156-915.80 Dumps

156-915.80 Free Practice Test

Check-Point 156-915.80: Check Point Certified Security Expert Update - R80

QUESTION 31

- (Exam Topic 2)
A Web server behind the Security Gateway is set to Automatic Static NAT. Client side NAT is not checked in the Global Properties. A client on the Internet initiates a session to the Web Server. Assuming there is a rule allowing this traffic, what other configuration must be done to allow the traffic to reach the Web server?

Correct Answer: C

QUESTION 32

- (Exam Topic 1)
What is a feature that enables VPN connections to successfully maintain a private and secure VPN session without employing Stateful Inspection?

Correct Answer: C
Wire Mode is a VPN-1 NGX feature that enables VPN connections to successfully fail over, bypassing Security Gateway enforcement. This improves performance and reduces downtime. Based on a trusted source and destination, Wire Mode uses internal interfaces and VPN Communities to maintain a private and secure VPN session, without employing Stateful Inspection. Since Stateful Inspection no longer takes place, dynamic-routing protocols that do not survive state verification in non-Wire Mode configurations can now be deployed. The VPN connection is no different from any other connections along a dedicated wire, thus the meaning of "Wire Mode".

QUESTION 33

- (Exam Topic 3)
How do you configure the Security Policy to provide user access to the Captive Portal through an external (Internet) interface?

Correct Answer: A

QUESTION 34

- (Exam Topic 3)
Fill in the blank. To save your OSPF configuration in GAiA, enter the command .
Solution:
save config

Does this meet the goal?

Correct Answer: A

QUESTION 35

- (Exam Topic 3)
A ClusterXL configuration is limited to members.

Correct Answer: C