156-561 Sample Questions

156-561 Sample Questions & Answers

CloudGuard network security spans eight equally weighted areas, from reference architectures and auto-scaling the management server to cloud clustering for high availability, adaptive policy, deployment automation, and gateway troubleshooting.

Launch the full 156-561 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Introducing CloudGuard · Platform overview

    A multinational retail bank is migrating its core payment processing application to Azure. The bank's compliance team mandates that all traffic entering the application must undergo deep packet inspection, zero-day threat extraction, and application-level control.

    The cloud operations team argues that native Azure Network Security Groups (NSGs) and Azure Firewall Basic are sufficient to meet these requirements while keeping costs low.

    As the Lead Security Architect, you must justify the deployment of Check Point CloudGuard Network Security instead of relying solely on the native basic controls. Which of the following provides the most accurate architectural justification for this decision?

    graph TD Internet((Internet)) --> NativeFW[Native Cloud Basic Firewall] Internet --> CG[CloudGuard Network Security] NativeFW -->|Layer 3/4 Only| App1[Payment App] CG -->|Layer 7 + Threat Extraction| App2[Payment App] style NativeFW fill:#ff9999 style CG fill:#99ff99
    Show answer & explanation

    Correct answer: D

    This is the optimal answer. Native Network Security Groups (NSGs) in Azure are stateful, Layer 3/4 packet filters. They can block or allow traffic based on IP addresses, ports, and protocols, but they cannot look inside the payload to identify specific applications, nor can they perform advanced functions like Intrusion Prevention (IPS) or Zero-Day Threat Extraction (SandBlast). CloudGuard Network Security provides this required Layer 7 visibility and advanced threat prevention.

  2. Question 2IntermediateSelect 2

    Introducing CloudGuard · Platform overview

    While analyzing the security posture of an AWS environment, a consultant notices that the organization relies entirely on AWS Security Groups. Which TWO advanced capabilities will the organization gain by implementing Check Point CloudGuard Network Security Gateways? (Select TWO)

    Show answer & explanation

    Correct answers: C, D

    AWS Security Groups are stateful firewalls operating at Layer 3/4. They provide stateful inspection of TCP connections and basic IP/port filtering, but they cannot look inside the packet payload. CloudGuard Network Security adds Layer 7 visibility, allowing for deep packet inspection, malware detection, and zero-day threat prevention (SandBlast) which native security groups lack.

    AWS Security Groups are stateful firewalls operating at Layer 3/4. They provide stateful inspection of TCP connections and basic IP/port filtering, but they cannot look inside the packet payload. CloudGuard Network Security adds Layer 7 visibility, allowing for deep packet inspection, malware detection, and zero-day threat prevention (SandBlast) which native security groups lack.

  3. Question 3Intermediate

    CloudGuard Network Security Architectures · Single gateway, scaling, and clustering architectures

    A manufacturing enterprise is designing a multi-VNet architecture in Azure. They require all traffic moving between their "HR" VNet and "Finance" VNet to be inspected by a Check Point CloudGuard Gateway. Which architectural model is best suited for this requirement?

    Show answer & explanation

    Correct answer: D

    A Hub-and-Spoke architecture is the standard and most efficient design for East-West traffic inspection in cloud environments. The "HR" and "Finance" VNets act as spokes. Instead of peering them directly to each other (which bypasses inspection), both are peered to a central "Hub" VNet. User Defined Routes (UDRs) in the spoke VNets force inter-spoke traffic through the CloudGuard Gateway residing in the Hub, enabling full security inspection.

  4. Question 4Intermediate

    CloudGuard Network Security Architectures · Single gateway, scaling, and clustering architectures

    When integrating Check Point CloudGuard Network Security with AWS Transit Gateway (TGW) for East-West inspection, which AWS service is commonly utilized alongside CloudGuard Auto Scaling to ensure symmetric routing and high throughput without requiring Source NAT (SNAT)?

    Show answer & explanation

    Correct answer: A

    AWS Gateway Load Balancer (GWLB) is designed specifically to integrate third-party virtual appliances like Check Point CloudGuard. It uses the GENEVE encapsulation protocol to forward traffic to the firewall appliances while preserving the original source and destination IP addresses. This eliminates the need for Source NAT (SNAT) to maintain symmetric routing in an active-active auto-scaling environment.

  5. Question 5Beginner

    CloudGuard Network Security Architectures · Single gateway, scaling, and clustering architectures

    A cloud architect is designing an architecture to protect web servers hosted in a public cloud. They decide to place a public-facing load balancer that receives traffic from the internet and forwards it to the Check Point CloudGuard Gateway cluster, which then inspects and routes it to the web servers. This specific flow is best described as:

    Show answer & explanation

    Correct answer: D

    Ingress architecture refers to the design handling inbound traffic originating from the outside (e.g., the Internet) and flowing into the cloud environment. Placing a load balancer in front of the CloudGuard gateways to handle incoming web requests is a classic North-South Ingress pattern. Egress handles outbound traffic, and East-West handles lateral traffic.

  6. Question 6Beginner

    CloudGuard Network Security Architectures · Single gateway, scaling, and clustering architectures

    The architectural pattern where traffic moving laterally between two subnets or VNets/VPCs is redirected through a CloudGuard Gateway for inspection is known as ________ inspection.

    Show answer & explanation

    Correct answer: D

    East-West traffic refers to lateral network communication within a data center or cloud environment (e.g., between a web tier and a database tier, or between two peered VNets). Routing this lateral traffic through a CloudGuard Gateway provides East-West inspection, preventing threats from moving laterally if one segment is compromised.

Ready for the real thing?

The full 156-561 simulator has every exam-style question, timed mode, and instant scoring.