Courseiva

156-215.81.20 SIC and SmartConsole Management Practice Question

A security administrator has just installed a new R81 Security Gateway. In SmartConsole, the gateway object shows SIC status 'Not Communicating'. The administrator has already initialized SIC on the gateway using 'cpconfig' and entered the activation key. What is the next step required in SmartConsole to complete SIC establishment?

⚠ Common exam trap

The trap here is assuming that testing SIC status or restarting services will initiate the trust handshake, when the actual requirement is entering the matching activation key in SmartConsole.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the gateway object's General Properties, enter the same activation key in the 'One-time password' field and click 'Initialize'.

SIC establishment requires a shared secret (activation key) to be configured on both the gateway and the management server. After initializing SIC on the gateway via 'cpconfig', the administrator must enter the same one-time password in the gateway object's General Properties in SmartConsole and click 'Initialize'. This allows the management server to authenticate the gateway and issue the SIC certificate, transitioning the status to 'Communicating'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run 'cpstart' on the Security Management Server to restart the SIC daemon and push the trust configuration to the gateway.

    Why it's wrong here

    Restarting the management server's services with 'cpstart' does not push SIC credentials to the gateway. SIC trust is established through the one-time password exchange, not by restarting services. Running 'cpstart' would cause unnecessary downtime and would not resolve the 'Not Communicating' status because the activation key has not been entered in SmartConsole.

  • ✗

    On the gateway, run 'sic_reset' and then import the management server's SIC certificate manually using 'cpca_client'.

    Why it's wrong here

    Running 'sic_reset' would erase the SIC configuration the administrator just initialized, undoing the previous step. Manually importing certificates with 'cpca_client' is not the standard procedure for initial SIC establishment. The correct process is to enter the one-time password in the gateway object in SmartConsole, which automates the trust establishment.

  • ✗

    In the gateway object's General Properties, click 'Test SIC Status' to force the gateway to initiate the SIC handshake.

    Why it's wrong here

    Clicking 'Test SIC Status' only checks the current SIC status; it does not initiate the trust establishment. The management server must first be told the activation key so it can authenticate the gateway. Without entering the key in SmartConsole, the gateway cannot be trusted, and testing will continue to show 'Not Communicating'.

  • ✓

    In the gateway object's General Properties, enter the same activation key in the 'One-time password' field and click 'Initialize'.

    Why this is correct

    After running 'cpconfig' on the gateway and entering the activation key, the administrator must enter the identical one-time password in the gateway object's General Properties in SmartConsole and click 'Initialize'. This triggers the management server to establish trust with the gateway using the shared secret, completing SIC. The gateway then generates its SIC certificate and the status changes to 'Communicating'.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.