Courseiva

156-215.81.20 SIC and SmartConsole Management Practice Question

An administrator is using SmartConsole to manage a Security Gateway. The gateway's SIC status shows 'Communicating', but the administrator cannot install policy; the installation fails with an error about the gateway not being trusted. Which action should the administrator take to resolve this?

⚠ Common exam trap

The trap here is assuming that 'Communicating' status guarantees a valid certificate; actually, an expired certificate can still show as communicating until a policy push attempts authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the gateway's SIC certificate has not expired and re-initialize SIC if necessary.

A gateway can show SIC status 'Communicating' even if its SIC certificate has expired, because the status may reflect the last known state or a cached connection. However, policy installation requires a valid trust relationship. An expired certificate prevents the management server from authenticating the gateway, resulting in a trust error. The administrator must check the certificate expiration and re-initialize SIC to issue a new certificate, restoring trust and enabling policy installation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run 'fw putkey' on the gateway to manually update the SIC key and then push policy again.

    Why it's wrong here

    'fw putkey' is a legacy command used to manually set the SIC activation key, but it does not renew an expired certificate. The SIC process has evolved; modern versions use 'cpconfig' and SmartConsole for initialization. Using 'fw putkey' might be part of older procedures, but it would not resolve a certificate expiration issue. The correct approach is to re-initialize SIC through the proper channels, ensuring a new certificate is issued.

  • ✗

    Restart the Check Point services on the management server using 'cpstop' and 'cpstart' to refresh the SIC daemon.

    Why it's wrong here

    Restarting services might temporarily clear some errors, but it does not fix an expired SIC certificate. The trust failure is due to certificate expiration, not a service glitch. While a restart could be part of troubleshooting, it is not the correct resolution here. The administrator must address the expired certificate by re-initializing SIC, which involves resetting SIC on both the gateway and management server and re-establishing trust.

  • ✓

    Verify that the gateway's SIC certificate has not expired and re-initialize SIC if necessary.

    Why this is correct

    Even if SIC status shows 'Communicating', an expired SIC certificate can cause policy installation to fail with a trust error. SIC certificates have a validity period, typically one year. If expired, the gateway and management server cannot authenticate each other. The administrator should check the certificate expiration in SmartConsole (under the gateway's SIC properties) and re-initialize SIC by resetting and re-establishing trust. This resolves the trust issue and allows policy installation.

  • ✗

    Check the firewall rulebase to ensure that TCP port 18191 is allowed between the management server and gateway.

    Why it's wrong here

    If SIC status is 'Communicating', then TCP port 18191 is already open and functional. The error is about trust, not connectivity. While port 18191 is necessary for SIC, it is not the cause of the policy installation failure in this scenario. The administrator should focus on the certificate trust issue, not the firewall rules, as the communication is already established but authentication is failing due to an expired certificate.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.