Pre-Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Checkpoint 156-590 Dumps

Page: 1 / 8
Total 75 questions

Check Point Certified Threat Prevention Specialist (CTPS) Questions and Answers

Question 1

What is the impact of changing the Preconfigured Threat Prevention Profiles?

Options:

A.

The best practice for all Check Point delivered profiles and object is to first clone them and work on the clones.

B.

The impact is minimum if you first delete all of them and then build them from scratch.

C.

The impact can be minimized if you use the performance check tool. You can enable it in IPS protections - > actions - > Run Protection performance check tool.

D.

There is no performance or security impact in changing the Preconfigured Profiles.

Question 2

Which statement is true concerning the Custom Policy Tools?

Options:

A.

Block List files - Configure disallowed files.

B.

Allow List Files - Configure allowed files.

C.

Indicators - Configure indicators for benign activity.

D.

Profiles - Edit profiles which are only available for Autonomous Threat Prevention.

Question 3

Mike wants to block all files in the event of internal failure; what option should he choose?

Options:

A.

open system

B.

fail-close

C.

fail-open

D.

closed system

Question 4

What is the purpose of the Packet Capture Track option?

Options:

A.

You can visualize traffic information with a third-party XDR tool.

B.

The security Gateway sends a packet capture file along with the log file. The former can by analyzed with an external tool, such as WireShark.

C.

You can specify the time after which the connection has to be reinitialized.

D.

You can specify a threshold value which serves as a limit after which the connection will be reset.

Question 5

What kind of blade is the IPS considered?

Options:

A.

Preventative

B.

Pre-infection

C.

Inline

D.

Post-infection

Question 6

What are examples of evidence of compromises from inside network in conjunction with Bot-infected systems?

Options:

A.

Users surfing the website directly by IP address or using domains registered within the last 30 days.

B.

Trying to access web resources using explicit proxy servers instead of transparent ones.

C.

Repetitive access to the same specific Intranet web servers within business hours.

D.

Trying to access a web server via HTTP instead of HTTPS.

Question 7

IPS stands for?

Options:

A.

Invasion Prevention Software

B.

Intrusion Prevention System

C.

Intrusion Prevention Software

D.

Invasion Prevention System

Question 8

That Tracking option can be used to capture additional data for analysis by Check Point TAC?

Options:

A.

Alert

B.

Forensics

C.

SNMP

D.

User Defined

Question 9

What is the recommended setting for Anti-Virus and why?

Options:

A.

Background because it is Post-infection

B.

Hold because it is Pre-infection and inspects a limited subset of traffic

C.

Hold because it inspects a limited subset of traffic

D.

Background because it inspects a large subset of traffic

Question 10

You have been asked to inform your CEO about last week's security incident.

What SmartEvent mechanism are you going to use?

Options:

A.

You have to use Smart Event threat prevention View to get the information then extract it to csv format and then generate a pdf with this info.

B.

The executive reports generally contain abstract information without much technical detail. You have to use Smart Event Threat Prevention Report filtered for last week data.

C.

From the smart log you filter out traffic for last week and export it to a special report generate tool.

D.

You have to build a view for last week and submit it to your CEO.

Question 11

What is necessary to do in order for the IPS Core Protection to take effect?

Options:

A.

Nothing is to be done, since the Core Protection settings are immediately active.

B.

Install the Access Control Policy.

C.

Install the Threat Prevention Policy.

D.

Perform "Install Database" on the Management Server.

Question 12

What does not belong to types of exceptions?

Options:

A.

IPS Settings Exceptions.

B.

QoS Policy exemptions.

C.

Core Activations Exceptions.

D.

Implied IPS Exceptions.

Question 13

What information is provided by "fwaccel stats"?

Options:

A.

This command is to enable acceleration on QoS packets.

B.

You can check the percentage of F2F connections along with the reason why those connections could not be accelerated.

C.

The command is used to examine traffic utilization statistics.

D.

You can check the SecureXL status of your Security Gateway.

Question 14

What is a distinct limitation of Active Streaming compared to Passive Streaming in conjunction with Anti-Virus?

Options:

A.

Only scheduled scans are possible.

B.

File size limits.

C.

There is no limitation.

D.

Only a subset of file types supported.

Question 15

Protections with a High Protection Impact rating go through which path?

Options:

A.

PXL

B.

SXL

C.

CPASXL

D.

F2F

Question 16

What type of layer is the threat Prevention?

Options:

A.

It can be ordered or inline

B.

Inline

C.

Post Access Control follow-up layer

D.

Ordered

Question 17

Which protection setting is generally the LEAST resource intensive?

Options:

A.

Prevent

B.

Inspect

C.

Detect

D.

Inactive

Question 18

How can the IPS Blade be activated?

Options:

A.

The IPS Blade must be activated on the Management Server object and can be used on every gateway managed by this Management server.

B.

No need to activate the IPS Blade as far as you have installed the correct IPS license on the gateways.

C.

In a ClusterXL deployment, the IPS Blade must be activated on the individual cluster nodes.

D.

The IPS Blade must be activated on the individual Security Gateway object.

Question 19

Which of the following protocols can be scanned by Anti-Virus?

Options:

A.

RemoteDesktop

B.

SNMP

C.

CIFS

D.

Telnet

Question 20

Using IPS can send a large part of traffic to F2F path.

Which command can you use to enforce traffic quotas?

Options:

A.

fw dos rate

B.

fwaccel rate

C.

fw ctl dos

D.

fwaccel dos rate

Question 21

What are the logical components of a SNORT rule?

Options:

A.

Rule Header / rule body

B.

Rule Header and Rule Options

C.

Rule start / rule stop

D.

Rule start / rule options

Question 22

What is the default SMS and SG update interval for IPS Protections (R80.20+)?

Options:

A.

Six hours

B.

Twelve hours

C.

Two hours

D.

Daily

Page: 1 / 8
Total 75 questions