Practice Q&As Flashcards
(129 cards)
Which of the following is NOT an integral part of VPN communication within a network:
- VPN Key
- VPN Community
- VPN Trust Entities
- VPN Domain
VPN Key
✑ VPN trust entities, such as a Check Point Internal Certificate Authority (ICA). The ICA is part of the Check Point suite used for creating SIC trusted connection between Security Gateways, authenticating administrators and third party servers. The ICA provides certificates for internal Security Gateways and remote access clients which negotiate the VPN link.
✑ VPN Domain - A group of computers and networks connected to a VPN tunnel by one VPN gateway that handles encryption and protects the VPN Domain members.
✑ VPN Community - A named collection of VPN domains, each protected by a VPN gateway.
How can you tell if another Checkpoint Admin is working on a rule, but has not published the changes?
There’s a little pencil symbol next to the rule.
What encryption is used in SIC, and what does SIC stand for?
Gateways above R71 use AES128 for SIC, R71 and below use 3DES. SIC stands for Secure Internal Communications.
What are the five types of SecureXL flow?
Accelerated Path (sometimes called “fastpath” or SXL)
F2V (Forward to Virtual Machine) Path
PSLXL Path (also called the “Medium Path” or “Passive Streaming”)
CPASXL Path (also called “Active Streaming”)
Firewall Path (also called “slowpath”, “non-accelerated”, or F2F)
What are the three main components of the Checkpoint Three-tier architecture?
SmartConsole
Security Management Server
Security Gateway
What is the main purpose of the SmartConsole?
SmartConsole is a GUI software installed on a windows platform allowing for centralised management of a Check Point environment
What is the main purpose of the Security Management Server?
The Security Management Server is a dedicated server that runs Check Point software to manage the objects and policies in a Check Point environment. The Security Management Server is installed on a server running the Check Point Gaia OS.
What is the main purpose of a security gateway?
The security gateway is essentially a firewall - it’s Check Points term for it
What are the two main shells that the gaia OS provides?
Gaia Clish and Bash (Expert Mode)
Which shell is the most restrictive
Clish
What is the default shell?
Clish
What is the default password for Expert Mode?
There is no default password, you must define it using the ‘set expert-password’ command
What physical components may be represented by a network object?
A user, a server, a gateway, any physical components
What logical components may be represented by a network object?
Applications, IP Ranges, Services etc
What permissions profile allows unrestricted permissions?
Super User
Name three types of Software Containers?
Security Management
Security Gateway
Endpoint Security
What are the subscription blades?
Service blades such as IPS, URL Filtering, Application Control are considered subscription blades
Name on reason to generate and install a new license?
Existing license expires
License is upgraded
IP address of the security management or security gateway has changed
What types of rules are created by the security gateway?
Implied Rules
What type of rules are created by the administrator?
Explicit Rules
Where should the clean up rule be placed?
At the bottom of the rulebase
What is the purpose of policy layers?
Policy layers are sets of rules or a rulebase. They let you divide up a policy into smaller, more manageable sections.
What type of Policy layer is independent of the rest of the rulebase?
Inline
List the two types of rules that Check Point NAT supports for address translation?
Automatic
Manual