Courseiva

156-215.81.20 SIC and SmartConsole Management Practice Question

A security administrator has just installed a new R81 Security Gateway and initialized SIC with the Security Management Server. The gateway appears in SmartConsole with SIC status 'Trust established'. However, the administrator notices that the gateway's fingerprint was not verified before initialization. Which action should the administrator take to ensure the gateway's identity is trusted?

⚠ Common exam trap

The trap here is assuming that a 'Trust established' status alone guarantees the gateway's identity is verified, when in fact fingerprint verification is a separate manual step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In SmartConsole, open the gateway object, go to the 'Secure Internal Communication' section, and compare the fingerprint displayed there with the one shown on the gateway via 'cpconfig'.

After SIC initialization, the administrator must verify the gateway's fingerprint to ensure it matches the one presented during initialization. SmartConsole displays the fingerprint in the gateway object's Secure Internal Communication section. Comparing it with the fingerprint shown on the gateway via cpconfig or cpstat confirms authenticity. This step prevents man-in-the-middle attacks and is a best practice even when SIC status shows 'Trust established'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Edit the gateway object in SmartConsole and change the 'One-time password' to a new value, then install policy.

    Why it's wrong here

    The one-time password is used during initial SIC initialization, not for verifying an already established trust. Changing it after SIC is established has no effect on the existing certificate and does not verify the fingerprint. Policy installation does not validate SIC identity. This action is irrelevant to the scenario.

  • ✗

    Run 'cpconfig' on the gateway and select 'Secure Internal Communication' to regenerate the SIC certificate.

    Why it's wrong here

    Running cpconfig to regenerate the SIC certificate would reset the trust relationship and require re-initialization. This does not verify the existing fingerprint; it destroys it. The administrator needs to confirm the current fingerprint, not replace it. Regenerating is unnecessary and disruptive because SIC is already established and functional.

  • ✓

    In SmartConsole, open the gateway object, go to the 'Secure Internal Communication' section, and compare the fingerprint displayed there with the one shown on the gateway via 'cpconfig'.

    Why this is correct

    SmartConsole displays the gateway's SIC fingerprint in the gateway object under Secure Internal Communication. Comparing it with the fingerprint shown on the gateway (via cpconfig or cpstat) verifies the gateway's identity. This is the correct procedure to confirm trust after initialization, ensuring no man-in-the-middle occurred during SIC establishment.

  • ✗

    Use the 'sic_reset' command on the gateway and then re-initialize SIC from SmartConsole.

    Why it's wrong here

    sic_reset is used to reset SIC when trust is broken or compromised. In this scenario, SIC is already established and working. Resetting would unnecessarily break communication and require re-initialization, causing downtime. The goal is to verify the fingerprint, not to reset the trust relationship.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.