156-610 Check Point Certified Security Expert R82 - Practice Practice Questions
Prepare for 156-610 with more than an answer.
- Exam fee
- $50 USD
- Level
- Expert
- Valid for
- 2 years
Domains covered on the exam 7
- Management High Availability14%
- Advanced Policy Management14%
- Site-to-Site VPN14%
- Advanced Security Monitoring14%
- Security Gateway Upgrades14%
- Advanced Upgrades and Migrations15%
- ElasticXL Cluster15%
- 1
What is the primary benefit of using 'Inline Layers' in an R82 Access Control Policy?
Show answer details
Correct answer: A
Inline Layers (or sub-policies) enable delegation of control, allowing specific administrators to manage parts of the rulebase without affecting the main policy, and improve rulebase organization.
- 2
A customer wants to use an 'Updatable Object' for Microsoft 365 services in their policy. Which requirement must be met by the Security Gateway to successfully enforce this object?
Show answer details
Correct answer: A
Updatable Objects are maintained by Check Point and hosted in the cloud. The Security Gateway downloads these updates directly, so it requires internet connectivity (or a proxy).
- 3
Select TWO valid ways to enable 'Content Awareness' in an R82 Security Policy. (Select TWO)
Show answer details
Correct answer: A, B
Content Awareness is activated by enabling the blade on the layer and can be used to filter files and data types.
Using Data Type objects in the Content column allows granular control over specific file types or content patterns.
- 4
Case Study: Company A has two internet links (ISP1 and ISP2). They have a Site-to-Site VPN with Company B. The VPN must always use ISP2 for traffic to Company B unless ISP2 fails, in which case it should use ISP1. However, regular internet traffic should use ISP1 as primary.
Which 'Link Selection' method should be configured on Company A's gateway for the VPN?
Show answer details
Correct answer: A
Configuring Link Selection in High Availability mode allows specifying an ordered list of links for VPN traffic specifically, separate from the OS routing table used for general traffic.
- 5
In an R82 Site-to-Site VPN, what is the purpose of configuring a 'Permanent Tunnel'?
Show answer details
Correct answer: A
Permanent Tunnels constantly send keep-alive packets (Tunnel Test) to monitor the status of the VPN link, ensuring it is up before traffic is sent and facilitating faster failure detection.
- 6
You are troubleshooting a VPN negotiation failure. The log shows 'Main Mode packet 1 sent' but no response is received. Which diagrams best represents the initial flow where the failure is occurring, and what is the likely cause?
Show answer details
Correct answer: A
If Packet 1 (Proposal) is sent but no Packet 2 is received, it usually indicates a network connectivity issue or that a device in between (or the target) is blocking IKE (UDP 500).
sequenceDiagram participant Source participant Destination Source->>Destination: IKE MM Packet 1 (Proposal) Note over Destination: No Response - 7
A Senior Security Administrator is troubleshooting a synchronization issue between the Primary and Secondary Security Management Servers in an R82 environment. The SmartConsole status indicates a 'Collision' state. Based on the architecture flow below, which action describes the correct behavior of the system to resolve this collision without administrator intervention?
Show answer details
Correct answer: B
In a 'Collision' state, the system cannot automatically decide which changes are correct because both servers have been modified independently. The administrator must intervene manually to choose which peer overwrites the other.
- 8
Which Check Point command line tool is MOST appropriate for checking the detailed synchronization status of a Multi-Domain Security Management environment in R82?
Show answer details
Correct answer: C
The
cpm_status.shscript located in the MDS directory is the correct tool to verify the status of the Check Point Management (CPM) process and synchronization in R80+ and R82 management environments.
