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Deploying CloudGuard · Auto Scaling Architecture

    True or False: When deploying a CloudGuard Auto Scaling group for AWS, the Security Management Server (SMS) must be deployed in the same AWS region as the auto-scaling gateways to ensure proper functionality.

    Show answer & explanation

    Correct answer: B

    The Security Management Server, especially if it's Smart-1 Cloud, can be located anywhere with network connectivity to the gateways. It does not need to be in the same AWS region. The gateways are configured during bootstrap to connect to the specified management server, regardless of its location.

  2. Question 2Advanced

    Deploying CloudGuard · Troubleshooting Auto Scaling

    An e-commerce company uses AWS with an Auto Scaling group of CloudGuard gateways behind a Gateway Load Balancer (GWLB) to inspect traffic. During a sales event, traffic spikes, but the number of active gateways in the Auto Scaling group does not increase, leading to performance degradation. A review of CloudWatch metrics for the Auto Scaling group shows that CPU utilization is consistently below the scaling threshold. What is the MOST likely cause of this issue?

    Show answer & explanation

    Correct answer: C

    A common misconfiguration is to base scaling decisions solely on CPU utilization. Security gateways can become bottlenecks due to high network throughput, a large number of concurrent connections, or high packets per second, even when CPU usage is not high. The most likely cause is that the scaling trigger is not aligned with the actual performance bottleneck. The solution is to use a more relevant metric, such as a network-related metric or a custom Check Point metric, for scaling decisions.

  3. Question 3Intermediate

    Security for IaaS Clouds with Dome9 · Kubernetes Runtime Protection

    A security team is implementing CloudGuard Kubernetes runtime protection. They want to prevent a specific malicious behavior: a process inside a container attempting to load a kernel module. Which CloudGuard feature is designed to detect and block this type of activity in real-time?

    Show answer & explanation

    Correct answer: D

    CloudGuard's Kubernetes Runtime Protection uses an agent that monitors system calls (syscalls) made by processes within containers. Attempting to load a kernel module involves specific syscalls (init_module, finit_module). The Runtime Protection agent can detect these anomalous and potentially malicious syscalls, generating an alert or blocking the action based on the configured policy. Image scanning and admission control are pre-runtime checks, and threat hunting is a post-incident analysis tool.

  4. Question 4Beginner

    Introducing CloudGuard Protections · Deployment Modes

    A cloud administrator is configuring a CloudGuard Security Gateway in a 'Standalone' deployment mode. What does this deployment mode signify?

    Show answer & explanation

    Correct answer: B

    In Check Point terminology, a 'Standalone' deployment means that both the Security Gateway (which enforces the policy) and the Security Management Server (which manages the policy) are installed and run on the same machine or virtual instance. This is common for small deployments, labs, or proof-of-concept environments.

  5. Question 5Intermediate

    CloudGuard Security Policy · Multi-Cloud Dynamic Objects

    An organization is using CloudGuard to secure its multi-cloud environment, which includes AWS and Azure. The security policy needs to allow SSH access to all Linux servers for the IT administration team. The Linux servers in AWS are tagged with OS:Linux and in Azure are tagged with OS:Linux. To avoid creating separate rules for each cloud, the administrator wants to use a single dynamic object. What is the correct procedure to create a single policy object that represents all Linux servers across both clouds?

    Show answer & explanation

    Correct answer: C

    The correct method to represent assets from multiple, different cloud providers within a single policy object is to use a Group. You would first create a Data Center Query object for AWS filtering on the tag, then a second Data Center Query object for Azure filtering on the tag. Finally, you create a new Group object and add both of the Data Center Query objects to it. This group can then be used as a single entity in the source or destination of a security rule.

  6. Question 6Beginner

    Security for IaaS Clouds with Dome9 · Serverless Security

    A company is migrating its applications to a serverless architecture using AWS Lambda. The security team wants to ensure that these functions are protected against vulnerabilities and threats. Which CloudGuard product is specifically designed to provide runtime protection for serverless functions?

    Show answer & explanation

    Correct answer: C

    CloudGuard Workload Protection (part of the CWPP capabilities in the CNAPP suite) is the component designed to secure serverless functions. It provides runtime protection by analyzing the function's behavior, detecting threats, and preventing attacks without needing a network gateway.

  7. Question 7Beginner

    Automating CloudGuard Protections · Management API Authentication

    A cloud security architect wants to use the Check Point Management API to automate the creation of a new host object. The API call needs to be authenticated. Which command should be run first to obtain an authentication token (SID)?

    Show answer & explanation

    Correct answer: B

    Before any other API calls can be made to the Check Point Management API, a client must authenticate by sending a login command with valid credentials (username/password or an API key). The successful response to the login call contains a session identifier (SID) that must be included in the header of all subsequent API requests.

  8. Question 8Advanced

    Deploying CloudGuard · AWS Transit Gateway Integration

    A security engineer is analyzing traffic logs from a CloudGuard IaaS gateway and notices that traffic between two EC2 instances in the same VPC is being dropped. The security policy explicitly allows this traffic. The company is using an AWS Transit Gateway architecture. What is a possible reason for this behavior?

    Show answer & explanation

    Correct answer: C

    In a Transit Gateway architecture, it's critical to ensure symmetric routing, meaning both the request and response packets of a connection pass through the same CloudGuard gateway. If the VPC route tables are misconfigured, traffic might go to the gateway on the way to the destination but return directly, bypassing the gateway. The CloudGuard gateway's stateful firewall will see this as an invalid connection and drop the return packet. This is a common issue with complex cloud routing.

  9. Question 9Intermediate

    Security for IaaS Clouds with Dome9 · Kubernetes Admission Controller

    What is the primary function of the CloudGuard Admission Controller in a Kubernetes environment?

    graph TD A[Developer pushes new Pod manifest] --> B{CI/CD Pipeline} B --> C{Kubernetes API Server} C --> D[CloudGuard Admission Controller] D -- Validation --> C C -->|Policy Pass| E[Pod Scheduled] C -->|Policy Fail| F[Request Rejected]
    Show answer & explanation

    Correct answer: B

    The CloudGuard Admission Controller acts as a validating webhook for the Kubernetes API server. Its primary function is to enforce 'shift-left' security by intercepting deployment requests (e.g., creating a Pod or Deployment) and validating them against a defined security policy before they are persisted in the cluster. It can block deployments that use insecure images, have excessive privileges, or violate other configured rules.

  10. Question 10IntermediateSelect 2

    Deploying CloudGuard · AWS Gateway Load Balancer

    What are the key benefits of using the AWS Gateway Load Balancer (GWLB) with a fleet of CloudGuard Security Gateways? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

Ready for the real thing?

The full 156-560 simulator has every exam-style question, timed mode, and instant scoring.