John is the Security Administrator in his company. He needs to maintain the highest level of security on the firewalls he manages. He is using Check Point R75. Does he need the IPS Software Blade for achieving this goal?
A. No, all IPS protections are active, but can’t be uploaded without the license like SmartDefense.
B. Yes, otherwise no protections can be enabled.
C. Yes, otherwise the firewall will pass all traffic unfiltered and unchecked.
D. No, the Gateway will always be protected and the IPS checks can’t be managed without a license.
Which command allows you to view the contents of an R75 table?
A. fw tab -x <tablename>
B. fw tab -a <tablename>
C. fw tab -s <tablename>
D. fw tab -t <tablename>
Your R75 enterprise Security Management Server is running abnormally on Windows 2003 Server. You decide to try reinstalling the Security Management Server, but you want to try keeping the critical Security Management Server configuration settings intact (i.e., all Security Policies, databases, SIC, licensing etc.) What is the BEST method to reinstall the Server and keep its critical configuration?
A. 1) Run the latest upgrade_export utility to export the configuration
2) Leave the exported – tgz file in %FWDIR\bin.
3) Install the primary security Management Server on top of the current installation
4) Run upgrade_import to Import the configuration.
B. 1) Insert theR75CD-ROM. and select the option to export the configuration into a . tgz file
2) Skip any upgrade verification warnings since you are not upgrading.
3) Transfer the. tgz file to another networked machine.
4) Download and run the cpclean utility and reboot.
5) Use theR75CD_ROM to select the upgrade__import option to import the c
C. 1) Download the latest upgrade_export utility and run it from a \ temp directory to export the
2) Perform any requested upgrade verification suggested steps.
3) Uninstall allR75packages via Add/Remove Programs and reboot
4) Use smartUpdate to reinstall the Security Management server and reboot
5) Transfer the .tgz file back to the local \ temp.
6) Run upgrade_import to import the configuration.
D. 1) Download the latest upgrade_export utility and run it from a \ temp directory to export the
2) Transferee .tgz file to another network machine
3) Uninstall allR75packages via Add/Remove Programs and reboot
4) Install again using theR75CD ROM as a primary security management server
5) Reboot and than transfer the .tgz file back to the local\ tem p
6) Run upgcade_import to import the configuration.
Your primary Security Management Server runs on SecurePlatform. What is the easiest way to back up your Security Gateway R75 configuration, including routing and network configuration files?
A. Using the upgrade_export command.
B. Copying the $FWDIR/conf and $FWDIR/lib directory to another location.
C. Run the pre_upgrade_verifier and save the .tgz file to the /temp directory.
D. Using the native SecurePlatform backup utility from command line or in the Web based user interface.
Your R75 primary Security Management Server is installed on SecurePlatform. You plan to schedule the Security Management Server to run fw logswitch automatically every 48 hours. How do you create this schedule?
A. Create a time object, and add 48 hours as the interval. Open the primary Security Management
Server object’s Logs and Masters window, enable Schedule log switch, and select the Time object.
B. Create a time object, and add 48 hours as the interval. Open the Security Gateway object’s Logs
and Masters window, enable Schedule log switch, and select the Time object.
C. Create a time object, and add 48 hours as the interval. Select that time object’s Global Properties >
Logs and Masters window, to schedule a logswitch.
D. On a SecurePlatform Security Management Server, this can only be accomplished by configuring
the fw logswitch command via the cron utility.
Which of the following methods will provide the most complete backup of an R75 configuration?
A. Policy Package Management
B. Copying the $PWDIR\conf and $CPDIR\conf directories to another server
C. upgrade_export command
D. Database Revision Control
Which of the following commands can provide the most complete restore of an R75 configuration?
C. fwm dbimport -p
D. cpinfo -recover
When restoring R75 using the command upgrade > Port. Which of the following items is NOT restored?
B. Global properties
C. SIC Certificates
D. Route tables
Your organization’s disaster recovery plan needs an update to the backup and restore section to reap the benefits of the new distributed R75 installation. Your plan must meet the following required and desired objectives:
-Required Objective: The Security Policy repository must be backed up no less frequently than every 24 hours.
-Desired Objective: The R75 components that enforce the Security Polices should be blocked up at least once a week.
-Desired Objective: Back up R75 logs at least once a week
Your disaster recovery plan is as follows:
-Use the cron utility to run the upgrade_ export command each night on the Security Management Servers.
-Configure the organization’s routine backup software to back up the files created by the upgrade_ export command.
-Configure the SecurePlatform backup utility to back up the Security Gateways every Saturday night
-Use the cron utility to run the upgrade export: command each Saturday niqht on the log servers
-Configure an automatic, nightly loqswitch
-Configure the organization’s routine backup software to back up the switched logs every night
Upon evaluation, your plan:
A. Meets the required objective but does not meet either desired objective.
B. Does not meet the required objective.
C. Meets the required objective and only one desired objective.
D. Meets the required objective and both desired objectives.
Your company is running Security Management Server R75 on SecurePlatform, which has been migrated through each version starting from Check Point 4.1. How do you add a new administrator account?
A. Using SmartDashboard, under Users, select Add New Administrator
B. Using the Web console on SecurePlatform under Product configuration, select Administrators
C. Using SmartDashboard or cpconf ig
D. Using cpconftg on the Security Management Server, choose Administrators
If you want to pass the Check Point CCSA 156-215.75 exam sucessfully, recommend to read latest Check Point CCSA 156-215.75 Test Engine full version.