What is the mechanism behind Threat Extraction?
A. This a new mechanism which extracts malicious files from a document to use it as a counter-attack against its
B. This is a new mechanism which is able to collect malicious files out of any kind of file types to destroy it prior to
sending it to the intended recipient.
C. This is a new mechanism to identify the IP address of the sender of malicious codes and put it into the SAM
database (Suspicious Activity Monitoring).
D. Any active contents of a document, such as JavaScripts, macros and links will be removed from the document and
forwarded to the intended recipient, which makes this solution very fast.
Correct Answer: D

Which TCP port does the CPM process listen on?
A. 18191
B. 18190
C. 8983
D. 19009
Correct Answer: D

What has to be taken into consideration when configuring Management HA?
A. The Database revisions will not be synchronized between the management servers
B. SmartConsole must be closed prior to synchronized changes in the objects database
C. If you wanted to use Full Connectivity Upgrade, you must change the Implied Rules to allow FW1_cpredundant to
pass before the Firewall Control Connections.
D. For Management Server synchronization, only External Virtual Switches are supported. So, if you wanted to employ
Virtual Routers instead, you have to reconsider your design.
Correct Answer: A
Check Point ClusterXL Active/Active deployment is used when:
A. Only when there is Multicast solution set up.
B. There is Load Sharing solution set up.
C. Only when there is Unicast solution set up.
D. There is High Availability solution set up.
Correct Answer: B
Fill in the blank: A new license should be generated and installed in all of the following situations EXCEPT when
________ .
A. The license is attached to the wrong Security Gateway.
B. The existing license expires.
C. The license is upgraded.
D. The IP address of the Security Management or Security Gateway has changed.
Correct Answer: A

Which is NOT a SmartEvent component?
A. SmartEvent Server
B. Correlation Unit
C. Log Consolidator
D. Log Server
Correct Answer: C

When users connect to the Mobile Access portal they are unable to open File Shares.
Which log file would you want to examine?
A. cvpnd.elg
B. httpd.elg
C. vpnd.elg
D. fw.elg
Correct Answer: A

Which of these is an implicit MEP option?
A. Primary-backup
B. Source address based
C. Round robin
D. Load Sharing
Correct Answer: A

What CLI utility runs connectivity tests from a Security Gateway to an AD domain controller?
A. test_connectivity_ad –d
B. test_ldap_connectivity –d
C. test_ad_connectivity –d
D. ad_connectivity_test –d
Correct Answer: C

How many policy layers do Access Control policy support?
A. 2
B. 4
C. 1
D. 3
Correct Answer: A
Two policy layers:
-Network Policy Layer
-Application Control Policy Layer

You want to store the GAIA configuration in a file for later reference. What command should you use?
A. write mem
B. show config -f
C. save config -o
D. save configuration
Correct Answer: D

What does the Log “Views” tab show when SmartEvent is Correlating events?
A. A list of common reports
B. Reports for customization
C. Top events with charts and graphs
D. Details of a selected logs
Correct Answer: D

