Skip to content

156-521 Check Point Certified Automation Specialist R81.20 (CCAS) Practice Questions

Prepare for 156-521 with more than an answer.

226 questions in the full set20 sample questionsUpdated Jan 24, 2026
Exam fee
$300 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 7
  1. Introduction to Automation and Orchestration10%
  2. Check Point API Infrastructure15%
  3. Management API30%
  4. Gaia API20%
  5. Best Practices and Guidelines10%
  6. JSON and jq Utility10%
  7. Postman Integration5%
  1. 1

    A developer is writing a script to add 100 rules to a policy package. After the script runs, the changes are visible in the session but not to other administrators. What step was missed?

    Show answer details

    Correct answer: B

    In Check Point's management model, changes made during a session are private until they are 'published'. The publish command commits the changes to the database, making them visible to others and ready for installation.

  2. 2

    You need to add a new access rule to the 'Network' layer of the 'Standard' policy package. Which command syntax is correct?

    Show answer details

    Correct answer: A

    Rules are added to a specific Layer, not directly to a Package (since R80). You must specify the layer parameter. The layer name is often 'PackageName Network' (e.g., 'Standard Network').

  3. 3

    What is the primary function of the install-policy command in the Management API?

    Show answer details

    Correct answer: B

    The install-policy command triggers the compilation and distribution of the security policy to the enforcement points (gateways). This is distinct from publish, which saves changes to the management database.

  4. 4

    You are creating a script to bulk import objects from a CSV file. Which mgmt_cli flag allows you to read input directly from a CSV file?

    Show answer details

    Correct answer: B

    The --batch flag (or -b) allows mgmt_cli to read a file containing a list of commands or CSV data to execute in sequence, which is ideal for bulk operations.

  5. 5

    A script attempts to delete a host object named 'OldServer' but fails with an error stating the object is in use. Which API command would help identify where this object is being referenced?

    Show answer details

    Correct answer: B

    The where-used command identifies all policies, groups, and rules where a specific object is referenced. You must remove these references before the object can be deleted.

  6. 6

    An administrator wants to run a script that logs in, adds a host, and logs out. They want to avoid storing the session ID in a variable manually. Which mgmt_cli feature facilitates this when running multiple commands in a single session?

    Show answer details

    Correct answer: B

    When you login with mgmt_cli login > session.txt, you can subsequently use mgmt_cli ... -s session.txt. This reads the SID from the file automatically, simplifying script logic.

  7. 7

    You are tasked with automating the creation of NAT rules. Unlike access rules, NAT rules in R81.20 API are added to which policy type?

    Show answer details

    Correct answer: B

    NAT rules are managed in a separate NAT policy/layer associated with the package. You typically use add nat-rule package "Standard" ....

  8. 8

    A security architect is designing a solution to automatically update a dynamic blocklist of malicious IP addresses every hour based on a threat intelligence feed. The solution must minimize human intervention and ensure consistency across 50 gateways. Which concept best describes this implementation?

    Show answer details

    Correct answer: B

    This scenario describes Automation. Automation focuses on performing a single repetitive task (updating a blocklist) with minimal human intervention. Orchestration would involve coordinating multiple automated tasks across different systems and workflows.

  9. 9

    An organization is evaluating technologies to streamline their security operations. They need a method that allows them to execute complex sequences of tasks involving the Check Point Management Server, an ITSM ticketing system, and a vulnerability scanner. Which approach is most appropriate?

    Show answer details

    Correct answer: B

    SOAR platforms are designed specifically for Orchestration: coordinating workflows across disparate systems like firewalls, ticketing systems, and scanners. Simple scripting would be insufficient for complex cross-system coordination.

  10. 10

    A network team wants to reduce the time spent on manual rule creation requests. They implement a self-service portal where developers submit requests, which are then validated and automatically pushed to the firewall policy. What is the primary business benefit of this automation initiative?

    Show answer details

    Correct answer: B

    The primary benefits of automating manual tasks like rule creation are operational efficiency (speed) and the reduction of human error (consistency). While cost savings may follow, the direct impact is on operations and accuracy.

Create an account to continue.