156-215.81.20 · domain
troubleshooting
Practise Check Point Certified Security Administrator troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about troubleshooting
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All troubleshooting questions (210)
Click any question to see the full explanation, or start a practice session above.
A Check Point administrator is configuring user authentication for a Remote Access VPN. The administrator wants to use certificates for authentication but also requires a second factor. The administrator decides to use SecurID tokens as the second factor. Which authentication method should be configured in the user object to achieve this?
Hard2A security administrator is preparing to establish Secure Internal Communication (SIC) between a Security Management Server and a new Security Gateway. Which two actions are required to successfully initialize SIC? (Choose two.)
Medium3A security administrator at a financial firm needs to block all peer-to-peer file-sharing applications for the entire company, but must allow legitimate business use of instant messaging. The administrator wants the least administrative effort and automatic updates of new application signatures. What should the administrator do?
Medium4An administrator notices that a user is able to access a website categorized as 'Social Networking' even though the URL Filtering policy blocks that category. The administrator confirms the policy is installed and the user's traffic is inspected. What is the most likely cause?
Hard5Which of these is the primary benefit of using manual NAT rules in a large, complex network?
Easy6An administrator notices that Application Control is not identifying a popular cloud-based application even though it is listed in the Application Control database. The gateway is running R81.10 and the database is up to date. What could be the cause?
Hard7A security administrator needs to allow access to a specific website that is categorized as 'Social Networking' while blocking all other social networking sites. The administrator wants to ensure that only that particular URL is allowed. What is the most efficient way to achieve this in the URL Filtering policy?
Easy8What is the primary function of the 'Identity Collector' in a distributed Identity Awareness environment?
Medium9When using LDAP as an external authentication provider for administrators, why must the 'Search Base' be configured correctly?
Hard10Where do you configure 'Automatic NAT' for a specific network host object in SmartConsole?
Easy11Which phase of the IKE negotiation is responsible for authenticating the peers and establishing a secure channel for subsequent management traffic?
Medium12An administrator wants to enforce a policy that blocks access to websites categorized as 'Hacking' but allows access to 'Computer Security' sites. The administrator creates a URL Filtering rule with the action 'Block' for the 'Hacking' category and places it above a rule that allows 'Computer Security'. However, users report that they can still access some hacking-related sites. Upon investigation, the administrator finds that these sites are categorized as 'Computer Security' by the Check Point URL Filtering database. What should the administrator do to ensure these sites are blocked?
Hard13A Security Management Server (SMS) is configured in a High Availability (HA) cluster with a primary and secondary server. The primary server fails, and the secondary takes over. An administrator notices that SIC communication with remote gateways continues without interruption. What is the reason for this seamless SIC continuity?
Hard14Which TWO of the following are consequences of using 'Hide NAT' incorrectly in a network environment?
Medium15Which blade must be active to perform HTTPS Inspection on traffic?
Medium16What is the difference between 'Main Mode' and 'Aggressive Mode' in IKE Phase 1?
Hard17A network administrator is configuring a VPN community that includes a Check Point R81 Security Gateway and a third-party IPsec gateway. The administrator needs to ensure that the VPN tunnel uses specific encryption and hashing algorithms that are supported by both devices. Where should the administrator configure these settings in SmartConsole?
Medium18A security administrator is configuring a new Security Gateway in SmartConsole. The gateway is behind a NAT device and its internal IP address is 10.1.1.1, but it communicates with the Management Server over the internet using a public IP address of 203.0.113.5. The administrator needs to ensure that SIC and policy installation work correctly. What should be configured on the gateway object in SmartConsole?
Medium19A security administrator is troubleshooting a Site-to-Site VPN between two Check Point R81 gateways. The VPN tunnel is up, but traffic from a specific subnet behind Gateway A is not reaching the corresponding subnet behind Gateway B. The administrator has verified that the encryption domains include the correct subnets and that the VPN community is properly configured. Which action should the administrator take next to resolve the issue?
Hard20Refer to the exhibit. The log shows a drop. What does this indicate about the rule base?
Hard21An administrator attempts to establish Secure Internal Communication between a newly installed Security Gateway and the Management Server, but the SIC status repeatedly shows 'Trust Not Established'. The network path is verified and standard TCP port 1849 is fully open. What is the most likely root cause of this failure?
Medium22A Check Point administrator is configuring a Remote Access VPN with Endpoint Security VPN clients. The administrator wants to ensure that all traffic from the remote clients, including Internet-bound traffic, is routed through the Security Gateway for inspection. Which configuration should be enabled in the Remote Access VPN community?
Hard23What is the purpose of the 'Auditor' role in Check Point management?
Medium24A security administrator needs to block access to a specific unknown application that uses HTTP but does not match any signature in the current Application Control database. The administrator wants to ensure the application is blocked immediately without waiting for a database update. What is the most efficient way to achieve this?
Medium25A company wants users on managed Windows endpoints to be identified by Identity Awareness without requiring them to open a browser or wait for an AD event log poll. The endpoints are domain-joined and already managed by the organization. Which acquisition method meets this requirement most directly?
Easy26Which object property must be enabled on a gateway for it to support NAT?
Easy27A Check Point administrator is configuring NAT for a new subnet that will be used for a guest wireless network. The guest subnet is 172.16.50.0/24, and the administrator wants to hide all guest traffic behind the external interface IP 203.0.113.5. The administrator creates a network object for the guest subnet and configures Hide NAT using the external interface. After testing, guests can access the Internet, but the administrator notices that the translation is not being applied to traffic originating from the guest subnet when it is destined to a server on the internal network (192.168.1.0/24). What is the most likely reason for this behavior?
Medium28A security administrator notices that users are accessing a newly registered domain that is not yet categorized by Check Point. The administrator wants to block access to uncategorized sites until they are reviewed. Which URL Filtering action should be configured?
Easy29Which option is recommended to prevent 'VPN tunnel flapping' when a connection is unstable?
Medium30A security administrator needs to send only Security Gateway log records to an external SIEM over syslog, while keeping the Management Server's own audit logs local. Which Check Point configuration should be performed?
Medium31An administrator is setting up a Remote Access VPN using Check Point Mobile Access Blade. The company wants to ensure that remote users can access internal resources using the same IP address throughout their session, and that the IP address is from a specific internal subnet. Which feature should be enabled in the gateway's Remote Access configuration?
Easy32When configuring a VPN Community, what is the impact of selecting 'Maintain persistent tunnels' on the gateway?
Medium33An administrator is configuring a new Security Gateway to communicate with a Security Management Server using SIC. The administrator must ensure the SIC trust is established securely. Which two actions are required to complete SIC initialization? (Choose two.)
Hard34An administrator needs to allow internal users to access the Internet using Hide NAT. The internal network is 192.168.1.0/24, and the gateway's external interface IP is 203.0.113.5. Which NAT rule should be configured?
Easy35A security administrator is configuring a rule in the Application Control policy to block all peer-to-peer file sharing applications. After enabling the rule, users report that they can still use uTorrent to download files. The administrator checks the logs and sees that the uTorrent traffic is being matched by a different rule that allows all allowed applications. What is the most likely cause of this issue?
Medium36A security administrator at a company with a Check Point R81 management server and two clustered Security Gateways is configuring NAT for a web server on the internal network. The server's private IP is 192.168.10.50, and it must be reachable from the Internet at public IP 203.0.113.25. The administrator wants to ensure that return traffic from the server is automatically translated back to the public IP without creating a separate outbound NAT rule. Which NAT method should be configured on the web server object in SmartConsole?
Hard37A security administrator has configured a URL Filtering rule to block the 'Gambling' category. Users report that they can still access some gambling sites. The administrator checks the logs and sees that the traffic is being allowed by a rule that allows 'Any' application and 'Any' URL. The administrator verifies that the block rule is above the allow rule. What is the most likely reason for the issue?
Hard38An administrator wants to ensure that logs are indexed properly for quick searching in SmartView. Which process is responsible for this indexing?
Medium39Refer to the exhibit. An administrator notices that traffic from Internal_Net to Server_Farm is being translated by Rule 1 instead of Rule 2. What is the most likely cause?
Hard40A security administrator at a financial firm wants to allow access to the corporate banking portal at 'secure.bank.com' but block all other online banking sites for a specific user group. The policy already includes a rule that blocks the 'Financial Services' category. How should the administrator configure the policy to meet this requirement?
Medium41A security administrator is deploying Identity Awareness using the Identity Collector in an environment with multiple domain controllers. The administrator wants to ensure that user identity information is collected from all domain controllers and that the load is distributed. Which configuration should be implemented?
Hard42A security administrator is using SmartConsole to manage a Security Gateway. The administrator needs to verify that Secure Internal Communication (SIC) is properly established between the Management Server and the gateway. Which SmartConsole status indicates that SIC is successfully established?
Easy43An administrator is troubleshooting an issue where logs from a Security Gateway are not appearing in SmartLog. The administrator verifies that the gateway is sending logs to the Management Server, but the logs are not indexed. Which service should the administrator check on the Management Server to ensure proper log indexing?
Hard44An administrator is troubleshooting an issue where users are identified as 'Unknown' despite having Identity Awareness enabled. What is the first logical step to investigate?
Hard45A security administrator must let contractors on personally owned, non-domain laptops access internal resources. The contractors cannot install endpoint software, and the organization wants them to authenticate through a web page before access is granted. Which Identity Awareness acquisition method fits these constraints?
Medium46A security policy requires that users are presented with a warning page before accessing sites categorized as 'High Risk'. After the warning, they can choose to proceed. Which URL Filtering action should be configured in the rule?
Easy47A security administrator manages a Check Point R81.20 environment with a Security Gateway and a separate Identity Collector. Users authenticate through Microsoft Active Directory, and the administrator wants to minimize the number of AD queries sent from the gateway. Which configuration should the administrator use to achieve this?
Medium48An administrator needs to review logs from a specific Security Gateway that occurred between 2:00 AM and 4:00 AM yesterday. Which SmartConsole application should the administrator use to efficiently filter and analyze these logs?
Easy49Which object type should an administrator use to block access to a wide range of websites deemed inappropriate, such as adult content?
Medium50What is the primary benefit of the 'ThreatCloud' service for URL Filtering?
Medium51A security administrator notices that users are accessing a gambling website that is not being blocked, even though the 'Gambling' category is set to Block in the URL Filtering policy. The administrator verifies that the policy is installed and the site is indeed categorized as 'Gambling'. What is the most likely reason for this issue?
Hard52A security administrator needs to configure a Security Gateway to send its logs to a third-party SIEM via syslog. The SIEM is reachable only through an external interface, and the administrator wants to avoid sending logs over the internal network. Which Check Point feature should be used to achieve this requirement?
Medium53A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a web server farm. The administrator needs to ensure that external users can access the web servers using a single public IP, and that the web servers can initiate outbound connections to the Internet. The administrator decides to use manual NAT rules. Which two statements are correct regarding the configuration of manual NAT rules in this scenario? (Choose two.)
Hard54Refer to the exhibit. An administrator reports they can see all objects but cannot push policies. Reviewing the configuration, what is the most likely cause of this restriction?
Hard55Why might you use a 'Hide NAT' rule with a specific IP pool instead of a single interface IP?
Hard56Which of the following describes the function of the 'Identity Awareness Gateway' in a load-sharing cluster?
Medium57An administrator needs to reset Secure Internal Communication (SIC) on a remote Security Gateway that is currently showing a status of 'Communication Error' in SmartConsole. Which TWO actions must be performed to successfully re-establish the SIC relationship? (Choose TWO)
Hard58Which TWO of the following are mandatory steps when configuring a new Site-to-Site VPN community?
Medium59A security administrator needs to allow a group of external consultants to access the corporate network via the Remote Access VPN. These consultants are not defined in the internal Active Directory. The administrator wants to minimize administrative overhead and ensure that the consultants can authenticate using their own existing credentials from their home company's LDAP server. Which Check Point object should be used to represent these external consultants?
Medium60An administrator is configuring Application Control and URL Filtering on a new Security Gateway. The administrator wants to ensure that the gateway can identify applications and enforce policy correctly. Which two actions are required to enable Application Control and URL Filtering? (Choose two.)
Medium61An administrator is creating a new user account in the SmartConsole. The user needs to authenticate via a username and password that is stored in the Check Point user database. Which user type should the administrator select?
Easy62Which TWO settings are required when configuring the 'Active Directory Query' method in the Identity Awareness blade?
Medium63Refer to the exhibit. [VPN] Community: HQ-Branch-Star Tunnel type: Permanent Tunnel Status: Down (Reason: No valid SA found) An administrator reviews the VPN status output shown above for a permanent tunnel in a Star community. Despite the permanent tunnel setting, the tunnel remains down. What is the most likely cause of this behavior?
Hard64An administrator is configuring Identity Awareness on a Security Gateway and wants to enable users to authenticate via a web portal before accessing network resources. The administrator wants to minimize user disruption and avoid installing additional software. Which Identity Awareness method should be used?
Easy65An administrator is deploying Identity Awareness on a Check Point R81.20 Security Gateway. Users authenticate to a captive portal hosted by the gateway itself, without any external directory service. Which Identity Awareness method is being used?
Medium66Which IKE Phase 2 proposal setting specifically ensures that session keys are not derived from the original long-term keys, protecting past sessions if a key is compromised?
Medium67Refer to the exhibit. An administrator reviews the Identity Awareness status of a user workstation using CLI commands on the Security Gateway. What does the 'Identity Source: Identity Agent' field specifically indicate about how this user's identity was acquired?
Medium68An administrator needs to restrict a junior admin's access to only managing security policies within a specific Management Server domain. Which feature should be configured to implement this granular control?
Medium69An administrator configures Identity Awareness with Active Directory Query on an R81.20 Security Gateway. Users are authenticated via Kerberos, and the gateway has been joined to the domain. However, after login, some users are not being identified. The administrator notices that the gateway's AD Query service account password has expired. What is the most likely cause of the identification failure?
Medium70A Check Point administrator is deploying a Mesh VPN community with three gateways: GW-A, GW-B, and GW-C. The administrator wants to ensure that traffic between any two gateways is encrypted and that the community automatically creates the necessary tunnels. After configuration, the administrator notices that traffic between GW-A and GW-C is not encrypted, while traffic between GW-A and GW-B is encrypted. What is the most likely reason for this issue?
Hard71What happens when the URL Filtering database is unreachable by the gateway?
Medium72A senior administrator needs to restrict a junior security operator so they can view and edit access control policies, but they must be strictly prohibited from installing policies onto production Security Gateways. Which SmartConsole mechanism should be utilized to enforce this operational boundary?
Medium73An administrator configures Identity Awareness in a Check Point environment using Active Directory Query. Users report that access policies based on user groups fail intermittently for workstations after users lock their screens. Which underlying mechanism causes this authentication loss?
Medium74A security administrator is configuring a Check Point R81 Management Server to authenticate administrators via RADIUS. The RADIUS server is already configured with the necessary user accounts. After creating a RADIUS server object and enabling RADIUS authentication for administrators, the administrator tests login with a RADIUS user but fails. The administrator confirms the RADIUS server is reachable and the shared secret matches. What is the most likely cause of the failure?
Medium75A security administrator has deployed Identity Awareness with Terminal Server Agent on a Check Point R81.20 gateway. Users report that their identities are correctly identified when they log in, but after disconnecting and reconnecting to a different session on the same terminal server, they are still associated with the old session. What is the most likely cause?
Hard76Why is it recommended to use a separate administrative account for policy management versus day-to-day monitoring?
Medium77What is the primary function of the 'Read-Only All' Permission Profile in Check Point?
Medium78Refer to the exhibit. An administrator is troubleshooting Application Control traffic. What does the CLI output verify regarding the traffic flow?
Hard79A security administrator is configuring NAT for a network where internal users need to access external web servers. The administrator wants to hide the internal IP addresses behind a single public IP address. However, some internal users report that they cannot access certain websites that require multiple simultaneous connections from the same source IP. What is the most likely cause of this issue?
Hard80When configuring a NAT rule that involves a VPN community, why is 'Hide NAT' often problematic?
Hard81An administrator needs to block a specific web application that is not recognized by the default Application Control signature database. The application uses a custom protocol on TCP port 8443. What is the most appropriate method to achieve this?
Medium82An administrator has just initialized Secure Internal Communication (SIC) on a new Security Gateway using the one-time password 'CpWk987'. In SmartConsole, the administrator opens the gateway object, goes to the General Properties > Secure Internal Communication section, and enters the same one-time password. After clicking Initialize, the SIC status changes to 'Trust established'. However, the administrator notices that the gateway's SIC status later reverts to 'Unknown' after a few minutes. What is the most likely cause?
Medium83Refer to the exhibit. An administrator is troubleshooting an intermittent SIC authentication failure between the Security Management Server and cluster-gw-01. Based on the CLI output, what does the cpca_client command verify?
Hard84An administrator is configuring Identity Awareness on a Check Point R81.20 gateway using the Identity Collector. Users are authenticated via multiple Active Directory domains in a forest. The administrator notices that users from one domain are not being identified. What is the most likely cause?
Hard85An administrator needs to review all logs generated by a specific Security Gateway over the past week. The administrator wants to see the logs in a tabular format and apply filters based on source IP. Which SmartConsole tool should the administrator use?
Easy86When configuring Check Point internal users for SmartConsole authentication, what is the best practice for password management?
Easy87A security administrator needs to allow a group of contractors to access the corporate network via Remote Access VPN. The contractors are already defined in an external LDAP directory. The administrator wants to avoid creating individual user accounts in SmartConsole and wants to apply a specific set of VPN settings to all contractors. Which object should the administrator use to represent the contractors in the VPN community configuration?
Hard88An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway. The company uses a single Active Directory domain and wants to identify users without installing any software on client machines. Which Identity Awareness method should the administrator choose?
Medium89An administrator needs to verify that a Security Gateway is sending logs to the Management Server. The administrator wants to see a real-time count of log messages received by the management server from each gateway. Which SmartConsole tool provides this information?
Easy90An administrator needs to implement Identity Awareness to control access based on user groups. Which authentication method should be configured to ensure seamless transparency for users already logged into a Windows domain without requiring manual credentials input?
Medium91When a Management Server is in a high-availability configuration, how does SIC handle communication if the primary management server fails?
Medium92A security administrator at a company with 500 employees needs to grant SmartConsole access to a team of 10 auditors. The auditors must be able to view all security policies and logs but must not be able to modify any objects or rules. The administrator wants to avoid creating 10 separate administrator accounts. What is the most efficient way to achieve this?
Medium93An administrator configures Identity Awareness using Active Directory Query to authenticate domain users. After deployment, users report intermittent authentication failures, and logs show that the Security Gateway fails to query the Domain Controllers due to insufficient privileges. Which account permission must be granted to resolve this issue without granting Domain Administrator rights?
Medium94An administrator has just deployed a new R81 Security Gateway and needs to establish Secure Internal Communication (SIC) with the existing Management Server. The administrator runs the command 'cpconfig' on the gateway, selects the option to initialize SIC, and enters the activation key. After completing the wizard, the administrator checks SmartConsole and sees that the gateway's SIC status is still 'Not Communicating'. The administrator verifies that the gateway's IP address is correct, the firewall policy allows traffic on port 257, and the Management Server is reachable. What is the most likely reason for the SIC status not being established?
Medium95An administrator needs to create a new administrator account in SmartConsole with permissions restricted exclusively to monitoring logs and viewing tracking data without any ability to modify rules. Which TWO configuration actions must be performed? (Choose TWO)
Hard96An administrator has configured Identity Awareness with Terminal Server Agent on a Terminal Server. Users report that after disconnecting from a Remote Desktop session and reconnecting, they are sometimes identified as the previous user. What is the most likely cause of this issue?
Hard97A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a DMZ. The DMZ contains a mail server with IP address 10.10.10.5 and a web server with IP address 10.10.10.6. Both servers must be accessible from the Internet using separate public IP addresses. The administrator wants to minimize the number of NAT rules and ensure that the translation is applied correctly. Which NAT configuration approach is most appropriate?
Hard98A security administrator is troubleshooting a Security Gateway that shows SIC status 'Unknown' in SmartConsole. The administrator suspects the gateway's SIC certificate has expired. Which command on the gateway can be used to check the SIC certificate's expiration date and validity?
Medium99A security administrator manages a Check Point R81.20 environment with Identity Awareness using Active Directory Query. Users on domain-joined machines are identified correctly, but users who connect through a NAT device are consistently shown as unknown. What is the most likely cause?
Hard100An administrator has configured a rule to block the 'File Storage and Sharing' category. Users report that they can still access 'Dropbox' via the web interface, but the log shows the connection as allowed. The administrator verifies that the rule is correctly placed and the Application Control blade is enabled. Which action should the administrator take to ensure 'Dropbox' is blocked?
Hard101A Check Point administrator is configuring user authentication for a remote access VPN community. The organization uses an external LDAP directory server for user credentials. The administrator wants to avoid creating local user accounts on the Security Management Server. Which Check Point object should be used to represent the external LDAP users for authentication?
Medium102Your organization requires that all log files be rotated when they reach a specific size limit to ensure efficient disk usage. Where should an administrator configure the automatic log rotation settings in SmartConsole?
Medium103Which action must be performed after updating a Permission Profile to ensure the changes take effect for active sessions?
Medium104What is the function of the 'Internal Certificate Authority' (ICA) in a Check Point environment?
Hard105What is the primary difference between a 'Site-to-Site' VPN and a 'Remote Access' VPN in a Check Point environment?
Easy106An administrator is creating a new user account in SmartConsole. The administrator wants the user to be able to authenticate to the Check Point Mobile Access portal using a username and password stored locally on the Management Server. Which authentication method should be selected for this user?
Easy107An administrator is troubleshooting an Identity Awareness deployment where some users are intermittently shown as unidentified on the Security Gateway. The environment uses AD Query. Which TWO conditions would cause AD Query to fail to identify a logged-in user? (Choose two.)
Hard108An administrator notices that the Security Management Server's disk space is being consumed rapidly by log files. The administrator wants to automatically delete logs older than 90 days to free up space. Which Check Point feature should be configured to achieve this?
Medium109A security administrator is investigating a suspicious connection to an external IP. The administrator needs to see the raw packet-level details captured by the Security Gateway's IPS blade to determine the exact payload that triggered the protection. Which SmartConsole tool should the administrator use to view this information?
Medium110A Check Point administrator needs to configure authentication for a group of external users who will access the network via a VPN. The users are stored in an Active Directory domain. The administrator wants to use the AD credentials for authentication and also wants to assign different permissions based on AD group membership. Which two actions must the administrator take to achieve this? (Choose two.)
Medium111A security analyst is investigating a suspected intrusion and needs to view all logs related to a specific source IP address across multiple Security Gateways. The logs are stored on a central Management Server. Which SmartConsole feature should the analyst use to efficiently search and filter these logs?
Hard112A security administrator is configuring NAT for a new internal server (10.0.0.5) that needs to be accessible from the Internet on port 443 using the public IP 203.0.113.20. The administrator creates a host object for the server and configures a Static NAT rule. Which additional configuration is required to allow inbound HTTPS traffic to reach the server?
Easy113An administrator is configuring NAT for a new web server on the internal network. The server must be accessible from the Internet using a public IP address, and connections must be initiated from the Internet to the server. The internal IP is 10.1.1.10, and the public IP is 203.0.113.10. Which NAT method should be used?
Medium114A security administrator at a company using Check Point R81 Management Server needs to verify that a newly created administrator account named 'jsmith' has been assigned the correct permission profile before the account is used. The administrator opens SmartConsole and navigates to the Manage & Settings view. Which action should the administrator take to view the permission profile assigned to 'jsmith'?
Medium115A security administrator wants to configure the Check Point Management Server to authenticate administrators using an external LDAP directory. The LDAP server is already defined as an object in SmartConsole. Which of the following is the correct next step to enable LDAP authentication for administrators?
Medium116Which tab in SmartConsole allows an administrator to view the status of the Security Management Server and its associated gateways, including CPU and memory usage?
Easy117A company wants to prevent employees from uploading files to cloud storage sites. Which action should the administrator take in the Application Control rule?
Medium118When configuring a VPN Community with 'Office Mode' enabled, what is the primary benefit for remote access clients?
Hard119An administrator is configuring a Remote Access VPN with Endpoint Security VPN clients connecting to a Check Point R81 gateway. The administrator wants to ensure that the VPN clients can access internal resources and that the gateway can apply security policies to the clients based on their user identity. Which two components must be configured to achieve this? (Choose two.)
Hard120When configuring an administrator with 'Read/Write' access in a specific domain, what does 'Scope' define?
Hard121An administrator manages multiple Security Gateways using a single Security Management Server. The administrator needs to restrict a new junior administrator so that they can only view and modify the Access Control policy for a specific gateway, but cannot install policies or modify other gateways. Which SmartConsole feature should the administrator use to meet this requirement?
Medium122An administrator is configuring a VPN community in SmartConsole for a set of gateways that will use IKEv2. The administrator wants to ensure that the VPN tunnel can be established even if the two gateways are behind NAT devices. Which setting should be enabled in the VPN community?
Medium123What is the primary benefit of using 'Identity Sharing' between multiple Check Point Security Gateways?
Medium124What is the purpose of the 'VPN Domain' object when configuring a gateway for a remote access VPN?
Medium125A security administrator is configuring a NAT rule to hide internal users behind the gateway's external IP when accessing the Internet. The administrator wants to ensure that return traffic is correctly routed back to the internal users. Which configuration setting is essential for this to work?
Medium126A security administrator is troubleshooting a performance issue on a Check Point R81 Security Gateway. The administrator suspects that a specific process is generating an excessive number of logs, causing high CPU usage. Which SmartConsole tool should the administrator use to view real-time, per-process resource consumption on the gateway?
Medium127A remote access user connects to a Check Point Security Gateway using the Mobile Access blade. The user needs to access internal resources, but the connection fails. The administrator checks the gateway and sees that the user authenticated successfully, but no IP address was assigned. Which component is responsible for assigning IP addresses to remote access users in this scenario?
Easy128An administrator wants to receive immediate notification when a critical security event, such as a malware infection, is detected by a Security Gateway. Which Check Point feature should the administrator configure to send an alert?
Easy129A security administrator is using Identity Awareness with Identity Agents in 'Browser-Based' mode. Users report they are prompted for authentication twice. What is the most likely cause?
Hard130What is the primary function of the Encryption Domain in a Check Point VPN environment?
Medium131If an administrator needs to identify the source of a connection drop in the logs, which field is most useful to inspect first?
Medium132Which of the following describes the 'VPN Community' object in SmartConsole?
Easy133An administrator is configuring a Site-to-Site VPN between two Check Point gateways. What is the primary purpose of the Phase 1 IKE negotiation in this tunnel setup?
Medium134An administrator wants to ensure that users are warned before accessing a potentially high-risk website. Which feature should be used?
Medium135A Check Point administrator is configuring a Route-Based VPN between two R81 gateways. The administrator wants to ensure that the VPN tunnel is established only when there is traffic that needs to be encrypted, and that the tunnel is torn down after a period of inactivity to conserve resources. Which Check Point feature should be configured to achieve this?
Hard136A security administrator is troubleshooting a NAT configuration on a Check Point Security Gateway. Internal users cannot reach an external web server through a manual Hide NAT rule, although the Security Policy allows the traffic. The administrator suspects that the NAT rule is not being applied. Which two actions should the administrator take to verify that NAT translation is occurring as expected? (Choose two.)
Hard137An administrator wants to audit all changes made to the security policy by other administrators. Which tool should they use?
Hard138Refer to the exhibit. A site-to-site VPN tunnel fails to initialize. What is the most likely cause of this error?
Medium139Which THREE of the following are valid methods or configurations associated with NAT in Check Point?
Medium140A security administrator has configured Identity Awareness with AD Query on a Check Point R81.20 Security Gateway. Users report that they can access resources immediately after logging in, but after a password change, some users are still identified with their old group memberships for an extended period. What is the most likely cause of this behavior?
Hard141During an emergency maintenance window, an administrator accidentally publishes a severely corrupted Access Control policy from SmartConsole, causing widespread connectivity outages. The administrator needs to immediately revert the management database to the exact state it was in before this faulty session was published. Which built-in mechanism provides the fastest resolution?
Hard142Refer to the exhibit. What is the most likely reason this traffic was dropped?
Hard143Which of the following is a recommended best practice when using Identity Awareness for internal network security?
Medium144Which of the following is the primary purpose of the Identity Awareness 'Captive Portal' feature?
Easy145An administrator is configuring a Security Gateway to send logs to an external SIEM via syslog. They want to ensure that the logs include the action taken and the rule number for each connection. Which TWO of the following log fields must be included in the exported syslog messages to meet this requirement? (Choose two.)
Medium146An administrator attempts to add a new user to the Management Server and receives an error indicating the object name is already in use. What is the most likely cause?
Medium147What is the primary function of the 'Application Wiki' (AppWiki) in Check Point?
Easy148Refer to the exhibit. An administrator is configuring RADIUS authentication for Identity Awareness. What is the cause of this error log?
Hard149What is the primary function of the 'Permissions Profile' in Check Point SmartConsole?
Easy150An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway using the Identity Collector. The administrator wants to ensure that the Identity Collector can retrieve user identity information from Active Directory. Which two components are required for the Identity Collector to function? (Choose two.)
Medium151An administrator has successfully established SIC between a Security Management Server and a Security Gateway. The administrator now needs to verify that SIC is working properly. Which SmartConsole status indicates that SIC is fully established and the gateway is trusted?
Easy152What is the primary function of the 'SmartEvent' blade in the context of logging?
Easy153Refer to the exhibit. An administrator is troubleshooting an issue where 'bob' is unable to access resources. Based on the CLI output, what is the most likely cause for the connectivity failure?
Medium154A security administrator has just installed a new R81 Security Gateway. In SmartConsole, the gateway object shows SIC status 'Not Communicating'. The administrator has already initialized SIC on the gateway using 'cpconfig' and entered the activation key. What is the next step required in SmartConsole to complete SIC establishment?
Medium155When would an administrator use a 'Custom Application' instead of a standard application in the Application Control blade?
Hard156An administrator is troubleshooting a Site-to-Site VPN between two Check Point R81 gateways. The VPN tunnel is up, but traffic is not passing through it. The administrator suspects that the encryption domains are misconfigured. Which SmartConsole tool should the administrator use to verify the encryption domains of the gateways?
Medium157An administrator needs to restrict access to social media applications while allowing access to specific professional features. Which feature in the Application Control blade provides this granularity?
Medium158A Security Gateway stops sending logs to the Management Server, and users report that SmartView Logs shows no new entries. The administrator confirms the gateway is passing traffic. Which action should be taken first to diagnose the log transmission problem?
Medium159Which component in a Check Point VPN community defines the specific subnets that are permitted to send and receive traffic through the VPN tunnel?
Medium160An administrator needs to ensure that employees cannot access known malicious websites. The company uses Check Point URL Filtering with ThreatCloud. Which action should the administrator take to block access to these sites?
Easy161A remote branch office requires a persistent VPN connection to the corporate headquarters. Which feature should be configured to ensure the tunnel remains active even when no user traffic is flowing?
Medium162Which protocol is primarily used by Check Point gateways to encapsulate IPsec traffic when NAT traversal is required for a VPN tunnel?
Easy163A Check Point administrator is configuring a new administrator account in SmartConsole. The administrator wants to grant this account permissions to manage only the Security Policies and objects within a specific Domain, while restricting access to other Domains in a Multi-Domain Management environment. The administrator plans to use a Permission Profile that is scoped to that Domain. Which two statements are true regarding this configuration? (Choose two.)
Hard164An administrator is troubleshooting why logs from a Security Gateway are not appearing in SmartLog, even though the gateway is configured to send logs to the Management Server and the connection is established. The administrator runs 'cp_log_export' on the Management Server and sees that logs are being exported to an external syslog server successfully. What is the most likely reason for the logs not appearing in SmartLog?
Hard165In the context of Check Point VPNs, what is the primary role of the Diffie-Hellman (DH) exchange during IKE negotiation?
Easy166An administrator is configuring a new user group in SmartConsole. The group will be used in a rule to allow access to a specific server. The administrator wants to ensure that only users who are members of this group can access the server, and that membership is managed dynamically based on the user's department in the LDAP directory. Which type of user group should the administrator create?
Hard167A security administrator has just installed a new R81 Security Gateway and initialized SIC with the Security Management Server. The gateway appears in SmartConsole with SIC status 'Trust established'. However, the administrator notices that the gateway's fingerprint was not verified before initialization. Which action should the administrator take to ensure the gateway's identity is trusted?
Medium168A company uses Hide NAT to allow internal users to access the Internet through a single public IP address on the gateway. The security administrator notices that external servers cannot initiate connections to internal hosts, but internal users can reach external services. Which statement explains why external servers cannot initiate connections to internal hosts in this scenario?
Medium169An administrator observes that logs are missing from the 'Logs & Monitor' tab, but the 'fw log' command shows logs are being generated on the gateway. What is the most likely cause?
Medium170When configuring Access Control policies based on Identity Awareness roles, an administrator places an identity-based rule above a traditional IP-based rule. A user authenticated via Identity Awareness attempts to access a blocked server. The rule base evaluates the connection and matches the user against the identity rule. What happens to the connection?
Medium171An administrator wants to ensure that all URLs are categorized correctly. Which tool is used to verify the category of a specific URL?
Medium172An administrator is configuring NAT on a Check Point R81 Security Gateway. A web server with a private IP address of 10.1.1.10 must be reachable from the Internet at the public IP address 203.0.113.10. The administrator creates a host object for the web server and configures a Static NAT rule. Which translation method should be selected in the NAT rule so that the internal IP address is translated to the public IP address?
Easy173An administrator is setting up a Remote Access VPN for employees using Check Point Mobile Access. The administrator wants to ensure that remote users can access internal web applications securely without installing a full VPN client. Which Check Point feature should be configured?
Easy174Which object should an administrator use to define an external user group for authentication purposes?
Medium175An administrator successfully logs into SmartConsole and modifies several Access Control rules. Another administrator attempts to open SmartConsole to review the threat prevention settings, but receives a warning message indicating that the database is currently locked by the first administrator. What is the standard behavior of SmartConsole regarding concurrent policy editing?
Medium176When defining an Encryption Domain for a Check Point Security Gateway, which TWO configuration methods are natively supported within SmartConsole? (Choose TWO)
Medium177Refer to the exhibit. An administrator sees the following debug output while troubleshooting a blocked connection. What is the most likely cause for this traffic being dropped?
Hard178An administrator is configuring a Site-to-Site VPN between two Check Point R81 Security Gateways using a Star community. The administrator wants to ensure that the VPN tunnel is established and that traffic is encrypted and decrypted correctly. Which two actions must be performed on both gateways to allow the VPN to function properly? (Choose two.)
Hard179An administrator is using SmartConsole to manage a Security Gateway. The gateway's SIC status shows 'Communicating', but the administrator cannot install policy; the installation fails with an error about the gateway not being trusted. Which action should the administrator take to resolve this?
Medium180Which command is most useful for troubleshooting NAT issues on a Check Point Security Gateway to see the actual translation occurring in real-time?
Medium181Which administrative action requires a 'Publish' operation in a Multi-Admin environment?
Easy182A security administrator needs to create a rule that matches HTTP traffic based on the specific web application 'LinkedIn' rather than the entire 'Social Networking' category. The administrator has already enabled Application Control and URL Filtering on the Security Gateway. In SmartConsole, which object type should be used in the Source or Destination column of the security rule to match the application directly?
Medium183A Check Point administrator is configuring a new SmartConsole administrator account for a security analyst. The analyst must be able to view all objects and rules but must not be able to modify any security policy or object. The administrator assigns the 'Read-Only All' Permission Profile. However, the analyst reports that they can still edit their own personal settings, such as changing their password. Is this expected behavior?
Hard184During an investigation, an administrator must find all connections that were dropped by the Security Gateway in the last 24 hours for a specific source IP. Which SmartConsole tool provides the most efficient way to search and filter these logs?
Hard185An administrator needs to ensure that traffic from the internal network (10.10.10.0/24) accessing the Internet is translated to the gateway's external interface IP. Which NAT configuration method is required to achieve this while ensuring that the internal IP addresses are never exposed to the Internet?
Medium186An administrator notices that the Security Management Server disk is filling rapidly because log files are retained indefinitely. The retention policy must keep logs for 90 days and then remove older records automatically. Where should this be configured?
Easy187Refer to the exhibit. Why are users on non-domain machines labeled as 'unknown'?
Hard188An administrator is setting up a Remote Access VPN using Check Point Mobile Access. The administrator wants to ensure that remote users can access internal resources using the same IP address throughout their session, even if they disconnect and reconnect. Which Check Point feature should be enabled to achieve this?
Easy189Which command is used to clear the user sessions in the Identity Awareness database on a Security Gateway?
Medium190Refer to the exhibit. An administrator is troubleshooting a site-to-site VPN connection. Based on the debug log provided, what is the most likely cause of the issue?
Medium191What is the purpose of the 'SmartConsole Check Point User Center' integration?
Medium192Which security feature is enabled by default in Check Point VPN communities to protect against replay attacks?
Medium193An administrator is reviewing the NAT configuration on a Check Point R81 Security Gateway. The gateway has two interfaces: eth1 (internal, 192.168.1.1) and eth2 (external, 203.0.113.1). Internal users need to access the Internet, and the administrator wants to hide their private IP addresses behind the external interface IP. The administrator creates a Hide NAT rule for the internal network object. Which statement correctly describes the outcome of this configuration?
Easy194Refer to the exhibit. An administrator sees this error in the logs. What is the most effective way to resolve this for better visibility?
Hard195An administrator configures a Site-to-Site VPN between two Check Point R81 gateways using a Star community. IKE Phase 1 completes successfully, but IKE Phase 2 fails with the error 'No proposal chosen'. The administrator has verified that the encryption and hash algorithms match on both gateways. Which action should the administrator take to resolve this issue?
Medium196An administrator is configuring Static NAT for a server. Which NAT option should be selected in the object properties to ensure that the server is reachable via a dedicated public IP address, allowing both inbound and outbound traffic?
Medium197An administrator wants to ensure that mobile devices are correctly identified. Which method is most appropriate for mobile device identity identification in a Wi-Fi environment?
Medium198Refer to the exhibit. An administrator receives this message when trying to publish changes. How can the administrator resolve this conflict?
Hard199A security administrator has just initialized a new Security Gateway with the First Time Configuration Wizard. In SmartConsole, the gateway object exists but its SIC status shows 'Not Communicating'. The administrator opens the gateway object and clicks 'Communication' to initialize SIC. Which action must be performed on the gateway itself for the trust to be established?
Easy200Refer to the exhibit. An administrator notices that traffic intended for a NAT rule is being dropped because the destination interface is being incorrectly evaluated. Given the current kernel parameter setting, what does this indicate regarding NAT policy processing?
Medium201An administrator configures a Site-to-Site VPN between two Check Point R81 Security Gateways using IKEv2. The VPN tunnel establishes successfully, but after several hours, users report that the tunnel is dropping and re-establishing repeatedly. Logs show 'IKEv2 Child SA rekey failed' and 'Received INVALID_KE_PAYLOAD'. Which action should the administrator take to resolve this?
Medium202A security administrator is configuring user authentication for the corporate VPN. Employees must authenticate using their Active Directory credentials via LDAP, but the administrator wants to avoid storing user passwords in the Check Point database. Which Check Point object should be used to integrate the AD server for authentication?
Medium203An administrator configures Identity Awareness to use AD Query and creates an Access Control rule allowing the 'Sales' identity group to reach a CRM server. Users in Sales are identified, yet some still get blocked. Reviewing logs shows their sessions exist but the group membership is missing. Which configuration should the administrator verify first?
Hard204An administrator is configuring a Remote Access VPN on a Check Point R81 Security Gateway using the Endpoint Security VPN client. The administrator wants to ensure that all traffic from remote users, including Internet-bound traffic, is routed through the VPN tunnel and inspected by the gateway's security policies. Which configuration should be enabled in the Remote Access VPN community?
Medium205What is the consequence of setting the 'Log Severity' threshold too high on a Security Gateway?
Hard206Refer to the exhibit. An administrator is experiencing intermittent connectivity issues for users behind Hide NAT. What might this setting indicate regarding the root cause?
Medium207What is the purpose of 'Anti-Replay' in an IPsec VPN?
Medium208A security administrator is configuring Identity Awareness with Terminal Server Agent on a Citrix server. Users report that after logging off and logging back in, they are still associated with their previous session, causing policy inconsistencies. What is the most likely cause of this issue?
Medium209When adding a new Check Point Cluster member to an existing management environment, which command must be run on the new member to prepare it for SIC establishment?
Medium210An administrator wants to ensure that specific logs are always sent to a remote Log Server, even if the primary Log Server becomes unreachable. Which feature should they configure?
MediumOther domains
All 156-215.81.20 exam domains
Frequently asked questions
- What does the troubleshooting domain cover on the 156-215.81.20 exam?
- troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 210 troubleshooting questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.