156-215.81.20 SIC and SmartConsole Management Practice Question
When a Management Server is in a high-availability configuration, how does SIC handle communication if the primary management server fails?
⚠ Common exam trap
Candidates often incorrectly assume that a secondary management server requires a complete manual reset of all gateway SIC configurations during a failover event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The gateways automatically connect to the secondary management server.
In a High Availability environment, the secondary management server is configured with the same ICA and identity as the primary. When a failover occurs, the gateways continue to trust the certificates issued by the same ICA. As long as the secondary server is active, it assumes the management role seamlessly, and the gateways maintain their SIC connections without requiring any manual reconfiguration or key reset.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All gateways must be manually re-initialized with the new management IP.
Why it's wrong here
Manual re-initialization is unnecessary in a properly configured HA setup. The secondary management server shares the same identity and certificate authority as the primary. Gateways use the same trust relationship to communicate with the secondary, ensuring high availability of management services without manual intervention or configuration changes.
- ✓
The gateways automatically connect to the secondary management server.
Why this is correct
Since the secondary management server in an HA setup holds the same ICA and credentials, it is a trusted partner for the gateways. The gateways are configured to know about the management HA pair, allowing them to fail over their communication to the active server automatically.
- ✗
The administrator must run 'sic_reset' on all gateways after failover.
Why it's wrong here
Running 'sic_reset' would destroy the existing trust relationship and force a new, manual setup process. This is contrary to the purpose of high availability, which is designed to maintain operational continuity without manual administrative tasks. Resetting SIC would cause unnecessary downtime and significant administrative overhead.
- ✗
SIC is disabled until a manual policy push is performed.
Why it's wrong here
SIC remains active throughout the failover process. The secondary management server is designed to provide immediate control, and it does not wait for a policy push to re-establish its role. The communication channel is active and ready to handle commands as soon as the service is promoted.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.