with correct answers 100% 2025
Three ways to control network traffic - Correct Answer Packet filtering, stateful inspection, application
firewall
Packet filtering - Correct Answer source & destination IP, port, protocol
Stateful Inspection - Correct Answer same as packet filtering but now looking at packet content
Application FW - Correct Answer Granular level filtering; inspects traffic through lower levels of TCP/IP
module and up to the application layer
SIC - Correct Answer Secure internal communications - how gateways and mgmt servers authenticate
one another to communicate
Three authentication methods for SIC - Correct Answer Certificates, TLS for encrypted channels, 3DES
(for R71-) or AES128 (for R71+)
ICA - Correct Answer Internal certificate authority
Responsible for issuing certs for SIC, VPN communities, Users
SIC statuses - Correct Answer Communicating - mgmt server and gateway are talking
Unknown - gateway and mgmt server no connection
Not communicating - mgmt server can contact gateway but can't establish SIC
Three components of CP Sec Architecture - Correct Answer Smart console --> mgmt server --> sec
gateway
Smart console = GUI
mgmt server = where policies are stored
sec gateway = enforces policies
,Smart Console tabs - Correct Answer 1. Gateways and servers
2. security policy
3. Logs & Monitors
4. manage & settings
Smart Console apps - Correct Answer Smart Event - correlates logs and detects sec threats
Smart View - displays complete pic of network and sec performance
Smart Update - manage licenses and packages
Smart Dashboard - used for legacy applications
Checkpoint deployment platforms - Correct Answer Small business and branch office, enterprise, DC,
Chassis, Rugged appliance, open servers
Deployment options - Correct Answer Standalone - mgmt server and gw are on same appliance
distributed - mgmt server and gw on different appliances
bridge mode - using switches
CPUSE - Correct Answer updates for CP products, auto update CP products for GAIA, hotfixes
Two hardware options for deploying CP tech - Correct Answer CP appliances or open servers (non CP)
Object types for rules - Correct Answer used to represent physical and virtual network components
network object - Correct Answer gw, host, networks, address ranges, etc
service object - Correct Answer protocols
custom app/site object - Correct Answer applications, user categories, URL categorizations
, VPN community object - Correct Answer site to site or remote access VPN
user object - Correct Answer user groups, users, user templates
server object - Correct Answer trusted CAs, RADIUS, TACACS, OPSEC servers
time object - Correct Answer time, time group, bw limit on upload and download rates
Security zone - Correct Answer group of one or more network interfaces from a centrally managed gw
bound together and used directly in the rule base
Anti-Spoofing - Correct Answer spoofing - where intrude gains access by changing IP
verifies packets are going from and going to the correct interfaces
Cleanup rule - Correct Answer how to handle traffic not matched by the above rule base - placed at the
bottom
Stealth rule - Correct Answer rule added so that a user cannot connect directly to the gw - gw is invisible
to users over the network
Explicit Rule - Correct Answer created in the rule base by the admin
Implicit rule - Correct Answer rules defined by the sec gw to allow certain connections to and from the
gw - not visible in rule base
two types: control connections and outgoing packets
Control connection - Correct Answer type of implicit rule that can be placed first, last, or before last in
the explicitly defined rule base. Three types
- gw specific traffic like logging, mgmt, key exchange