Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: s2p65

Easiest Solution 2 Pass Your Certification Exams

156-215.81 Checkpoint Check Point Certified Security Administrator R81.20 CCSA (156-215.81.20) Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Checkpoint 156-215.81 Check Point Certified Security Administrator R81.20 CCSA (156-215.81.20) certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 2 / 7
Total 411 questions

Which command shows detailed information about VPN tunnels?

A.

cat $FWDIR/conf/vpn.conf

B.

vpn tu tlist

C.

vpn tu

D.

cpview

The Gateway Status view in SmartConsole shows the overall status of Security Gateways and Software Blades. What does the Status Attention mean?

A.

Cannot reach the Security Gateway.

B.

The gateway and all its Software Blades are working properly.

C.

At least one Software Blade has a minor issue, but the gateway works.

D.

Cannot make SIC between the Security Management Server and the Security Gateway

Tom has connected to the Management Server remotely using SmartConsole and is in the process of making some Rule Base changes, when he suddenly loses connectivity. Connectivity is restored shortly afterward. What will happen to the changes already made?

A.

Tom will have to reboot his SmartConsole computer, clear the cache, and restore changes.

B.

Tom will have to reboot his SmartConsole computer, and access the Management cache store on that computer, which is only accessible after a reboot.

C.

Tom's changes will be lost since he lost connectivity and he will have to start again.

D.

Tom's changes will have been stored on the Management when he reconnects and he will not lose any of his work.

Core Protections are installed as part of what Policy?

A.

Access Control Policy.

B.

Desktop Firewall Policy

C.

Mobile Access Policy.

D.

Threat Prevention Policy.

Which one of these features is NOT associated with the Check Point URL Filtering and Application Control Blade?

A.

Detects and blocks malware by correlating multiple detection engines before users are affected.

B.

Configure rules to limit the available network bandwidth for specified users or groups.

C.

Use UserCheck to help users understand that certain websites are against the company’s security policy.

D.

Make rules to allow or block applications and Internet sites for individual applications, categories, and risk levels.

Which of the following is used to initially create trust between a Gateway and Security Management Server?

A.

Internal Certificate Authority

B.

Token

C.

One-time Password

D.

Certificate

Using AD Query, the security gateway connections to the Active Directory Domain Controllers using what protocol?

A.

Windows Management Instrumentation (WMI)

B.

Hypertext Transfer Protocol Secure (HTTPS)

C.

Lightweight Directory Access Protocol (LDAP)

D.

Remote Desktop Protocol (RDP)

Most Check Point deployments use Gaia but which product deployment utilizes special Check Point code (with unification in R81.10)?

A.

Enterprise Network Security Appliances

B.

Rugged Appliances

C.

Scalable Platforms

D.

Small Business and Branch Office Appliances

Fill in the bank: In Office mode, a Security Gateway assigns a remote client to an IP address once___________.

A.

the user connects and authenticates

B.

office mode is initiated

C.

the user requests a connection

D.

the user connects

DLP and Geo Policy are examples of what type of Policy?

A.

Inspection Policies

B.

Shared Policies

C.

Unified Policies

D.

Standard Policies

There are four policy types available for each policy package. What are those policy types?

A.

Access Control, Threat Prevention, Mobile Access and HTTPS Inspection

B.

Access Control, Custom Threat Prevention, Autonomous Threat Prevention and HTTPS Inspection

C.

There are only three policy types: Access Control, Threat Prevention and NAT.

D.

Access Control, Threat Prevention, NAT and HTTPS Inspection

Which of the following is NOT a policy type available for each policy package?

A.

Threat Emulation

B.

Access Control

C.

Desktop Security

D.

Threat Prevention

Where can administrator edit a list of trusted SmartConsole clients?

A.

cpconfig on a Security Management Server, in the WebUI logged into a Security Management Server.

B.

In cpconfig on a Security Management Server, in the WebUI logged into a Security Management Server, in SmartConsole: Manage and Settings > Permissions and Administrators > Advanced > Trusted Clients.

C.

WebUI client logged to Security Management Server, SmartDashboard: Manage and Settings > Permissions and Administrators > Advanced > Trusted Clients, via cpconfig on a Security Gateway.

D.

Only using SmartConsole: Manage and Settings > Permissions and Administrators > Advanced > Trusted Clients.

Which information is included in the “Extended Log” tracking option, but is not included in the “Log” tracking option?

A.

file attributes

B.

application information

C.

destination port

D.

data type information

Fill in the blank: Browser-based Authentication sends users to a web page to acquire identities using ___________.

A.

Captive Portal and Transparent Kerberos Authentication

B.

UserCheck

C.

User Directory

D.

Captive Portal

Application Control/URL filtering database library is known as:

A.

Application database

B.

AppWiki

C.

Application-Forensic Database

D.

Application Library

What are the three components for Check Point Capsule?

A.

Capsule Docs, Capsule Cloud, Capsule Connect

B.

Capsule Workspace, Capsule Cloud, Capsule Connect

C.

Capsule Workspace, Capsule Docs, Capsule Connect

D.

Capsule Workspace, Capsule Docs, Capsule Cloud

What are the three types of UserCheck messages?

A.

inform, ask, and block

B.

block, action, and warn

C.

action, inform, and ask

D.

ask, block, and notify

Which deployment adds a Security Gateway to an existing environment without changing IP routing?

A.

Distributed

B.

Bridge Mode

C.

Remote

D.

Standalone

When configuring Spoof Tracking, which tracking actions can an administrator select to be done when spoofed packets are detected?

A.

Log, send snmp trap, email

B.

Drop packet, alert, none

C.

Log, alert, none

D.

Log, allow packets, email

Page: 2 / 7
Total 411 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved