Courseiva

156-215.81.20 SIC and SmartConsole Management Practice Question

A security administrator is preparing to establish Secure Internal Communication (SIC) between a Security Management Server and a new Security Gateway. Which two actions are required to successfully initialize SIC? (Choose two.)

⚠ Common exam trap

The trap here is thinking that manual certificate creation or legacy commands like fw putkey are needed, when the modern process relies solely on the one-time password exchange.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

On the gateway, run cpconfig and enter the same one-time password in the Secure Internal Communication section.

SIC initialization requires a shared secret. The administrator sets a one-time password in the gateway object in SmartConsole, then enters the identical password on the gateway using cpconfig's Secure Internal Communication section. This exchange authenticates the gateway to the management server's internal CA, which issues the SIC certificate. Both actions are mandatory for successful initialization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    On the gateway, run cpconfig and enter the same one-time password in the Secure Internal Communication section.

    Why this is correct

    Entering the one-time password on the gateway via cpconfig completes the initial trust handshake. The gateway uses this password to authenticate to the management server, which then issues the SIC certificate. This step is mandatory; without it, the gateway remains in 'Not Communicating' state.

  • ✗

    On the management server, run fw putkey to push the SIC certificate to the gateway.

    Why it's wrong here

    fw putkey is an obsolete command used in older versions to establish SIC without a one-time password. In current versions, SIC initialization uses the one-time password method via SmartConsole and cpconfig. fw putkey is not used and is considered insecure, so it is not a required action.

  • ✗

    On the gateway, run sic_reset to clear any existing trust before initialization.

    Why it's wrong here

    sic_reset is used to reset an existing SIC trust, not to initialize a new one. For a new gateway with no prior SIC configuration, running sic_reset is unnecessary and could complicate the process. It is only needed when re-establishing trust after a failure or certificate change.

  • ✗

    On the management server, run cpca_client create_cert to generate a new SIC certificate for the gateway.

    Why it's wrong here

    cpca_client create_cert is not a standard command for SIC initialization. The management server's internal CA automatically issues the SIC certificate during the one-time password exchange. Manually creating a certificate is unnecessary and not part of the supported SIC initialization process.

  • ✓

    In SmartConsole, open the gateway object, navigate to Communication, and set a one-time password.

    Why this is correct

    Setting a one-time password in the gateway object's Communication section is the first required step. This password is stored on the management server and must match what is entered on the gateway. Without it, the gateway cannot authenticate to the management server's internal CA, and SIC initialization will fail.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.