Courseiva

156-215.81.20 SIC and SmartConsole Management Practice Question

A security administrator has just initialized a new Security Gateway with the First Time Configuration Wizard. In SmartConsole, the gateway object exists but its SIC status shows 'Not Communicating'. The administrator opens the gateway object and clicks 'Communication' to initialize SIC. Which action must be performed on the gateway itself for the trust to be established?

⚠ Common exam trap

The trap here is assuming that starting services or rebooting the gateway will automatically pull the SIC certificate, when in fact the one-time password must be manually entered on both sides to bootstrap trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enter the one-time password on the gateway in the 'Secure Internal Communication' section of cpconfig.

SIC initialization always requires a shared secret: the administrator sets a one-time password in the gateway object in SmartConsole, then enters that same password on the gateway through cpconfig's Secure Internal Communication section. The gateway uses this password to authenticate itself to the management server's internal CA, which then issues the gateway's SIC certificate. Only after this exchange does the status change to Communicating.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run 'cpstart' on the gateway to start all Check Point services.

    Why it's wrong here

    Starting Check Point services with cpstart does not complete SIC initialization. The gateway must trust the management server's certificate; simply running services leaves the one-time password unentered and SIC stays in a 'Not Communicating' state, so this action alone will not establish trust.

  • ✗

    Reboot the gateway so it can retrieve its SIC certificate from the management server.

    Why it's wrong here

    A reboot does not trigger SIC certificate retrieval. The gateway cannot pull its certificate without first proving trust via the one-time password. Rebooting only restarts services and leaves the SIC state unchanged, so this will not resolve the 'Not Communicating' status.

  • ✗

    Import the management server's SIC certificate manually using 'cpca_client'.

    Why it's wrong here

    cpca_client is used for certificate authority operations, not for initial SIC trust establishment. Manually importing a certificate bypasses the one-time password mechanism and is not the supported method. SIC initialization is designed to be performed through cpconfig on the gateway, not by manual certificate import.

  • ✓

    Enter the one-time password on the gateway in the 'Secure Internal Communication' section of cpconfig.

    Why this is correct

    SIC initialization requires a one-time password set on the management server and entered on the gateway via cpconfig. This one-time password is used to authenticate the initial certificate exchange, creating the trust relationship. Without this step, the gateway will never transition to 'Communicating' status.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.