156-215.81.20 SIC and SmartConsole Management Practice Question
A Security Management Server (SMS) is configured in a High Availability (HA) cluster with a primary and secondary server. The primary server fails, and the secondary takes over. An administrator notices that SIC communication with remote gateways continues without interruption. What is the reason for this seamless SIC continuity?
⚠ Common exam trap
The trap here is thinking that gateways maintain dual SIC tunnels or that SIC is stateless, when the seamless failover actually results from the secondary server sharing the same CA and SIC certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The secondary management server shares the same internal CA and SIC certificates as the primary, allowing it to authenticate gateways without re-establishing trust.
In a High Availability management server deployment, the secondary server is kept in sync with the primary, including the internal Certificate Authority (CA) and all SIC certificates. When the primary fails, the secondary can immediately take over because it shares the same trust anchors. Gateways already trust the CA, so they accept the secondary's management connection without requiring a new SIC initialization. This ensures uninterrupted management and policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SIC uses a stateless protocol that does not rely on a persistent connection, so the secondary server can immediately resume communication using the gateway's public key.
Why it's wrong here
SIC is not stateless; it relies on certificates and a trust relationship. The secondary server can resume communication not because SIC is stateless, but because it possesses the same CA and certificate store as the primary. The gateway's public key alone is insufficient without the corresponding trust and CA validation. The HA synchronization of the certificate store is what enables seamless failover.
- ✗
Each gateway maintains a direct SIC tunnel to both the primary and secondary management servers, and automatically switches to the secondary upon primary failure.
Why it's wrong here
Gateways do not maintain simultaneous SIC tunnels to both management servers. SIC is a point-to-point trust between a gateway and the management server object. While the secondary server has a copy of the SIC certificates and can take over, the gateway does not proactively establish a second tunnel. The failover is handled by the management server cluster, not by the gateway maintaining dual connections.
- ✓
The secondary management server shares the same internal CA and SIC certificates as the primary, allowing it to authenticate gateways without re-establishing trust.
Why this is correct
In an HA configuration, the secondary management server is synchronized with the primary, including the internal Certificate Authority (CA) and all SIC certificates. When the secondary takes over, it can continue to authenticate gateways using the same CA and trust relationships. Gateways already trust the CA, so they accept the secondary's management connection without needing a new SIC initialization. This seamless failover is a key benefit of HA.
- ✗
The gateways are configured with a backup management server IP, and upon primary failure, they automatically run 'sic_reset' and re-establish SIC with the secondary.
Why it's wrong here
Gateways do not automatically run 'sic_reset' upon management failure. 'sic_reset' is a manual command that would break trust and require re-initialization. In HA, the secondary server is already trusted because it shares the same CA and SIC certificates. The gateways simply continue communicating with the secondary, which now acts as the active management server, without any manual intervention.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.