156-215.81.20 SIC and SmartConsole Management Practice Question
An administrator is configuring a new Security Gateway to communicate with a Security Management Server using SIC. The administrator must ensure the SIC trust is established securely. Which two actions are required to complete SIC initialization? (Choose two.)
⚠ Common exam trap
The trap here is thinking that SIC initialization involves manual certificate exchange or policy installation, when it actually relies on a one-time password and automated certificate signing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'cpconfig' on the gateway and select 'Secure Internal Communication' to enter the one-time password.
SIC initialization requires two key actions: generating a one-time password in SmartConsole for the gateway object, and then entering that password on the gateway via cpconfig under Secure Internal Communication. These steps create the trust relationship. Other actions like DNS configuration or policy installation are either prerequisites or subsequent tasks, not part of SIC initialization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the Security Policy on the gateway to activate SIC.
Why it's wrong here
Installing the Security Policy does not activate SIC. SIC must be established before policy installation can occur, as the management server needs secure communication to push the policy. Policy installation is a subsequent step after SIC trust is confirmed. It is not part of SIC initialization.
- ✗
Manually copy the management server's certificate to the gateway using SCP.
Why it's wrong here
SIC initialization does not require manually copying certificates via SCP. The process is automated: the gateway generates a certificate request and the management server signs it. Manual copying is unnecessary and could introduce security risks. The one-time password mechanism handles authentication securely.
- ✓
Run 'cpconfig' on the gateway and select 'Secure Internal Communication' to enter the one-time password.
Why this is correct
After obtaining the one-time password, the administrator must run cpconfig on the gateway and select Secure Internal Communication. Entering the password there initiates the certificate request and establishes trust with the management server. This step is mandatory to complete SIC initialization.
- ✗
Configure the gateway's DNS settings to resolve the management server's hostname.
Why it's wrong here
While DNS resolution is important for connectivity, it is not part of the SIC initialization process itself. SIC uses IP addresses or hostnames configured in SmartConsole, but DNS configuration is a prerequisite for network communication, not a step in establishing SIC trust. The required steps are generating and entering the one-time password.
- ✓
Generate a one-time password in SmartConsole for the gateway object.
Why this is correct
Generating a one-time password in SmartConsole is the first step. This password is used to authenticate the gateway during SIC initialization. It is displayed in the gateway's Secure Internal Communication properties and must be entered on the gateway. Without it, the gateway cannot initiate the trust establishment process.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.