Question No: 6

Which of the following is a CLI command for Security Gateway R80?

A. fw tab -u

B. fw shutdown

C. fw merge

D. fwm policy_print <policyname>

Answer: A

Question No: 7

Which of the following tools is used to generate a Security Gateway R80 configuration report?

A. fw cpinfo

B. infoCP

C. cpinfo

D. infoview

Answer: C

Question No: 8

Which features are only supported with R80.10 Gateways but not R77.x?

A. Access Control policy unifies the Firewall, Application Control & URL Filtering, Data Awareness, and Mobile Access Software Blade policies.

B. Limits the upload and download throughput for streaming media in the company to 1 Gbps.

C. The rule base can be built of layers, each containing a set of the security rules. Layers are inspected in the order in which they are defined, allowing control over the rule base flow and which security functionalities take precedence.

D. Time object to a rule to make the rule active only during specified times.

Answer: C

Question No: 9

Type the command and syntax you would use to verify that your Check Point cluster is functioning correctly.


cphaprob state

Question No: 10

Your primary Security Gateway runs on GAiA. What is the easiest way to back up your Security Gateway R80 configuration, including routing and network configuration files?

A. Copying the directories $FWDIR/conf and $FWDIR/lib to another location.

B. Using the native GAiA backup utility from command line or in the Web based user interface.

C. Using the command upgrade_export.

D. Run the pre_upgrade_verifier and save the .tgz file to the directory /temp.

Answer: B

Question No: 11

Type the full cphaprob command and syntax that will show full synchronization status.


cphaprob -i list

Question No: 12

Which file gives you a list of all security servers in use, including port number?

A. $FWDIR/conf/conf.conf

B. $FWDIR/conf/servers.conf

C. $FWDIR/conf/fwauthd.conf

D. $FWDIR/conf/serversd.conf

Answer: C

Question No: 13

ALL of the following options are provided by the GAiA sysconfig utility, EXCEPT:

A. Export setup

B. DHCP Server configuration

C. Time & Date

D. GUI Clients

Answer: D

Question No: 14

You just installed a new Web server in the DMZ that must be reachable from the Internet. You create a manual Static NAT rule as follows:

Source: Any || Destination: web_public_IP || Service: Any || Translated Source: original || Translated Destination: web_private_IP || Service: Original

u201cweb_public_IPu201d is the node object that represents the new Web serveru2019s public IP address. u201cweb_private_IPu201d is the node object that represents the new Web siteu2019s private IP address. You enable all settings from Global Properties > NAT.

When you try to browse the Web server from the Internet you see the error u201cpage cannot be displayedu201d. Which of the following is NOT a possible reason?

A. There is no Security Policy defined that allows HTTP traffic to the protected Web server.

B. There is no ARP table entry for the protected Web serveru2019s public IP address.

C. There is no route defined on the Security Gateway for the public IP address to the Web serveru2019s private IP address.

D. There is no NAT rule translating the source IP address of packets coming from the protected Web server.

Answer: D

Question No: 15

Which of the following statements accurately describes the command upgrade_export?

A. upgrade_export stores network-configuration data, objects, global properties, and the database revisions prior to upgrading the Security Management Server.

B. Used primarily when upgrading the Security Management Server, upgrade_export stores all object databases and the /conf directories for importing to a newer Security Gateway version.

C. upgrade_export is used when upgrading the Security Gateway, and allows certain files to be included or excluded before exporting.

D. This command is no longer supported in GAiA.

Answer: B

