Certified of 156-115.77 simulations materials and secret for Check Point certification for IT professionals, Real Success Guaranteed with Updated 156-115.77 pdf dumps vce Materials. 100% PASS Check Point Certified Security Master exam Today!

2021 Nov 156-115.77 vce

Q31. - (Topic 11) 

The current release of Check Point R77, what is a potential performance-related drawback to using Virtual Tunnel Interfaces (VTI) rather than Domain-based VPNs? 

A. Use of VTIs will disable CoreXL and therefore will negatively impact hardware platforms running more than one CPU core. 

B. Dynamic routing protocols will work across a domain-based VPN, but will not work across a VTI. 

C. Use of VTIs will disable the entire SecureXL mechanism and prevent any traffic acceleration. 

D. Domain-based VPNs are easier to configure than VTIs and therefore is the preferred implementation. 

Answer:


Q32. - (Topic 1) 

John is a Security Administrator of a Check Point platform. He has a mis-configuration issue that points to the Rule Base. To obtain information about the issue, John runs the command: 

A. fw debug fw on and checks the file fwm.elg. 

B. fw kdebug fwm on and checks the file fwm.elg. 

C. fw debug fwm on and checks the file fwm.elg. 

D. fw kdebug fwm on and checks the file fw.elg. 

Answer:

27. - (Topic 1) 

True or False: Software blades perform their inspection primarily through the kernel chain modules. 

A. False. Software blades do not pass through the chain modules. 

B. True. Many software blades have their own dedicated kernel chain module for inspection. 

C. True. All software blades are inspected by the IP Options chain module. 

D. True. Most software blades are inspected by the TCP streaming or Passive Streaming chain module. 

Answer:


Q33. - (Topic 6) 

From which version can you add Proxy ARP entries through the GAiA portal? 

A. R77.10 

B. R77 

C. R75.40 

D. R76 

Answer:


Q34. - (Topic 7) 

You are a system administrator and you are working with Support. Support asked you to enable kernel core dumps on the files. You are unsure if this has already been set. You run the command chkconfig -list kdump. Does the screen capture tell you if kernel dumps are enabled on this gateway? 

A. There is not enough information to determine if kernel core files will be generated. 

B. Yes kernel dump has been enabled and kernel files should be captured. 

C. Kdump has nothing to do with kernel core file generation. 

D. All values should be set to “on”. A kernel core dump will not be created. 

Answer:


Q35. - (Topic 6) 

You have a requirement to implement a strict security policy. With this in mind, you must create a stealth rule. How will this impact your packet acceleration? 

A. Using a stealth rule disables SecureXL. 

B. There will be no impact as long as the rule is not logged. 

C. NAT templates will not work. 

D. There will be no impact, since stealth rules do not affect SecureXL. 

Answer:


Refresh 156-115.77 free practice questions:

Q36. - (Topic 8) 

Where would you go to adjust the number of Kernels in CoreXL? 

A. Cpconfig 

B. fw ctl conf 

C. fw ctl affinity 

D. fw ctl multik stat 

Answer:


Q37. - (Topic 3) 

Adam wants to find idle connections on his gateway. Which command would be best suited for viewing the connections table? 

A. fw tab -t connections 

B. fw tab -t connections -u –f 

C. fw tab -t connections –x 

D. fw tab -t connections –s 

Answer:


Q38. - (Topic 5) 

In the policy below, which rule disables SecureXL? 

A. 5 

B. 1 

C. 4 

D. 3 

Answer:


Q39. - (Topic 1) 

The command _____________ shows which firewall chain modules are active on a gateway. 

A. fw stat 

B. fw ctl debug 

C. fw ctl chain 

D. fw ctl multik stat 

Answer:


Q40. - (Topic 5) 

How to check the overall SecureXL statistics: 

A. fwaccel on B. fwaccel stat 

C. cat /proc/ppk/statistics 

D. fwaccel conns 

Answer: