CheckPoint Check Point Certified Security Administrator R71 認定 156-215-71 試験問題:
1. Which of the following statements BEST describes Check Point's Hide Network Address Translation method?
A) One-to-one NAT which implements PAT (Port Address Translation) for accomplishing both Source and Destination IP address translation
B) Many-to-one NAT which implements PAT (Port Address Translation) for accomplishing both Source and Destination IP address translation
C) Translates many source IP addresses into one source IP address
D) Translates many destination IP addresses into one destination IP address
2. In order to have full control, you decide to use Manual NAT entries instead of Automatic NAT rules. Which is of the following is NOT true?
A) If you chose Automatic NAT instead, all necessary entries are done for you.
B) When using Dynamic Hide NAT with an address that is not configured on a Gateway interface, you need to add a proxy ARP entry for that address.
C) When using Static NAT, you must add proxy ARP entries to the Gateway for all hiding addresses.
D) When using Static NAT, you must enter ARP entries for the Gateway on all hosts that are using the NAT Gateway with that Gateway's internal interface IP address.
3. Which Security Gateway R71 configuration setting forces the Client Authentication authorization time-out to refresh, each time a new user is authenticated? The:
A) Global Properties > Authentication parameters, adjusted to allow for Regular Client Refreshment
B) Time properties, adjusted on the user objects for each user, in the source of the Client Authentication rule
C) Refreshable Timeout setting, in the Limits tab of the Client Authentication Action Properties screen
D) IPS > Application Intelligence > Client Authentication > Refresh User Timeout option enabled
4. After installing Security Gateway R71, you discover that one port on your Intel Quad NIC on the Security Gateway is not fetched by a Get Topology request. What is the most likely cause and solution?
A) If an interface is not configured, it is not recognized. Assign an IP address and subnet mask using the WebUI.
B) The NIC is faulty. Replace it and reinstall.
C) Make sure the driver for your particular NIC is available, and reinstall. You will be prompted for the driver.
D) Your NIC driver is installed but was not recognized. Apply the latest SecurePlatform R71 Hotfix Accumulator (HFA).
5. In the SmartView Tracker you receive the error, ...peer send invalid ID information... while trying to establish an IKE VPN tunnel. Where does this error normally result from and how can you solve it? This error normally results from:
A) a mismatch in the authentication algorithms used in IKE phase one and can be corrected by changing them to match.
B) a mismatch in the IPs of the VPN tunnel endpoints and can not be resolved.
C) an invalid IP address configured on one tunnel endpoint; normally the internal one in the General tab. This can be solved with link selection or by changing this IP to the one facing the other tunnel endpoint.
D) an invalid IP address configured on one tunnel endpoint, normally the internal one in the General tab. This can be resolved by adding the correct IPs to the Topology tab of both Gateways on both sites.
質問と回答:
| 質問 # 1 正解: C | 質問 # 2 正解: D | 質問 # 3 正解: C | 質問 # 4 正解: A | 質問 # 5 正解: C |














1030 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
