Be able to reset SIC on a Gateway, re-establish trust with a one-time password, and restore a corrupted policy using SmartConsole revision history. The single most important thing: know that SIC trust requires matching activation keys and that publishing does not install policy to Gateways.
Start practicing
SIC and SmartConsole Management — choose a session length
Free · No account required
Domain overview
This domain covers Secure Internal Communication (SIC) between Check Point Security Management Server and Security Gateways, plus SmartConsole session, policy publication, and revision workflows. Questions present operational scenarios: SIC status errors, trust establishment failures, corrupted policy publication, and concurrent administrator access, requiring you to select correct recovery or configuration actions.
Exam objectives
Resetting SIC via cpconfig or SmartConsole Gateway properties, then re-establishing trust with the one-time password
Using SmartConsole revision history and policy restore to roll back a corrupted published Access Control policy
Diagnosing 'Trust Not Established' by verifying the activation key, SIC certificate state, and TCP 257 connectivity
Managing concurrent SmartConsole administrator sessions, database locks, and publishing versus installing policy changes
Resetting SIC on the Gateway but forgetting to re-enter the same one-time password and re-establish trust from SmartConsole, leaving status unchanged
Confusing 'Publish' with 'Install Policy': publishing saves to the Management database but does not push policy to Gateways
Assuming a SIC failure is always network-related, ignoring expired or revoked SIC certificates that require a full reset
Click any question to see the full explanation and answer options, or start a focused practice session above.
When adding a new Check Point Cluster member to an existing management environment, which command must be run on the new member to prepare it for SIC establishment?
2What is the function of the 'Internal Certificate Authority' (ICA) in a Check Point environment?
3When a Management Server is in a high-availability configuration, how does SIC handle communication if the primary management server fails?
4An administrator needs to reset Secure Internal Communication (SIC) on a remote Security Gateway that is currently showing a status of 'Communication Error' in SmartConsole. Which TWO actions must be performed to successfully re-establish the SIC relationship? (Choose TWO)
5An administrator needs to create a new administrator account in SmartConsole with permissions restricted exclusively to monitoring logs and viewing tracking data without any ability to modify rules. Which TWO configuration actions must be performed? (Choose TWO)
6Refer to the exhibit. An administrator is troubleshooting an intermittent SIC authentication failure between the Security Management Server and cluster-gw-01. Based on the CLI output, what does the cpca_client command verify?
7An administrator attempts to establish Secure Internal Communication between a newly installed Security Gateway and the Management Server, but the SIC status repeatedly shows 'Trust Not Established'. The network path is verified and standard TCP port 1849 is fully open. What is the most likely root cause of this failure?
8A senior administrator needs to restrict a junior security operator so they can view and edit access control policies, but they must be strictly prohibited from installing policies onto production Security Gateways. Which SmartConsole mechanism should be utilized to enforce this operational boundary?
9During an emergency maintenance window, an administrator accidentally publishes a severely corrupted Access Control policy from SmartConsole, causing widespread connectivity outages. The administrator needs to immediately revert the management database to the exact state it was in before this faulty session was published. Which built-in mechanism provides the fastest resolution?
10An administrator successfully logs into SmartConsole and modifies several Access Control rules. Another administrator attempts to open SmartConsole to review the threat prevention settings, but receives a warning message indicating that the database is currently locked by the first administrator. What is the standard behavior of SmartConsole regarding concurrent policy editing?
11An administrator has just deployed a new R81 Security Gateway and needs to establish Secure Internal Communication (SIC) with the existing Management Server. The administrator runs the command 'cpconfig' on the gateway, selects the option to initialize SIC, and enters the activation key. After completing the wizard, the administrator checks SmartConsole and sees that the gateway's SIC status is still 'Not Communicating'. The administrator verifies that the gateway's IP address is correct, the firewall policy allows traffic on port 257, and the Management Server is reachable. What is the most likely reason for the SIC status not being established?
12An administrator has just initialized Secure Internal Communication (SIC) on a new Security Gateway using the one-time password 'CpWk987'. In SmartConsole, the administrator opens the gateway object, goes to the General Properties > Secure Internal Communication section, and enters the same one-time password. After clicking Initialize, the SIC status changes to 'Trust established'. However, the administrator notices that the gateway's SIC status later reverts to 'Unknown' after a few minutes. What is the most likely cause?
13A security administrator has just initialized a new Security Gateway with the First Time Configuration Wizard. In SmartConsole, the gateway object exists but its SIC status shows 'Not Communicating'. The administrator opens the gateway object and clicks 'Communication' to initialize SIC. Which action must be performed on the gateway itself for the trust to be established?
14A security administrator is troubleshooting a Security Gateway that shows SIC status 'Unknown' in SmartConsole. The administrator suspects the gateway's SIC certificate has expired. Which command on the gateway can be used to check the SIC certificate's expiration date and validity?
15A security administrator is using SmartConsole to manage a Security Gateway. The administrator needs to verify that Secure Internal Communication (SIC) is properly established between the Management Server and the gateway. Which SmartConsole status indicates that SIC is successfully established?
16A security administrator is configuring a new Security Gateway in SmartConsole. The gateway is behind a NAT device and its internal IP address is 10.1.1.1, but it communicates with the Management Server over the internet using a public IP address of 203.0.113.5. The administrator needs to ensure that SIC and policy installation work correctly. What should be configured on the gateway object in SmartConsole?
17An administrator manages multiple Security Gateways using a single Security Management Server. The administrator needs to restrict a new junior administrator so that they can only view and modify the Access Control policy for a specific gateway, but cannot install policies or modify other gateways. Which SmartConsole feature should the administrator use to meet this requirement?
18A security administrator has just installed a new R81 Security Gateway and initialized SIC with the Security Management Server. The gateway appears in SmartConsole with SIC status 'Trust established'. However, the administrator notices that the gateway's fingerprint was not verified before initialization. Which action should the administrator take to ensure the gateway's identity is trusted?
19A security administrator is preparing to establish Secure Internal Communication (SIC) between a Security Management Server and a new Security Gateway. Which two actions are required to successfully initialize SIC? (Choose two.)
20An administrator has successfully established SIC between a Security Management Server and a Security Gateway. The administrator now needs to verify that SIC is working properly. Which SmartConsole status indicates that SIC is fully established and the gateway is trusted?
21A security administrator has just installed a new R81 Security Gateway. In SmartConsole, the gateway object shows SIC status 'Not Communicating'. The administrator has already initialized SIC on the gateway using 'cpconfig' and entered the activation key. What is the next step required in SmartConsole to complete SIC establishment?
22An administrator is configuring a new Security Gateway to communicate with a Security Management Server using SIC. The administrator must ensure the SIC trust is established securely. Which two actions are required to complete SIC initialization? (Choose two.)
23A Security Management Server (SMS) is configured in a High Availability (HA) cluster with a primary and secondary server. The primary server fails, and the secondary takes over. An administrator notices that SIC communication with remote gateways continues without interruption. What is the reason for this seamless SIC continuity?
24An administrator is using SmartConsole to manage a Security Gateway. The gateway's SIC status shows 'Communicating', but the administrator cannot install policy; the installation fails with an error about the gateway not being trusted. Which action should the administrator take to resolve this?
Be able to reset SIC on a Gateway, re-establish trust with a one-time password, and restore a corrupted policy using SmartConsole revision history. The single most important thing: know that SIC trust requires matching activation keys and that publishing does not install policy to Gateways.
The Courseiva 156-215.81.20 question bank contains 24 questions in the SIC and SmartConsole Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the SIC and SmartConsole Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included