Validated of 156-115.77 exam prep materials and rapidshare for Check Point certification for IT engineers, Real Success Guaranteed with Updated 156-115.77 pdf dumps vce Materials. 100% PASS Check Point Certified Security Master exam Today!

2021 Nov 156-115.77 free download

Q121. - (Topic 11) 

You are configuring dynamic routing on Secure Platform, as the administrator you run the command pro enable and reboot. You are confident that your configuration has been done correctly. When you check, you find the dynamic routing daemon has not started. What is the likely cause of this issue? 

A. Secure Platform does not support dynamic routing. 

B. You need to apply the license and push the policy. 

C. Dynamic routing needs to be enabled in cpconfig. 

D. You must push the policy after your reboot. 

Answer:


Q122. - (Topic 5) 

Which of the following statements are TRUE about SecureXL? 

I. SecureXL is able to accelerate all connections through the firewall. 

II. Medium path acceleration will still cause some CPU utilization of CoreXL cores. 

III. F2F connections represent “forwarded to firewall” connections that are not accelerated and fully processed through the firewall kernel. 

IV.

 Packets going through SecureXL must be inspected by the firewall kernel before being accelerated. 

A. 

II and III 

B. 

I, II, and III 

C. 

III and IV 

D. 

I and IV 

Answer:


Q123. - (Topic 10) 

Which of the following is true when IPv6 is enabled on a Security Gateway? 

A. An interface on the Gateway can either have IPv4 or IPv6 IP address or have both. 

B. As of version R77, IPv6 is only supported on Security Management Server. 

C. IPv4 will be completely disabled when IPv6 has been enabled. 

D. An interface on the Gateway can either have IPv4 or IPv6 IP address but cannot have both. 

Answer:

240. - (Topic 10) 

What VSX components do not support IPv6 in R77 VSX mode? 

A. VSX mode does not support IPv6 

B. All devices support IPv6 

C. Virtual Systems 

D. Virtual Routers 

Answer:


Q124. - (Topic 10) 

Does R77 SmartDashboard support IPv6? 

A. Yes provided the operating system on which Smart Dashboard is installed is configured with IPv6. 

B. SmartDashboard does not support IPv6. 

C. IPv6 needs to be tunneled through IPv4 to support IPv6. 

D. R77.20 and above provides the support for Smart Dashboard and IPv6 support. 

Answer:


Q125. - (Topic 1) 

You are troubleshooting a Security Gateway, attempting to determine which chain is causing a problem. What command would you use to show all the chains through which traffic passed? 

A. [Expert@HostName]# fw ctl chain 

B. [Expert@HostName]# fw monitor -e "accept;" -p all 

C. [Expert@HostName]# fw ctl debug –m 

D. [Expert@HostName]# fw ctl zdebug all 

Answer:


Most up-to-date 156-115.77 exam fees:

Q126. - (Topic 1) 

What does the IP Options Strip represent under the fw chain output? 

A. IP Options Strip is not a valid fw chain output. 

B. The IP Options Strip removes the IP header of the packet prior to be passed to the other kernel functions. 

C. The IP Options Strip copies the header details to forward the details for further IPS inspections. 

D. IP Options Strip is only used when VPN is involved. 

Answer:

Topic 2, NAT 


Q127. - (Topic 3) 

Your customer receives an alert from their network operation center, they are seeing ARP and Ping scans of their network originating from the firewall..What could be the reason for the behaviour? 

A. Check Point firewalls probe adjacent networking devices during normal operation. 

B. IPS is disabled on the firewalls and there is a known OpenSSL vulnerability that allows a hacker to cause a network scan to originate from the firewall. 

C. One or both of the firewalls in a cluster have stopped receiving CCP packets on an interface. 

D. Check Point's Antibot blade performs anti-bot scans of the surrounding network. 

Answer:


Q128. - (Topic 9) 

Your Customer would like to enable IPS in his Corporate Cluster, but he is concerned about high CPU usage because if the IPS inspection. What feature would you configure to disable inspection if a high CPU usage develops? 

A. It is not possible. In this case no enable IPS 

B. Bypass Under Load. (In IPS Option on Gateway Properties) 

C. Bypass Inspection. (In IPS Option on Gateway Properties) 

D. Disable Inspection. (In IPS Option on Gateway Properties) 

Answer:


Q129. - (Topic 3) 

In order to prevent outgoing NTP traffic from being hidden behind a Cluster IP you should? 

A. Edit the relevant table.def on the Management Server and add the line no_hide_services_ports = { <17, 123> }; and then push policy. 

B. Edit the relevant table.def on the gateway and add the line no_hide_services_ports = { <17, 123> };. 

C. Edit the relevant table.def on the Management Server and add the line no_hide_services_ports = { <123, 17> }; and then push policy. 

D. Edit the relevant table.def on the gateway and add the line no_hide_services_ports = { <123, 17> }. 

Answer:


Q130. - (Topic 2) 

You are attempting to establish an FTP session between your computer and a remote server, but it is not being completed successfully. You think the issue may be due to IPS. Viewing SmartView Tracker shows no drops. How would you confirm if the traffic is actually being dropped by the gateway? 

A. Search the connections table for that connection. 

B. Run a fw monitor packet capture on the gateway. 

C. Look in SmartView Monitor for that connection to see why it’s being dropped. 

D. Run fw ctl zdebug drop on the gateway. 

Answer: