156-915.80 Check Point Certified Security Expert Update - R80 Practice Questions
Prepare for 156-915.80 with more than an answer.
- Exam fee
- $250 USD
- Time limit
- 90 minutes
- Questions on the exam
- 90
- Passing score
- 70% (scale 0-100)
- Level
- Expert
- Valid for
- 2 years
Domains covered on the exam 7
- Security Management Architecture15%
- Access Control and Threat Prevention20%
- Network Address Translation10%
- VPN and Remote Access15%
- ClusterXL and High Availability15%
- Advanced Monitoring and Troubleshooting15%
- Advanced Features and Optimization10%
- 1
Which of the following is NOT an internal/native Check Point command?
Show answer details
Correct answer: B
tcpdump is NOT an internal Check Point command but rather a standard Linux network packet analyzer tool available in Expert mode. While Check Point provides native commands like fw monitor for packet capture with Check Point-specific filtering and cpview for system monitoring, tcpdump is inherited from the underlying Linux operating system. Understanding the distinction between native Check Point tools and standard Linux utilities is crucial for effective troubleshooting and proper diagnostic methodology in Check Point environments.
- 2
What is the SandBlast Agent designed to do?
Show answer details
Correct answer: C
SandBlast Agent is designed to prevent malware lateral movement within the network if malware successfully enters an end user's system. The agent provides endpoint protection, behavioral analysis, and network-level containment to stop infected endpoints from spreading threats to other network resources. This endpoint-to-network protection is critical for limiting breach impact and providing time for incident response in enterprise security architectures. Reference: https://www.checkpoint.com/downloads/product-related/datasheets/ds-sandblast- agent.pdf
- 3
The SmartEvent R80 Web application for real-time event monitoring is called:
Show answer details
Correct answer: A
SmartView Monitor is the SmartEvent R80 web application used for real-time event monitoring, providing a centralized interface for viewing security events, system status, and performance metrics. This web-based monitoring tool enables administrators to track security incidents, analyze event correlations, and monitor system health in real-time without requiring thick client installations. SmartView Monitor is essential for 24/7 security operations and rapid incident response in enterprise Check Point environments. Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_LoggingAndMonitoring/html_frameset.htm?t opic=documents/R80/CP_R80_LoggingAndMonitoring/120829
- 4
What Shell is required in Gaia to use WinSCP?
Show answer details
Correct answer: C
Bash shell is required in Gaia to use WinSCP for secure file transfer operations. WinSCP relies on bash shell capabilities for executing file operations, directory navigation, and maintaining secure communication protocols. The bash shell provides the necessary command execution environment that WinSCP requires for its SCP and SFTP operations, making it essential for remote file management and configuration backup/restore procedures in Check Point Gaia environments. Reference: https://winscp.net/eng/docs/ui_login_scp
- 5
Which one of the following is true about Threat Emulation?
Show answer details
Correct answer: A
Threat Emulation analysis takes less than 3 minutes to complete, providing rapid malware detection and analysis for real-time threat prevention. This quick analysis time enables near real-time protection without significantly impacting network performance or user experience. The speed is achieved through optimized virtual execution environments and efficient behavior analysis algorithms, making Threat Emulation suitable for high-throughput enterprise networks requiring immediate threat response and minimal latency impact.
- 6
What are the minimum open server hardware requirements for a Security Management Server/Standalone in R80.10?
Show answer details
Correct answer: D
The minimum hardware requirements for Security Management Server/Standalone in R80.10 are 4 CPU cores, 8GB RAM, and 500GB disk space. These specifications ensure adequate performance for policy management, log processing, and database operations in typical enterprise environments. The requirements reflect the increased resource demands of R80.10's enhanced features including unified policy management, advanced logging capabilities, and improved management architecture compared to previous versions. Reference: http://dl3.checkpoint.com/paid/db/dbf0aa7672f1dd6031e6096b40510674/CP_R80.10_ReleaseNot es.pdf?HashKey=1522175073_c4e7fc63c894ad28b3fbe49f9430c023&xtn=.pdf page 16
- 7
The “MAC magic” value must be modified under the following condition:
Show answer details
Correct answer: C
The "MAC magic" value must be modified when a firewall cluster is configured to use Broadcast for CCP (Cluster Control Protocol) traffic. This modification prevents MAC address conflicts and ensures proper cluster communication in broadcast-based CCP configurations. The MAC magic value provides unique addressing for cluster members communicating via broadcast, preventing network confusion and ensuring reliable cluster state synchronization in complex network topologies. Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails= &solutionid=sk25977
- 8
What is the port used for SmartConsole to connect to the Security Management Server:
Show answer details
Correct answer: B
SmartConsole connects to the Security Management Server using CPM (Check Point Management) port 19009/TCP, which is the dedicated management communication port for R80 and later versions. This port handles all SmartConsole administrative traffic including policy installation, object management, and real-time monitoring. SIC port 18191 is used for Secure Internal Communication between gateways and management, CPMI port 18191 is legacy, and HTTPS port 4434 is used for web-based management interfaces, not SmartConsole connectivity.
- 9
Which is the correct order of a log flow processed by SmartEvent components:
Show answer details
Correct answer: C
The correct SmartEvent log processing flow is: Firewall generates logs ? Log Server receives and processes logs ? Correlation Unit analyzes events for patterns ? SmartEvent Server Database stores correlated events ? SmartEvent Client displays results. This sequential architecture ensures proper log aggregation before correlation analysis, preventing data loss and enabling accurate event correlation for security incident detection in enterprise troubleshooting scenarios.
- 10
In SmartEvent, what are the different types of automatic reactions that the administrator can configure?
Show answer details
Correct answer: B
SmartEvent automatic reactions include Mail notifications, Block Source (blocking suspicious IPs), Block Event Activity (stopping specific event types), External Script execution (for custom responses), and SNMP Trap generation for network management integration. These automated responses enable immediate threat mitigation without manual intervention, critical for enterprise security operations and troubleshooting rapid incident response in complex Check Point environments. Reference: https://sc1.checkpoint.com/documents/R80/CP_R80_LoggingAndMonitoring/html_frameset.htm?topic=documents/R80/CP_R80_LoggingAndMonitoring/131915
