Courseiva

156-215.81.20 · domain

troubleshooting

Practise Check Point Certified Security Administrator troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

210 questions38 easy109 medium63 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (210)

Click any question to see the full explanation, or start a practice session above.

1

A Check Point administrator is configuring user authentication for a Remote Access VPN. The administrator wants to use certificates for authentication but also requires a second factor. The administrator decides to use SecurID tokens as the second factor. Which authentication method should be configured in the user object to achieve this?

Hard
2

A security administrator is preparing to establish Secure Internal Communication (SIC) between a Security Management Server and a new Security Gateway. Which two actions are required to successfully initialize SIC? (Choose two.)

Medium
3

A security administrator at a financial firm needs to block all peer-to-peer file-sharing applications for the entire company, but must allow legitimate business use of instant messaging. The administrator wants the least administrative effort and automatic updates of new application signatures. What should the administrator do?

Medium
4

An administrator notices that a user is able to access a website categorized as 'Social Networking' even though the URL Filtering policy blocks that category. The administrator confirms the policy is installed and the user's traffic is inspected. What is the most likely cause?

Hard
5

Which of these is the primary benefit of using manual NAT rules in a large, complex network?

Easy
6

An administrator notices that Application Control is not identifying a popular cloud-based application even though it is listed in the Application Control database. The gateway is running R81.10 and the database is up to date. What could be the cause?

Hard
7

A security administrator needs to allow access to a specific website that is categorized as 'Social Networking' while blocking all other social networking sites. The administrator wants to ensure that only that particular URL is allowed. What is the most efficient way to achieve this in the URL Filtering policy?

Easy
8

What is the primary function of the 'Identity Collector' in a distributed Identity Awareness environment?

Medium
9

When using LDAP as an external authentication provider for administrators, why must the 'Search Base' be configured correctly?

Hard
10

Where do you configure 'Automatic NAT' for a specific network host object in SmartConsole?

Easy
11

Which phase of the IKE negotiation is responsible for authenticating the peers and establishing a secure channel for subsequent management traffic?

Medium
12

An administrator wants to enforce a policy that blocks access to websites categorized as 'Hacking' but allows access to 'Computer Security' sites. The administrator creates a URL Filtering rule with the action 'Block' for the 'Hacking' category and places it above a rule that allows 'Computer Security'. However, users report that they can still access some hacking-related sites. Upon investigation, the administrator finds that these sites are categorized as 'Computer Security' by the Check Point URL Filtering database. What should the administrator do to ensure these sites are blocked?

Hard
13

A Security Management Server (SMS) is configured in a High Availability (HA) cluster with a primary and secondary server. The primary server fails, and the secondary takes over. An administrator notices that SIC communication with remote gateways continues without interruption. What is the reason for this seamless SIC continuity?

Hard
14

Which TWO of the following are consequences of using 'Hide NAT' incorrectly in a network environment?

Medium
15

Which blade must be active to perform HTTPS Inspection on traffic?

Medium
16

What is the difference between 'Main Mode' and 'Aggressive Mode' in IKE Phase 1?

Hard
17

A network administrator is configuring a VPN community that includes a Check Point R81 Security Gateway and a third-party IPsec gateway. The administrator needs to ensure that the VPN tunnel uses specific encryption and hashing algorithms that are supported by both devices. Where should the administrator configure these settings in SmartConsole?

Medium
18

A security administrator is configuring a new Security Gateway in SmartConsole. The gateway is behind a NAT device and its internal IP address is 10.1.1.1, but it communicates with the Management Server over the internet using a public IP address of 203.0.113.5. The administrator needs to ensure that SIC and policy installation work correctly. What should be configured on the gateway object in SmartConsole?

Medium
19

A security administrator is troubleshooting a Site-to-Site VPN between two Check Point R81 gateways. The VPN tunnel is up, but traffic from a specific subnet behind Gateway A is not reaching the corresponding subnet behind Gateway B. The administrator has verified that the encryption domains include the correct subnets and that the VPN community is properly configured. Which action should the administrator take next to resolve the issue?

Hard
20

Refer to the exhibit. The log shows a drop. What does this indicate about the rule base?

Hard
21

An administrator attempts to establish Secure Internal Communication between a newly installed Security Gateway and the Management Server, but the SIC status repeatedly shows 'Trust Not Established'. The network path is verified and standard TCP port 1849 is fully open. What is the most likely root cause of this failure?

Medium
22

A Check Point administrator is configuring a Remote Access VPN with Endpoint Security VPN clients. The administrator wants to ensure that all traffic from the remote clients, including Internet-bound traffic, is routed through the Security Gateway for inspection. Which configuration should be enabled in the Remote Access VPN community?

Hard
23

What is the purpose of the 'Auditor' role in Check Point management?

Medium
24

A security administrator needs to block access to a specific unknown application that uses HTTP but does not match any signature in the current Application Control database. The administrator wants to ensure the application is blocked immediately without waiting for a database update. What is the most efficient way to achieve this?

Medium
25

A company wants users on managed Windows endpoints to be identified by Identity Awareness without requiring them to open a browser or wait for an AD event log poll. The endpoints are domain-joined and already managed by the organization. Which acquisition method meets this requirement most directly?

Easy
26

Which object property must be enabled on a gateway for it to support NAT?

Easy
27

A Check Point administrator is configuring NAT for a new subnet that will be used for a guest wireless network. The guest subnet is 172.16.50.0/24, and the administrator wants to hide all guest traffic behind the external interface IP 203.0.113.5. The administrator creates a network object for the guest subnet and configures Hide NAT using the external interface. After testing, guests can access the Internet, but the administrator notices that the translation is not being applied to traffic originating from the guest subnet when it is destined to a server on the internal network (192.168.1.0/24). What is the most likely reason for this behavior?

Medium
28

A security administrator notices that users are accessing a newly registered domain that is not yet categorized by Check Point. The administrator wants to block access to uncategorized sites until they are reviewed. Which URL Filtering action should be configured?

Easy
29

Which option is recommended to prevent 'VPN tunnel flapping' when a connection is unstable?

Medium
30

A security administrator needs to send only Security Gateway log records to an external SIEM over syslog, while keeping the Management Server's own audit logs local. Which Check Point configuration should be performed?

Medium
31

An administrator is setting up a Remote Access VPN using Check Point Mobile Access Blade. The company wants to ensure that remote users can access internal resources using the same IP address throughout their session, and that the IP address is from a specific internal subnet. Which feature should be enabled in the gateway's Remote Access configuration?

Easy
32

When configuring a VPN Community, what is the impact of selecting 'Maintain persistent tunnels' on the gateway?

Medium
33

An administrator is configuring a new Security Gateway to communicate with a Security Management Server using SIC. The administrator must ensure the SIC trust is established securely. Which two actions are required to complete SIC initialization? (Choose two.)

Hard
34

An administrator needs to allow internal users to access the Internet using Hide NAT. The internal network is 192.168.1.0/24, and the gateway's external interface IP is 203.0.113.5. Which NAT rule should be configured?

Easy
35

A security administrator is configuring a rule in the Application Control policy to block all peer-to-peer file sharing applications. After enabling the rule, users report that they can still use uTorrent to download files. The administrator checks the logs and sees that the uTorrent traffic is being matched by a different rule that allows all allowed applications. What is the most likely cause of this issue?

Medium
36

A security administrator at a company with a Check Point R81 management server and two clustered Security Gateways is configuring NAT for a web server on the internal network. The server's private IP is 192.168.10.50, and it must be reachable from the Internet at public IP 203.0.113.25. The administrator wants to ensure that return traffic from the server is automatically translated back to the public IP without creating a separate outbound NAT rule. Which NAT method should be configured on the web server object in SmartConsole?

Hard
37

A security administrator has configured a URL Filtering rule to block the 'Gambling' category. Users report that they can still access some gambling sites. The administrator checks the logs and sees that the traffic is being allowed by a rule that allows 'Any' application and 'Any' URL. The administrator verifies that the block rule is above the allow rule. What is the most likely reason for the issue?

Hard
38

An administrator wants to ensure that logs are indexed properly for quick searching in SmartView. Which process is responsible for this indexing?

Medium
39

Refer to the exhibit. An administrator notices that traffic from Internal_Net to Server_Farm is being translated by Rule 1 instead of Rule 2. What is the most likely cause?

Hard
40

A security administrator at a financial firm wants to allow access to the corporate banking portal at 'secure.bank.com' but block all other online banking sites for a specific user group. The policy already includes a rule that blocks the 'Financial Services' category. How should the administrator configure the policy to meet this requirement?

Medium
41

A security administrator is deploying Identity Awareness using the Identity Collector in an environment with multiple domain controllers. The administrator wants to ensure that user identity information is collected from all domain controllers and that the load is distributed. Which configuration should be implemented?

Hard
42

A security administrator is using SmartConsole to manage a Security Gateway. The administrator needs to verify that Secure Internal Communication (SIC) is properly established between the Management Server and the gateway. Which SmartConsole status indicates that SIC is successfully established?

Easy
43

An administrator is troubleshooting an issue where logs from a Security Gateway are not appearing in SmartLog. The administrator verifies that the gateway is sending logs to the Management Server, but the logs are not indexed. Which service should the administrator check on the Management Server to ensure proper log indexing?

Hard
44

An administrator is troubleshooting an issue where users are identified as 'Unknown' despite having Identity Awareness enabled. What is the first logical step to investigate?

Hard
45

A security administrator must let contractors on personally owned, non-domain laptops access internal resources. The contractors cannot install endpoint software, and the organization wants them to authenticate through a web page before access is granted. Which Identity Awareness acquisition method fits these constraints?

Medium
46

A security policy requires that users are presented with a warning page before accessing sites categorized as 'High Risk'. After the warning, they can choose to proceed. Which URL Filtering action should be configured in the rule?

Easy
47

A security administrator manages a Check Point R81.20 environment with a Security Gateway and a separate Identity Collector. Users authenticate through Microsoft Active Directory, and the administrator wants to minimize the number of AD queries sent from the gateway. Which configuration should the administrator use to achieve this?

Medium
48

An administrator needs to review logs from a specific Security Gateway that occurred between 2:00 AM and 4:00 AM yesterday. Which SmartConsole application should the administrator use to efficiently filter and analyze these logs?

Easy
49

Which object type should an administrator use to block access to a wide range of websites deemed inappropriate, such as adult content?

Medium
50

What is the primary benefit of the 'ThreatCloud' service for URL Filtering?

Medium
51

A security administrator notices that users are accessing a gambling website that is not being blocked, even though the 'Gambling' category is set to Block in the URL Filtering policy. The administrator verifies that the policy is installed and the site is indeed categorized as 'Gambling'. What is the most likely reason for this issue?

Hard
52

A security administrator needs to configure a Security Gateway to send its logs to a third-party SIEM via syslog. The SIEM is reachable only through an external interface, and the administrator wants to avoid sending logs over the internal network. Which Check Point feature should be used to achieve this requirement?

Medium
53

A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a web server farm. The administrator needs to ensure that external users can access the web servers using a single public IP, and that the web servers can initiate outbound connections to the Internet. The administrator decides to use manual NAT rules. Which two statements are correct regarding the configuration of manual NAT rules in this scenario? (Choose two.)

Hard
54

Refer to the exhibit. An administrator reports they can see all objects but cannot push policies. Reviewing the configuration, what is the most likely cause of this restriction?

Hard
55

Why might you use a 'Hide NAT' rule with a specific IP pool instead of a single interface IP?

Hard
56

Which of the following describes the function of the 'Identity Awareness Gateway' in a load-sharing cluster?

Medium
57

An administrator needs to reset Secure Internal Communication (SIC) on a remote Security Gateway that is currently showing a status of 'Communication Error' in SmartConsole. Which TWO actions must be performed to successfully re-establish the SIC relationship? (Choose TWO)

Hard
58

Which TWO of the following are mandatory steps when configuring a new Site-to-Site VPN community?

Medium
59

A security administrator needs to allow a group of external consultants to access the corporate network via the Remote Access VPN. These consultants are not defined in the internal Active Directory. The administrator wants to minimize administrative overhead and ensure that the consultants can authenticate using their own existing credentials from their home company's LDAP server. Which Check Point object should be used to represent these external consultants?

Medium
60

An administrator is configuring Application Control and URL Filtering on a new Security Gateway. The administrator wants to ensure that the gateway can identify applications and enforce policy correctly. Which two actions are required to enable Application Control and URL Filtering? (Choose two.)

Medium
61

An administrator is creating a new user account in the SmartConsole. The user needs to authenticate via a username and password that is stored in the Check Point user database. Which user type should the administrator select?

Easy
62

Which TWO settings are required when configuring the 'Active Directory Query' method in the Identity Awareness blade?

Medium
63

Refer to the exhibit. [VPN] Community: HQ-Branch-Star Tunnel type: Permanent Tunnel Status: Down (Reason: No valid SA found) An administrator reviews the VPN status output shown above for a permanent tunnel in a Star community. Despite the permanent tunnel setting, the tunnel remains down. What is the most likely cause of this behavior?

Hard
64

An administrator is configuring Identity Awareness on a Security Gateway and wants to enable users to authenticate via a web portal before accessing network resources. The administrator wants to minimize user disruption and avoid installing additional software. Which Identity Awareness method should be used?

Easy
65

An administrator is deploying Identity Awareness on a Check Point R81.20 Security Gateway. Users authenticate to a captive portal hosted by the gateway itself, without any external directory service. Which Identity Awareness method is being used?

Medium
66

Which IKE Phase 2 proposal setting specifically ensures that session keys are not derived from the original long-term keys, protecting past sessions if a key is compromised?

Medium
67

Refer to the exhibit. An administrator reviews the Identity Awareness status of a user workstation using CLI commands on the Security Gateway. What does the 'Identity Source: Identity Agent' field specifically indicate about how this user's identity was acquired?

Medium
68

An administrator needs to restrict a junior admin's access to only managing security policies within a specific Management Server domain. Which feature should be configured to implement this granular control?

Medium
69

An administrator configures Identity Awareness with Active Directory Query on an R81.20 Security Gateway. Users are authenticated via Kerberos, and the gateway has been joined to the domain. However, after login, some users are not being identified. The administrator notices that the gateway's AD Query service account password has expired. What is the most likely cause of the identification failure?

Medium
70

A Check Point administrator is deploying a Mesh VPN community with three gateways: GW-A, GW-B, and GW-C. The administrator wants to ensure that traffic between any two gateways is encrypted and that the community automatically creates the necessary tunnels. After configuration, the administrator notices that traffic between GW-A and GW-C is not encrypted, while traffic between GW-A and GW-B is encrypted. What is the most likely reason for this issue?

Hard
71

What happens when the URL Filtering database is unreachable by the gateway?

Medium
72

A senior administrator needs to restrict a junior security operator so they can view and edit access control policies, but they must be strictly prohibited from installing policies onto production Security Gateways. Which SmartConsole mechanism should be utilized to enforce this operational boundary?

Medium
73

An administrator configures Identity Awareness in a Check Point environment using Active Directory Query. Users report that access policies based on user groups fail intermittently for workstations after users lock their screens. Which underlying mechanism causes this authentication loss?

Medium
74

A security administrator is configuring a Check Point R81 Management Server to authenticate administrators via RADIUS. The RADIUS server is already configured with the necessary user accounts. After creating a RADIUS server object and enabling RADIUS authentication for administrators, the administrator tests login with a RADIUS user but fails. The administrator confirms the RADIUS server is reachable and the shared secret matches. What is the most likely cause of the failure?

Medium
75

A security administrator has deployed Identity Awareness with Terminal Server Agent on a Check Point R81.20 gateway. Users report that their identities are correctly identified when they log in, but after disconnecting and reconnecting to a different session on the same terminal server, they are still associated with the old session. What is the most likely cause?

Hard
76

Why is it recommended to use a separate administrative account for policy management versus day-to-day monitoring?

Medium
77

What is the primary function of the 'Read-Only All' Permission Profile in Check Point?

Medium
78

Refer to the exhibit. An administrator is troubleshooting Application Control traffic. What does the CLI output verify regarding the traffic flow?

Hard
79

A security administrator is configuring NAT for a network where internal users need to access external web servers. The administrator wants to hide the internal IP addresses behind a single public IP address. However, some internal users report that they cannot access certain websites that require multiple simultaneous connections from the same source IP. What is the most likely cause of this issue?

Hard
80

When configuring a NAT rule that involves a VPN community, why is 'Hide NAT' often problematic?

Hard
81

An administrator needs to block a specific web application that is not recognized by the default Application Control signature database. The application uses a custom protocol on TCP port 8443. What is the most appropriate method to achieve this?

Medium
82

An administrator has just initialized Secure Internal Communication (SIC) on a new Security Gateway using the one-time password 'CpWk987'. In SmartConsole, the administrator opens the gateway object, goes to the General Properties > Secure Internal Communication section, and enters the same one-time password. After clicking Initialize, the SIC status changes to 'Trust established'. However, the administrator notices that the gateway's SIC status later reverts to 'Unknown' after a few minutes. What is the most likely cause?

Medium
83

Refer to the exhibit. An administrator is troubleshooting an intermittent SIC authentication failure between the Security Management Server and cluster-gw-01. Based on the CLI output, what does the cpca_client command verify?

Hard
84

An administrator is configuring Identity Awareness on a Check Point R81.20 gateway using the Identity Collector. Users are authenticated via multiple Active Directory domains in a forest. The administrator notices that users from one domain are not being identified. What is the most likely cause?

Hard
85

An administrator needs to review all logs generated by a specific Security Gateway over the past week. The administrator wants to see the logs in a tabular format and apply filters based on source IP. Which SmartConsole tool should the administrator use?

Easy
86

When configuring Check Point internal users for SmartConsole authentication, what is the best practice for password management?

Easy
87

A security administrator needs to allow a group of contractors to access the corporate network via Remote Access VPN. The contractors are already defined in an external LDAP directory. The administrator wants to avoid creating individual user accounts in SmartConsole and wants to apply a specific set of VPN settings to all contractors. Which object should the administrator use to represent the contractors in the VPN community configuration?

Hard
88

An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway. The company uses a single Active Directory domain and wants to identify users without installing any software on client machines. Which Identity Awareness method should the administrator choose?

Medium
89

An administrator needs to verify that a Security Gateway is sending logs to the Management Server. The administrator wants to see a real-time count of log messages received by the management server from each gateway. Which SmartConsole tool provides this information?

Easy
90

An administrator needs to implement Identity Awareness to control access based on user groups. Which authentication method should be configured to ensure seamless transparency for users already logged into a Windows domain without requiring manual credentials input?

Medium
91

When a Management Server is in a high-availability configuration, how does SIC handle communication if the primary management server fails?

Medium
92

A security administrator at a company with 500 employees needs to grant SmartConsole access to a team of 10 auditors. The auditors must be able to view all security policies and logs but must not be able to modify any objects or rules. The administrator wants to avoid creating 10 separate administrator accounts. What is the most efficient way to achieve this?

Medium
93

An administrator configures Identity Awareness using Active Directory Query to authenticate domain users. After deployment, users report intermittent authentication failures, and logs show that the Security Gateway fails to query the Domain Controllers due to insufficient privileges. Which account permission must be granted to resolve this issue without granting Domain Administrator rights?

Medium
94

An administrator has just deployed a new R81 Security Gateway and needs to establish Secure Internal Communication (SIC) with the existing Management Server. The administrator runs the command 'cpconfig' on the gateway, selects the option to initialize SIC, and enters the activation key. After completing the wizard, the administrator checks SmartConsole and sees that the gateway's SIC status is still 'Not Communicating'. The administrator verifies that the gateway's IP address is correct, the firewall policy allows traffic on port 257, and the Management Server is reachable. What is the most likely reason for the SIC status not being established?

Medium
95

An administrator needs to create a new administrator account in SmartConsole with permissions restricted exclusively to monitoring logs and viewing tracking data without any ability to modify rules. Which TWO configuration actions must be performed? (Choose TWO)

Hard
96

An administrator has configured Identity Awareness with Terminal Server Agent on a Terminal Server. Users report that after disconnecting from a Remote Desktop session and reconnecting, they are sometimes identified as the previous user. What is the most likely cause of this issue?

Hard
97

A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a DMZ. The DMZ contains a mail server with IP address 10.10.10.5 and a web server with IP address 10.10.10.6. Both servers must be accessible from the Internet using separate public IP addresses. The administrator wants to minimize the number of NAT rules and ensure that the translation is applied correctly. Which NAT configuration approach is most appropriate?

Hard
98

A security administrator is troubleshooting a Security Gateway that shows SIC status 'Unknown' in SmartConsole. The administrator suspects the gateway's SIC certificate has expired. Which command on the gateway can be used to check the SIC certificate's expiration date and validity?

Medium
99

A security administrator manages a Check Point R81.20 environment with Identity Awareness using Active Directory Query. Users on domain-joined machines are identified correctly, but users who connect through a NAT device are consistently shown as unknown. What is the most likely cause?

Hard
100

An administrator has configured a rule to block the 'File Storage and Sharing' category. Users report that they can still access 'Dropbox' via the web interface, but the log shows the connection as allowed. The administrator verifies that the rule is correctly placed and the Application Control blade is enabled. Which action should the administrator take to ensure 'Dropbox' is blocked?

Hard
101

A Check Point administrator is configuring user authentication for a remote access VPN community. The organization uses an external LDAP directory server for user credentials. The administrator wants to avoid creating local user accounts on the Security Management Server. Which Check Point object should be used to represent the external LDAP users for authentication?

Medium
102

Your organization requires that all log files be rotated when they reach a specific size limit to ensure efficient disk usage. Where should an administrator configure the automatic log rotation settings in SmartConsole?

Medium
103

Which action must be performed after updating a Permission Profile to ensure the changes take effect for active sessions?

Medium
104

What is the function of the 'Internal Certificate Authority' (ICA) in a Check Point environment?

Hard
105

What is the primary difference between a 'Site-to-Site' VPN and a 'Remote Access' VPN in a Check Point environment?

Easy
106

An administrator is creating a new user account in SmartConsole. The administrator wants the user to be able to authenticate to the Check Point Mobile Access portal using a username and password stored locally on the Management Server. Which authentication method should be selected for this user?

Easy
107

An administrator is troubleshooting an Identity Awareness deployment where some users are intermittently shown as unidentified on the Security Gateway. The environment uses AD Query. Which TWO conditions would cause AD Query to fail to identify a logged-in user? (Choose two.)

Hard
108

An administrator notices that the Security Management Server's disk space is being consumed rapidly by log files. The administrator wants to automatically delete logs older than 90 days to free up space. Which Check Point feature should be configured to achieve this?

Medium
109

A security administrator is investigating a suspicious connection to an external IP. The administrator needs to see the raw packet-level details captured by the Security Gateway's IPS blade to determine the exact payload that triggered the protection. Which SmartConsole tool should the administrator use to view this information?

Medium
110

A Check Point administrator needs to configure authentication for a group of external users who will access the network via a VPN. The users are stored in an Active Directory domain. The administrator wants to use the AD credentials for authentication and also wants to assign different permissions based on AD group membership. Which two actions must the administrator take to achieve this? (Choose two.)

Medium
111

A security analyst is investigating a suspected intrusion and needs to view all logs related to a specific source IP address across multiple Security Gateways. The logs are stored on a central Management Server. Which SmartConsole feature should the analyst use to efficiently search and filter these logs?

Hard
112

A security administrator is configuring NAT for a new internal server (10.0.0.5) that needs to be accessible from the Internet on port 443 using the public IP 203.0.113.20. The administrator creates a host object for the server and configures a Static NAT rule. Which additional configuration is required to allow inbound HTTPS traffic to reach the server?

Easy
113

An administrator is configuring NAT for a new web server on the internal network. The server must be accessible from the Internet using a public IP address, and connections must be initiated from the Internet to the server. The internal IP is 10.1.1.10, and the public IP is 203.0.113.10. Which NAT method should be used?

Medium
114

A security administrator at a company using Check Point R81 Management Server needs to verify that a newly created administrator account named 'jsmith' has been assigned the correct permission profile before the account is used. The administrator opens SmartConsole and navigates to the Manage & Settings view. Which action should the administrator take to view the permission profile assigned to 'jsmith'?

Medium
115

A security administrator wants to configure the Check Point Management Server to authenticate administrators using an external LDAP directory. The LDAP server is already defined as an object in SmartConsole. Which of the following is the correct next step to enable LDAP authentication for administrators?

Medium
116

Which tab in SmartConsole allows an administrator to view the status of the Security Management Server and its associated gateways, including CPU and memory usage?

Easy
117

A company wants to prevent employees from uploading files to cloud storage sites. Which action should the administrator take in the Application Control rule?

Medium
118

When configuring a VPN Community with 'Office Mode' enabled, what is the primary benefit for remote access clients?

Hard
119

An administrator is configuring a Remote Access VPN with Endpoint Security VPN clients connecting to a Check Point R81 gateway. The administrator wants to ensure that the VPN clients can access internal resources and that the gateway can apply security policies to the clients based on their user identity. Which two components must be configured to achieve this? (Choose two.)

Hard
120

When configuring an administrator with 'Read/Write' access in a specific domain, what does 'Scope' define?

Hard
121

An administrator manages multiple Security Gateways using a single Security Management Server. The administrator needs to restrict a new junior administrator so that they can only view and modify the Access Control policy for a specific gateway, but cannot install policies or modify other gateways. Which SmartConsole feature should the administrator use to meet this requirement?

Medium
122

An administrator is configuring a VPN community in SmartConsole for a set of gateways that will use IKEv2. The administrator wants to ensure that the VPN tunnel can be established even if the two gateways are behind NAT devices. Which setting should be enabled in the VPN community?

Medium
123

What is the primary benefit of using 'Identity Sharing' between multiple Check Point Security Gateways?

Medium
124

What is the purpose of the 'VPN Domain' object when configuring a gateway for a remote access VPN?

Medium
125

A security administrator is configuring a NAT rule to hide internal users behind the gateway's external IP when accessing the Internet. The administrator wants to ensure that return traffic is correctly routed back to the internal users. Which configuration setting is essential for this to work?

Medium
126

A security administrator is troubleshooting a performance issue on a Check Point R81 Security Gateway. The administrator suspects that a specific process is generating an excessive number of logs, causing high CPU usage. Which SmartConsole tool should the administrator use to view real-time, per-process resource consumption on the gateway?

Medium
127

A remote access user connects to a Check Point Security Gateway using the Mobile Access blade. The user needs to access internal resources, but the connection fails. The administrator checks the gateway and sees that the user authenticated successfully, but no IP address was assigned. Which component is responsible for assigning IP addresses to remote access users in this scenario?

Easy
128

An administrator wants to receive immediate notification when a critical security event, such as a malware infection, is detected by a Security Gateway. Which Check Point feature should the administrator configure to send an alert?

Easy
129

A security administrator is using Identity Awareness with Identity Agents in 'Browser-Based' mode. Users report they are prompted for authentication twice. What is the most likely cause?

Hard
130

What is the primary function of the Encryption Domain in a Check Point VPN environment?

Medium
131

If an administrator needs to identify the source of a connection drop in the logs, which field is most useful to inspect first?

Medium
132

Which of the following describes the 'VPN Community' object in SmartConsole?

Easy
133

An administrator is configuring a Site-to-Site VPN between two Check Point gateways. What is the primary purpose of the Phase 1 IKE negotiation in this tunnel setup?

Medium
134

An administrator wants to ensure that users are warned before accessing a potentially high-risk website. Which feature should be used?

Medium
135

A Check Point administrator is configuring a Route-Based VPN between two R81 gateways. The administrator wants to ensure that the VPN tunnel is established only when there is traffic that needs to be encrypted, and that the tunnel is torn down after a period of inactivity to conserve resources. Which Check Point feature should be configured to achieve this?

Hard
136

A security administrator is troubleshooting a NAT configuration on a Check Point Security Gateway. Internal users cannot reach an external web server through a manual Hide NAT rule, although the Security Policy allows the traffic. The administrator suspects that the NAT rule is not being applied. Which two actions should the administrator take to verify that NAT translation is occurring as expected? (Choose two.)

Hard
137

An administrator wants to audit all changes made to the security policy by other administrators. Which tool should they use?

Hard
138

Refer to the exhibit. A site-to-site VPN tunnel fails to initialize. What is the most likely cause of this error?

Medium
139

Which THREE of the following are valid methods or configurations associated with NAT in Check Point?

Medium
140

A security administrator has configured Identity Awareness with AD Query on a Check Point R81.20 Security Gateway. Users report that they can access resources immediately after logging in, but after a password change, some users are still identified with their old group memberships for an extended period. What is the most likely cause of this behavior?

Hard
141

During an emergency maintenance window, an administrator accidentally publishes a severely corrupted Access Control policy from SmartConsole, causing widespread connectivity outages. The administrator needs to immediately revert the management database to the exact state it was in before this faulty session was published. Which built-in mechanism provides the fastest resolution?

Hard
142

Refer to the exhibit. What is the most likely reason this traffic was dropped?

Hard
143

Which of the following is a recommended best practice when using Identity Awareness for internal network security?

Medium
144

Which of the following is the primary purpose of the Identity Awareness 'Captive Portal' feature?

Easy
145

An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)

Medium
146

An administrator attempts to add a new user to the Management Server and receives an error indicating the object name is already in use. What is the most likely cause?

Medium
147

What is the primary function of the 'Application Wiki' (AppWiki) in Check Point?

Easy
148

Refer to the exhibit. An administrator is configuring RADIUS authentication for Identity Awareness. What is the cause of this error log?

Hard
149

What is the primary function of the 'Permissions Profile' in Check Point SmartConsole?

Easy
150

An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway using the Identity Collector. The administrator wants to ensure that the Identity Collector can retrieve user identity information from Active Directory. Which two components are required for the Identity Collector to function? (Choose two.)

Medium
151

An administrator has successfully established SIC between a Security Management Server and a Security Gateway. The administrator now needs to verify that SIC is working properly. Which SmartConsole status indicates that SIC is fully established and the gateway is trusted?

Easy
152

What is the primary function of the 'SmartEvent' blade in the context of logging?

Easy
153

Refer to the exhibit. An administrator is troubleshooting an issue where 'bob' is unable to access resources. Based on the CLI output, what is the most likely cause for the connectivity failure?

Medium
154

A security administrator has just installed a new R81 Security Gateway. In SmartConsole, the gateway object shows SIC status 'Not Communicating'. The administrator has already initialized SIC on the gateway using 'cpconfig' and entered the activation key. What is the next step required in SmartConsole to complete SIC establishment?

Medium
155

When would an administrator use a 'Custom Application' instead of a standard application in the Application Control blade?

Hard
156

An administrator is troubleshooting a Site-to-Site VPN between two Check Point R81 gateways. The VPN tunnel is up, but traffic is not passing through it. The administrator suspects that the encryption domains are misconfigured. Which SmartConsole tool should the administrator use to verify the encryption domains of the gateways?

Medium
157

An administrator needs to restrict access to social media applications while allowing access to specific professional features. Which feature in the Application Control blade provides this granularity?

Medium
158

A Security Gateway stops sending logs to the Management Server, and users report that SmartView Logs shows no new entries. The administrator confirms the gateway is passing traffic. Which action should be taken first to diagnose the log transmission problem?

Medium
159

Which component in a Check Point VPN community defines the specific subnets that are permitted to send and receive traffic through the VPN tunnel?

Medium
160

An administrator needs to ensure that employees cannot access known malicious websites. The company uses Check Point URL Filtering with ThreatCloud. Which action should the administrator take to block access to these sites?

Easy
161

A remote branch office requires a persistent VPN connection to the corporate headquarters. Which feature should be configured to ensure the tunnel remains active even when no user traffic is flowing?

Medium
162

Which protocol is primarily used by Check Point gateways to encapsulate IPsec traffic when NAT traversal is required for a VPN tunnel?

Easy
163

A Check Point administrator is configuring a new administrator account in SmartConsole. The administrator wants to grant this account permissions to manage only the Security Policies and objects within a specific Domain, while restricting access to other Domains in a Multi-Domain Management environment. The administrator plans to use a Permission Profile that is scoped to that Domain. Which two statements are true regarding this configuration? (Choose two.)

Hard
164

An administrator is troubleshooting why logs from a Security Gateway are not appearing in SmartLog, even though the gateway is configured to send logs to the Management Server and the connection is established. The administrator runs 'cp_log_export' on the Management Server and sees that logs are being exported to an external syslog server successfully. What is the most likely reason for the logs not appearing in SmartLog?

Hard
165

In the context of Check Point VPNs, what is the primary role of the Diffie-Hellman (DH) exchange during IKE negotiation?

Easy
166

An administrator is configuring a new user group in SmartConsole. The group will be used in a rule to allow access to a specific server. The administrator wants to ensure that only users who are members of this group can access the server, and that membership is managed dynamically based on the user's department in the LDAP directory. Which type of user group should the administrator create?

Hard
167

A security administrator has just installed a new R81 Security Gateway and initialized SIC with the Security Management Server. The gateway appears in SmartConsole with SIC status 'Trust established'. However, the administrator notices that the gateway's fingerprint was not verified before initialization. Which action should the administrator take to ensure the gateway's identity is trusted?

Medium
168

A company uses Hide NAT to allow internal users to access the Internet through a single public IP address on the gateway. The security administrator notices that external servers cannot initiate connections to internal hosts, but internal users can reach external services. Which statement explains why external servers cannot initiate connections to internal hosts in this scenario?

Medium
169

An administrator observes that logs are missing from the 'Logs & Monitor' tab, but the 'fw log' command shows logs are being generated on the gateway. What is the most likely cause?

Medium
170

When configuring Access Control policies based on Identity Awareness roles, an administrator places an identity-based rule above a traditional IP-based rule. A user authenticated via Identity Awareness attempts to access a blocked server. The rule base evaluates the connection and matches the user against the identity rule. What happens to the connection?

Medium
171

An administrator wants to ensure that all URLs are categorized correctly. Which tool is used to verify the category of a specific URL?

Medium
172

An administrator is configuring NAT on a Check Point R81 Security Gateway. A web server with a private IP address of 10.1.1.10 must be reachable from the Internet at the public IP address 203.0.113.10. The administrator creates a host object for the web server and configures a Static NAT rule. Which translation method should be selected in the NAT rule so that the internal IP address is translated to the public IP address?

Easy
173

An administrator is setting up a Remote Access VPN for employees using Check Point Mobile Access. The administrator wants to ensure that remote users can access internal web applications securely without installing a full VPN client. Which Check Point feature should be configured?

Easy
174

Which object should an administrator use to define an external user group for authentication purposes?

Medium
175

An administrator successfully logs into SmartConsole and modifies several Access Control rules. Another administrator attempts to open SmartConsole to review the threat prevention settings, but receives a warning message indicating that the database is currently locked by the first administrator. What is the standard behavior of SmartConsole regarding concurrent policy editing?

Medium
176

When defining an Encryption Domain for a Check Point Security Gateway, which TWO configuration methods are natively supported within SmartConsole? (Choose TWO)

Medium
177

Refer to the exhibit. An administrator sees the following debug output while troubleshooting a blocked connection. What is the most likely cause for this traffic being dropped?

Hard
178

An administrator is configuring a Site-to-Site VPN between two Check Point R81 Security Gateways using a Star community. The administrator wants to ensure that the VPN tunnel is established and that traffic is encrypted and decrypted correctly. Which two actions must be performed on both gateways to allow the VPN to function properly? (Choose two.)

Hard
179

An administrator is using SmartConsole to manage a Security Gateway. The gateway's SIC status shows 'Communicating', but the administrator cannot install policy; the installation fails with an error about the gateway not being trusted. Which action should the administrator take to resolve this?

Medium
180

Which command is most useful for troubleshooting NAT issues on a Check Point Security Gateway to see the actual translation occurring in real-time?

Medium
181

Which administrative action requires a 'Publish' operation in a Multi-Admin environment?

Easy
182

A security administrator needs to create a rule that matches HTTP traffic based on the specific web application 'LinkedIn' rather than the entire 'Social Networking' category. The administrator has already enabled Application Control and URL Filtering on the Security Gateway. In SmartConsole, which object type should be used in the Source or Destination column of the security rule to match the application directly?

Medium
183

A Check Point administrator is configuring a new SmartConsole administrator account for a security analyst. The analyst must be able to view all objects and rules but must not be able to modify any security policy or object. The administrator assigns the 'Read-Only All' Permission Profile. However, the analyst reports that they can still edit their own personal settings, such as changing their password. Is this expected behavior?

Hard
184

During an investigation, an administrator must find all connections that were dropped by the Security Gateway in the last 24 hours for a specific source IP. Which SmartConsole tool provides the most efficient way to search and filter these logs?

Hard
185

An administrator needs to ensure that traffic from the internal network (10.10.10.0/24) accessing the Internet is translated to the gateway's external interface IP. Which NAT configuration method is required to achieve this while ensuring that the internal IP addresses are never exposed to the Internet?

Medium
186

An administrator notices that the Security Management Server disk is filling rapidly because log files are retained indefinitely. The retention policy must keep logs for 90 days and then remove older records automatically. Where should this be configured?

Easy
187

Refer to the exhibit. Why are users on non-domain machines labeled as 'unknown'?

Hard
188

An administrator is setting up a Remote Access VPN using Check Point Mobile Access. The administrator wants to ensure that remote users can access internal resources using the same IP address throughout their session, even if they disconnect and reconnect. Which Check Point feature should be enabled to achieve this?

Easy
189

Which command is used to clear the user sessions in the Identity Awareness database on a Security Gateway?

Medium
190

Refer to the exhibit. An administrator is troubleshooting a site-to-site VPN connection. Based on the debug log provided, what is the most likely cause of the issue?

Medium
191

What is the purpose of the 'SmartConsole Check Point User Center' integration?

Medium
192

Which security feature is enabled by default in Check Point VPN communities to protect against replay attacks?

Medium
193

An administrator is reviewing the NAT configuration on a Check Point R81 Security Gateway. The gateway has two interfaces: eth1 (internal, 192.168.1.1) and eth2 (external, 203.0.113.1). Internal users need to access the Internet, and the administrator wants to hide their private IP addresses behind the external interface IP. The administrator creates a Hide NAT rule for the internal network object. Which statement correctly describes the outcome of this configuration?

Easy
194

Refer to the exhibit. An administrator sees this error in the logs. What is the most effective way to resolve this for better visibility?

Hard
195

An administrator configures a Site-to-Site VPN between two Check Point R81 gateways using a Star community. IKE Phase 1 completes successfully, but IKE Phase 2 fails with the error 'No proposal chosen'. The administrator has verified that the encryption and hash algorithms match on both gateways. Which action should the administrator take to resolve this issue?

Medium
196

An administrator is configuring Static NAT for a server. Which NAT option should be selected in the object properties to ensure that the server is reachable via a dedicated public IP address, allowing both inbound and outbound traffic?

Medium
197

An administrator wants to ensure that mobile devices are correctly identified. Which method is most appropriate for mobile device identity identification in a Wi-Fi environment?

Medium
198

Refer to the exhibit. An administrator receives this message when trying to publish changes. How can the administrator resolve this conflict?

Hard
199

A security administrator has just initialized a new Security Gateway with the First Time Configuration Wizard. In SmartConsole, the gateway object exists but its SIC status shows 'Not Communicating'. The administrator opens the gateway object and clicks 'Communication' to initialize SIC. Which action must be performed on the gateway itself for the trust to be established?

Easy
200

Refer to the exhibit. An administrator notices that traffic intended for a NAT rule is being dropped because the destination interface is being incorrectly evaluated. Given the current kernel parameter setting, what does this indicate regarding NAT policy processing?

Medium
201

An administrator configures a Site-to-Site VPN between two Check Point R81 Security Gateways using IKEv2. The VPN tunnel establishes successfully, but after several hours, users report that the tunnel is dropping and re-establishing repeatedly. Logs show 'IKEv2 Child SA rekey failed' and 'Received INVALID_KE_PAYLOAD'. Which action should the administrator take to resolve this?

Medium
202

A security administrator is configuring user authentication for the corporate VPN. Employees must authenticate using their Active Directory credentials via LDAP, but the administrator wants to avoid storing user passwords in the Check Point database. Which Check Point object should be used to integrate the AD server for authentication?

Medium
203

An administrator configures Identity Awareness to use AD Query and creates an Access Control rule allowing the 'Sales' identity group to reach a CRM server. Users in Sales are identified, yet some still get blocked. Reviewing logs shows their sessions exist but the group membership is missing. Which configuration should the administrator verify first?

Hard
204

An administrator is configuring a Remote Access VPN on a Check Point R81 Security Gateway using the Endpoint Security VPN client. The administrator wants to ensure that all traffic from remote users, including Internet-bound traffic, is routed through the VPN tunnel and inspected by the gateway's security policies. Which configuration should be enabled in the Remote Access VPN community?

Medium
205

What is the consequence of setting the 'Log Severity' threshold too high on a Security Gateway?

Hard
206

Refer to the exhibit. An administrator is experiencing intermittent connectivity issues for users behind Hide NAT. What might this setting indicate regarding the root cause?

Medium
207

What is the purpose of 'Anti-Replay' in an IPsec VPN?

Medium
208

A security administrator is configuring Identity Awareness with Terminal Server Agent on a Citrix server. Users report that after logging off and logging back in, they are still associated with their previous session, causing policy inconsistencies. What is the most likely cause of this issue?

Medium
209

When adding a new Check Point Cluster member to an existing management environment, which command must be run on the new member to prepare it for SIC establishment?

Medium
210

An administrator wants to ensure that specific logs are always sent to a remote Log Server, even if the primary Log Server becomes unreachable. Which feature should they configure?

Medium

Frequently asked questions

What does the troubleshooting domain cover on the 156-215.81.20 exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 210 troubleshooting questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.