156-726.77 Sample Questions

156-726.77 Sample Questions & Answers

Three areas tie for the heaviest weight: identity-based access control, SSL and HTTPS traffic inspection, and application-control policy; smaller sections round it out with URL-filtering rules, UserCheck security notifications, and day-to-day log management.

Launch the full 156-726.77 simulator →

Showing 6 of 12 free samples.

  1. Question 1

    When analyzing Application Control data with SmartEvent, using the predefined queries, how are the events grouped? In order of:

    Show answer & explanation

    Correct answer: D

    SmartEvent groups Application Control events by the number of megabytes used, providing bandwidth consumption analysis to identify applications consuming the most network resources. This grouping method helps administrators prioritize bandwidth management policies and identify potential bandwidth abuse or unexpected application usage patterns. Analyzing by data volume is crucial for Application Control because it reveals the actual network impact of different applications beyond simple connection counts. The other grouping methods (date/time, rule applied, risk) do not provide the bandwidth utilization perspective that is essential for effective Application Control policy management and network optimization.

  2. Question 2

    Which of the following actions applies to a Risk Level of 4 - High?

    Show answer & explanation

    Correct answer: A

    Risk Level 4 (High) indicates applications that can cause data leakage or malware infection without user knowledge, representing severe security threats that operate silently in the background. These applications pose immediate danger because they can compromise systems or exfiltrate sensitive data without any visible indication to the user, making detection and prevention critical. Check Point Application Control uses this risk classification to help administrators prioritize security policies and blocking decisions. The other risk levels describe different threat categories: bypassing security (Risk Level 5), non-business applications (lower risk levels), and applications that require user interaction to cause harm (lower risk classifications).

  3. Question 3

    Dangerous websites are offering encrypted connections using HTTPS. The Chief Information Officer in your company decided to start inspecting such traffic. What step needs to be done in order to avoid SSL error messages when accessing sites?

    Show answer & explanation

    Correct answer: D

    To inspect HTTPS traffic without SSL error messages, the outbound certificate must be deployed to company clients so they trust the Check Point gateway acting as a Certificate Authority (CA). When the gateway intercepts SSL connections for inspection, it presents its own certificate to clients - without proper CA trust, browsers display security warnings. Deploying the gateway outbound certificate to the corporate certificate store enables transparent SSL inspection without user interruption. The other options are incorrect: bypass lists defeat the purpose of inspection, official certificates are not required for internal CA functionality, and automatic trust does not occur without proper certificate deployment.

  4. Question 4

    Which of these statements describes the Check Point URL Filtering software blade?

    Show answer & explanation

    Correct answer: B

    Check Point URL Filtering blade controls access to websites based on predefined and custom categories, providing administrators granular control over web browsing activities. The blade categorizes websites into groups such as social networking, gambling, malware, productivity tools, and business-related sites, enabling policy-based access control. URL Filtering integrates with ThreatCloud for real-time reputation updates and can enforce different access policies for different user groups or time periods. The other options describe different blades: ThreatCloud is the collaborative security network, Application Control blocks web applications, and IPS prevents vulnerability exploits rather than category-based web filtering.

  5. Question 5

    Which of the following actions applies to a Risk Level of 1 - Very Low?

    Show answer & explanation

    Correct answer: D

    Risk Level 1 (Very Low) applies to applications that are usually business-related with minimal security risk, representing legitimate enterprise applications that pose little threat to organizational security. These applications typically include standard business tools, productivity software, and approved enterprise applications that support business operations without introducing significant security vulnerabilities. Check Point Application Control assigns this low risk level to help administrators distinguish between essential business applications and potentially dangerous software. The other risk levels describe more severe threats: data leakage without user knowledge (High risk), security bypassing capabilities (Critical risk), and non-business applications (Medium risk).

  6. Question 6

    Which of these statements describes the Check Point IPS software blade?

    Show answer & explanation

    Correct answer: B

    Check Point IPS (Intrusion Prevention System) blade prevents vulnerability exploits by detecting and blocking network-based attacks in real-time before they can compromise systems. The IPS blade uses signature-based detection, protocol analysis, and behavioral monitoring to identify attack patterns and malicious traffic attempting to exploit known and unknown vulnerabilities. It provides comprehensive protection against network intrusions, denial of service attacks, and exploitation attempts targeting operating systems and applications. The other options describe different technologies: ThreatCloud is the collaborative security network, URL Filtering controls website access by category, and Application Control manages web application usage.

Ready for the real thing?

The full 156-726.77 simulator has every exam-style question, timed mode, and instant scoring.