CheckPoint 156-315 Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: 156-315
  • Exam Name/Title: Check Point Security Administration NGX II (156-315.1)
  • Certification Provider: CheckPoint
  • Corresponding Certification: CheckPoint Certification
  • Exam Questions: 205
  • Updated On: May 29, 2026
How can you prevent delay-sensitive applications, such as video and voice traffic, from being dropped due to long queues when using a Check Point QoS solution?
Correct Answer: A Vote an answer
You are preparing to configure your VoIP Domain Gatekeeper object. Which two other objects should you have created first?
Correct Answer: B Vote an answer
You are configuring the VoIP Domain object for a Skinny Client Control Protocol (SCCP) environment protected by VPN-1 NGX. Which VoIP Domain object type can you use?
Correct Answer: C Vote an answer
In a distributed VPN-1 Pro NGX environment, where is the Internal Certificate Authority (ICA) installed?
Correct Answer: C Vote an answer
You configure a Check Point QoS Rule Base with two rules: an HTTP rule with a weight of
40, and the Default Rule with a weight of 10. If the only traffic passing through your QoS Module is HTTP traffic, what percent of bandwidth will be allocated to the HTTP traffic?
Correct Answer: B Vote an answer
You want to block corporate-internal-net and localnet from accessing Web sites containing inappropriate content. You are using WebTrends for URL filtering. You have disabled VPN-
1 Control connections in the Global properties. Review the diagram and the Security Policies for GW_A and GW_B in the exhibit provided.
Corporate users and localnet users receive message "Web cannot be displayed". In SmartView Tracker, you see the connections are dropped with message "content security is not reachable". What is the problem, and how do you fix it?
Correct Answer: D Vote an answer
What is the command to upgrade a SecurePlatform NG with Application Intelligence (AI) R55 SmartCenter Server to VPN-1 NGX using a CD?
Correct Answer: D Vote an answer
You want to upgrade a cluster with two members to VPN-1 NGX. The SmartCenter Server and both members are version VPN-1/FireWall-1 NG FP3, with the latest Hotfix. What is the correct upgrade procedure?
1. Change the version, in the General Properties of the gateway-cluster object.
2. Upgrade the SmartCenter Server, and reboot after upgrade.
3. Run cpstop on one member, while leaving the other member running. Upgrade one member at a time, and reboot after upgrade.
4. Reinstall the Security Policy.
Correct Answer: E Vote an answer
The following is cphaprob state command output from a New Mode High Availability cluster member:Which machine has the highest priority?
Correct Answer: C Vote an answer
Your company has two headquarters, one in London, one in New York. Each headquarters includes several branch offices. The branch offices only need to communicate with the headquarters in their country, not with each other, and only the headquarters need to communicate directly. What is the BEST configuration for VPN Communities among the branch offices and their headquarters, and between the two headquarters? VPN Communities comprised of:
Correct Answer: D Vote an answer
You must set up SIP with a proxy for your network. IP phones are in the 172.16.100.0 network. The Registrar and proxy are installed on host 172.16.100.100. To allow handover enforcement for outbound calls from SIP-net to network Net_B on the Internet, you have defined the following objects:
Network object: SIP-net: 172.16.100.0/24
SIP-gateway: 172.16.100.100
VoIP Domain object: VoIP_domain_A
1.End-point domain: SIP-net
2.VoIP gateway installed at: SIP-gateway host object
How would you configure the rule?
Correct Answer: A Vote an answer
How would you configure a rule in a Security Policy to allow SIP traffic from end point Net_A to end point Net_B, through an NGX Security Gateway?
Correct Answer: C Vote an answer
0
0
0
10