質問 1:The following rule contains an FTP resource object in the Service field:
Source: local_net
Destination: Any
Service: FTP-resource object
Action: Accept
How do you define the FTP Resource Properties > Match tab to prevent internal users from sending corporate files to external FTP servers, while allowing users to retrieve files?
A. Disable the "Put" method globally.
B. Disable "Get" and "Put" methods on the Match tab.
C. Enable the "Put" and "Get" methods.
D. Enable the "Get" method on the match tab.
E. Enable the "Put" method only on the match tab.
正解:D
質問 2:How does ClusterXL Unicast mode handle new traffic?
A. All members receive all packets. The SmartCenter Server decides which member will process the packets. Other members simply drop the packets.
B. All cluster members process all packets, and members synchronize with each other.
C. The pivot machine receives and inspects all new packets, and synchronizes the connections with other members.
D. Only the pivot machine receives all packets. It runs an algorithm to determine which member should process the packets.
正解:D
質問 3:The following configuration is for VPN-1 NGX:Is this configuration correct for Management High Availability (HA)?
A. No, A VPN-1 NGX SmartCenter Server can only be in a Management HA configuration, if the operating system is Solaris.
B. No, a VPN-1 NGX SmartCenter Server cannot run on Red Hat Linux 7.3.
C. No, the SmartCenter Servers must be installed on the same operating system.
D. No, the SmartCenter Servers must reside on the same network.
E. No, the SmartCenter Servers do not have the same number of NICs.
正解:C
質問 4:You want only RAS signals to pass through H.323 Gatekeeper and other H.323 protocols, passing directly between end points. Which routing mode in the VoIP Domain Gatekeeper do you select?
A. Call Setup
B. Direct
C. Direct and Call Setup
D. Call Setup and Call Control
正解:B
質問 5:Problems sometimes occur when distributing IPSec packets to a few machines in a Load Sharing Multicast mode cluster, even though the machines have the same source and destination IP addresses. What is the best Load Sharing method for preventing this type of problem?
A. Load Sharing based on IP addresses, ports, and serial peripheral interfaces (SPI)
B. Load Sharing based on SPIs and ports only
C. Load Sharing based on IP addresses and ports
D. Load Sharing based on IP addresses only
E. Load Sharing based on SPIs only
正解:C
質問 6:After you add new interfaces to this cluster, how can you check if the new interfaces and associated virtual IP address are recognized by ClusterXL?
A. By running the cpconfig command on both members
B. By running the fw ctl iflist command on both members
C. By running the cphaprob state command on both members
D. By running the cphaprob -I list command on both members
E. By running the cphaprob -a if command on both members
正解:E
質問 7:If you check the box "Use Aggressive Mode", in the IKE Properties dialog box:
A. The standard six-packet IKE Phase 1 exchange is replaced by a three-packet exchange.
B. The standard six-packet IKE Phase 2 exchange is replaced by a three-packet exchange.
C. The standard three-packet IKE Phase 2 exchange is replaced by a six-packet exchange.
D. The standard three-packet IKE Phase 1 exchange is replaced by a six-packet exchange.
E. The standard six-packet IKE Phase 1 exchange is replaced by a twelve-packet exchange.
正解:A
質問 8:Barak is a Security Administrator for an organization that has two sites using pre-shared secrets in its VPN. The two sites are Oslo and London. Barak has just been informed that a new office is opening in Madrid, and he must enable all three sites to connect via the VPN to each other. Three Security Gateways are managed by the same SmartCenter Server, behind the Oslo Security Gateway. Barak decides to switch from pre-shared secrets to Certificates issued by the Internal Certificate Authority (ICA). After creating the Madrid gateway object with the proper VPN Domain, what are Barak's remaining steps?
1.Disable "Pre-Shared Secret" on the London and Oslo gateway objects.
2.Add the Madrid gateway object into the Oslo and London's mesh VPN Community.
3.Manually generate ICA Certificates for all three Security Gateways.
4.Configure "Traditional mode VPN configuration" in the Madrid gateway object's VPN screen.
5.Reinstall the Security Policy on all three Security Gateways.
A. 1,2,4,5
B. 1,3,4,5
C. 1, 2,3,4
D. 1,2,3,5
E. 1, 2, 5
正解:E
弊社のCheckPoint 156-315を利用すれば試験に合格できます
弊社のCheckPoint 156-315は専門家たちが長年の経験を通して最新のシラバスに従って研究し出した勉強資料です。弊社は156-315問題集の質問と答えが間違いないのを保証いたします。

この問題集は過去のデータから分析して作成されて、カバー率が高くて、受験者としてのあなたを助けて時間とお金を節約して試験に合格する通過率を高めます。我々の問題集は的中率が高くて、100%の合格率を保証します。我々の高質量のCheckPoint 156-315を利用すれば、君は一回で試験に合格できます。
一年間の無料更新サービスを提供します
君が弊社のCheckPoint 156-315をご購入になってから、我々の承諾する一年間の更新サービスが無料で得られています。弊社の専門家たちは毎日更新状態を検査していますから、この一年間、更新されたら、弊社は更新されたCheckPoint 156-315をお客様のメールアドレスにお送りいたします。だから、お客様はいつもタイムリーに更新の通知を受けることができます。我々は購入した一年間でお客様がずっと最新版のCheckPoint 156-315を持っていることを保証します。
TopExamは君に156-315の問題集を提供して、あなたの試験への復習にヘルプを提供して、君に難しい専門知識を楽に勉強させます。TopExamは君の試験への合格を期待しています。
弊社は無料CheckPoint 156-315サンプルを提供します
お客様は問題集を購入する時、問題集の質量を心配するかもしれませんが、我々はこのことを解決するために、お客様に無料156-315サンプルを提供いたします。そうすると、お客様は購入する前にサンプルをダウンロードしてやってみることができます。君はこの156-315問題集は自分に適するかどうか判断して購入を決めることができます。
156-315試験ツール:あなたの訓練に便利をもたらすために、あなたは自分のペースによって複数のパソコンで設置できます。
弊社は失敗したら全額で返金することを承諾します
我々は弊社の156-315問題集に自信を持っていますから、試験に失敗したら返金する承諾をします。我々のCheckPoint 156-315を利用して君は試験に合格できると信じています。もし試験に失敗したら、我々は君の支払ったお金を君に全額で返して、君の試験の失敗する経済損失を減少します。
安全的な支払方式を利用しています
Credit Cardは今まで全世界の一番安全の支払方式です。少数の手続きの費用かかる必要がありますとはいえ、保障があります。お客様の利益を保障するために、弊社の156-315問題集は全部Credit Cardで支払われることができます。
領収書について:社名入りの領収書が必要な場合、メールで社名に記入していただき送信してください。弊社はPDF版の領収書を提供いたします。
CheckPoint Check Point Security Administration NGX II (156-315.1) 認定 156-315 試験問題:
1. Which of the following TCP port numbers is used to connect the VPN-1 Gateway to the Content Vector Protocol (CVP) server?
A) 18181
B) 18180
C) 18182
D) 17242
E) 1456
2. DShield is a Check Point feature used to block which of the following threats?
A) Trojan horses
B) DDOS
C) SQL injection
D) Cross Site Scripting
E) Buffer overflows
3. You have an internal FTP server, and you allow uploading, but not downloading. Assume Network Address Translation (NAT) is set up correctly and you want to add an inbound rule with:
Source: Any
Destination: FTP server
Service: an FTP resource object.
How do you configure the FTP resource object and the action column in the rule to achieve this goal?
A) Disable "Get" and "Put" methods in the FTP Resource Properties and use them in the rule, with action accept.
B) Enable only the "Get" method in the FTP Resource Properties and use this method in the rule, with action accept.
C) Enable both "Put" and "Get" methods in the FTP Resource Properties and use them in the rule, with action drop.
D) Enable only "Put" method in the FTP Resource Properties and use this method in the rule, with action accept.
E) Enable only the "Put" method in the FTP Resource Properties and use this method in the rule, with action drop.
4. Jennifer wants to protect internal users from malicious Java code, but she does not want to strip Java scripts. Which is the BEST configuration option?
A) Use the URI resource to strip script tags
B) Use the URI resource to strip applet tags
C) Use the URI resource to block Java code
D) Use CVP in the URI resource to block Java code
E) Use the URI resource to strip ActiveX tags
5. You are preparing computers for a new ClusterXL deployment. For your cluster, you plan to use three machines with the following configurations:Are these machines correctly configured for a ClusterXL deployment?

A) No, a cluster must have an even number of machines.
B) Yes, these machines are configured correctly for a ClusterXL deployment.
C) No, all machines in a cluster must be running on the same OS.
D) No, QuadCards are not supported with ClusterXL.
E) No, ClusterXL is not supported on Red Hat Linux.
質問と回答:
質問 # 1 正解: A | 質問 # 2 正解: B | 質問 # 3 正解: D | 質問 # 4 正解: C | 質問 # 5 正解: C |