156-215.81 Dumps

156-215.81 Free Practice Test

CheckPoint 156-215.81: Check Point Certified Security Administrator R81

QUESTION 41

Which two Identity Awareness daemons are used to support identity sharing?

Correct Answer: D
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=

QUESTION 42

After trust has been established between the Check Point components, what is TRUE about name and IP-address changes?

Correct Answer: A

QUESTION 43

Which option, when applied to a rule, allows traffic to VPN gateways in specific VPN communities?

Correct Answer: B
The first rule is the automatic rule for the Accept All Encrypted Traffic feature. The Firewalls for the Security Gateways in the BranchOffices and LondonOffices VPN communities allow all VPN traffic from hosts in clients in these communities. Traffic to the Security Gateways is dropped. This rule is installed on all Security Gateways in these communities.
* 2. Site to site VPN - Connections between hosts in the VPN domains of all Site to Site VPN communities are allowed. These are the only protocols that are allowed: FTP, HTTP, HTTPS and SMTP.
* 3. Remote access - Connections between hosts in the VPN domains of RemoteAccess VPN community are allowed. These are the only protocols that are allowed: HTTP, HTTPS, and IMAP.

QUESTION 44

When defining group-based access in an LDAP environment with Identity Awareness, what is the BEST object type to represent an LDAP group in a Security Policy?

Correct Answer: A

QUESTION 45

What is the difference between SSL VPN and IPSec VPN?

Correct Answer: D