CheckPoint Accelerated CCSE NGX (156-915.1) 認定 156-915 試験問題:
1. You have two Nokia Appliances: one IP530 and one IP380. Both Appliances have IPSO
3.9 and VPN-1 Pro NGX installed in a distributed deployment. Can they be members of a gateway cluster?
A) Yes, because both gateways are from Nokia, whether they have the same VPN-1 PRO version or not.
B) No, because the Gateway versions must not be the same on both security gateways.
C) No, because the appliances must be of the same model (Both should be IP530 or IP380.)
D) Yes, as long as they have the same IPSO version and the same VPN-1 Pro version.
E) No, because members of a security gateway cluster must be installed as stand-alone deployments.
2. Which of these changes to a Security Policy optimizes Security Gateway performance?
A) Putting the least-used rule at the top of the Rule Base.
B) Using groups within groups in the manual NAT Rule Base
C) Using domain objects in rules when possible
D) Removing old or unused Security Policies from Policy Packaes.
E) Logging rules as much as possible.
3. Mary is recently hired as the Security Administrator for a public relations company. Mary's manager has asked her to investigate ways to improve the performance of the firm's perimeter Security Gateway. Mary must propose a plan based on the following required and desired results:
Required Result #1: Do not purchase new hardware.
Required Result #2: Use configuration changes that do not reduce security.
Desired Result #1: Reduce the number of explicit rules in the Rule Base.
Desired Result #2: Reduce the volume of logs.
Desired Result #3: Improve the Gateway's performance.
Proposed Solution:
Mary recommends the following changes to the Gateway's configuration:
Replace all domain objects with network and group objects.
Stop logging Domain Name over UDP (queries).
Use Global Properties, instead of explicit rules, to control ICMP, VRRP, and RIP.
Does Mary's proposed solution meet the required and desired results?
A) The solution meets the required results, and one of the desired results.
B) The solution does not meet the required results.
C) The solution meets the required results, and two of the desired results.
D) The solution meets all required and desired results.
E) The solution meets all required results, and none of the desired results.
4. You are running a VPN-1 NG with Application Intelligence R54 SecurePlatform VPN-1 Pro Gateway. The Gateway also serves as a Policy Server. When you run patch add cd from the NGX CD, what does this command allow you to upgrade?
A) Both the operating system (OS) and all Check Point products
B) Only VPN-1 Pro Security Gateway
C) Only the OS
D) Only the patch utility is upgraded using this command
E) All products, except the Policy Server
5. Steve tries to configure Directional VPN Rule Match in the Rule Base. But the Match column does not have the option to see the Directional Match. Steve sees the following screen. What is the problem?
A) Steve must enable VPN Directional Match on the VPN Advanced screen, in Global properties.
B) Steve must enable VPN Directional Match on the gateway object??s VPN tab.
C) Steve must enable a dynamic-routing protocol, such as OSPF, on the Gateways.
D) Steve must enable directional_match(true) in the objectes_5_0.C file on SmartCenter Server.
E) Steve must enable Advanced Routing on each Security Gateway.
質問と回答:
質問 # 1 正解: D | 質問 # 2 正解: D | 質問 # 3 正解: D | 質問 # 4 正解: A | 質問 # 5 正解: A |