156-215.81.20 SIC and SmartConsole Management Practice Question
A security administrator has just installed a new R81 Security Gateway and initialized SIC with the Security Management Server. The gateway appears in SmartConsole with SIC status 'Trust established'. However, the administrator notices that the gateway's fingerprint was not verified before initialization. Which action should the administrator take to ensure the gateway's identity is trusted?
⚠ Common exam trap
The trap here is assuming that a 'Trust established' status alone guarantees the gateway's identity is verified, when in fact fingerprint verification is a separate manual step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In SmartConsole, open the gateway object, go to the 'Secure Internal Communication' section, and compare the fingerprint displayed there with the one shown on the gateway via 'cpconfig'.
After SIC initialization, the administrator must verify the gateway's fingerprint to ensure it matches the one presented during initialization. SmartConsole displays the fingerprint in the gateway object's Secure Internal Communication section. Comparing it with the fingerprint shown on the gateway via cpconfig or cpstat confirms authenticity. This step prevents man-in-the-middle attacks and is a best practice even when SIC status shows 'Trust established'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Edit the gateway object in SmartConsole and change the 'One-time password' to a new value, then install policy.
Why it's wrong here
The one-time password is used during initial SIC initialization, not for verifying an already established trust. Changing it after SIC is established has no effect on the existing certificate and does not verify the fingerprint. Policy installation does not validate SIC identity. This action is irrelevant to the scenario.
- ✗
Run 'cpconfig' on the gateway and select 'Secure Internal Communication' to regenerate the SIC certificate.
Why it's wrong here
Running cpconfig to regenerate the SIC certificate would reset the trust relationship and require re-initialization. This does not verify the existing fingerprint; it destroys it. The administrator needs to confirm the current fingerprint, not replace it. Regenerating is unnecessary and disruptive because SIC is already established and functional.
- ✓
In SmartConsole, open the gateway object, go to the 'Secure Internal Communication' section, and compare the fingerprint displayed there with the one shown on the gateway via 'cpconfig'.
Why this is correct
SmartConsole displays the gateway's SIC fingerprint in the gateway object under Secure Internal Communication. Comparing it with the fingerprint shown on the gateway (via cpconfig or cpstat) verifies the gateway's identity. This is the correct procedure to confirm trust after initialization, ensuring no man-in-the-middle occurred during SIC establishment.
- ✗
Use the 'sic_reset' command on the gateway and then re-initialize SIC from SmartConsole.
Why it's wrong here
sic_reset is used to reset SIC when trust is broken or compromised. In this scenario, SIC is already established and working. Resetting would unnecessarily break communication and require re-initialization, causing downtime. The goal is to verify the fingerprint, not to reset the trust relationship.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.