Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Checkpoint 156-590 Dumps Questions Answers

Page: 1 / 6
Total 75 questions

Check Point Certified Threat Prevention Specialist (CTPS) Questions and Answers

Question 1

What Threat Prevention signature updates you can trigger manually?

Options:

A.

Non everything is updated automatically.

B.

Only IPS.

C.

IPS and antivirus.

D.

IPS, Antivirus and Antibot.

Buy Now
Question 2

What is necessary to activate the exception to all Security Gateways?

Options:

A.

Install Database is sufficient.

B.

You have to re-install the Threat Prevention policy.

C.

You have to re-install the Access Control policy.

D.

The changes will be applied immediately, so no need to do anything.

Question 3

What is the purpose of the Profile Cleanup option?

Options:

A.

It lets you start over by removing all administrator overrides.

B.

It merges protection settings from multiple profiles into the Optimized Profile.

C.

It serves as a cleanup policy if none of the protection matches the packets.

D.

It eliminates protections automatically which hasn't been used for a predefined amount of time.

Question 4

Which is NOT an available setting under Custom Policy Tools?

Options:

A.

IPS Protections

B.

UserCheck

C.

Indicators

D.

Malicious Activity Detection

Question 5

What are the three IPS update options?

Options:

A.

Auto Update, Policy Update, Update Now

B.

Update Now, Schedule Update, Follow Protections

C.

Update Now, Schedule Update, Follow policy

D.

Manual Update, Scheduled Update, Auto Update

Question 6

Which statement is true concerning the Custom Policy Tools?

Options:

A.

Block List files - Configure disallowed files.

B.

Allow List Files - Configure allowed files.

C.

Indicators - Configure indicators for benign activity.

D.

Profiles - Edit profiles which are only available for Autonomous Threat Prevention.

Question 7

Which of the following protocols can be scanned by Anti-Virus?

Options:

A.

RemoteDesktop

B.

SNMP

C.

CIFS

D.

Telnet

Question 8

IPS stands for?

Options:

A.

Invasion Prevention Software

B.

Intrusion Prevention System

C.

Intrusion Prevention Software

D.

Invasion Prevention System

Question 9

That Tracking option can be used to capture additional data for analysis by Check Point TAC?

Options:

A.

Alert

B.

Forensics

C.

SNMP

D.

User Defined

Question 10

Which protection setting is generally the LEAST resource intensive?

Options:

A.

Prevent

B.

Inspect

C.

Detect

D.

Inactive

Question 11

What is the name of the default Threat Prevention Profile?

Options:

A.

Basic

B.

Standard

C.

Strict

D.

Optimized

Question 12

What happens to traffic that matches the Access Control Policy but not the Threat Prevention Policy?

Options:

A.

It is dropped and logged.

B.

It is accepted and logged.

C.

It is accepted.

D.

The traffic is not dropped. It is simply not inspected by the Threat Prevention Engine.

Question 13

Which mode allows you to tune or troubleshoot the Threat Prevention Blade?

Options:

A.

Observe Mode

B.

Detect Mode

C.

Display Mode

D.

Watch Mode

Question 14

What are examples of evidence of compromises from inside network in conjunction with Bot-infected systems?

Options:

A.

Users surfing the website directly by IP address or using domains registered within the last 30 days.

B.

Trying to access web resources using explicit proxy servers instead of transparent ones.

C.

Repetitive access to the same specific Intranet web servers within business hours.

D.

Trying to access a web server via HTTP instead of HTTPS.

Question 15

Which feature can improve performance by allowing the gateway to bypass Anti-Virus inspection of specific files?

Options:

A.

Content Control

B.

Exclusions

C.

Exceptions

D.

Bypass

Question 16

How can the IPS Blade be activated?

Options:

A.

The IPS Blade must be activated on the Management Server object and can be used on every gateway managed by this Management server.

B.

No need to activate the IPS Blade as far as you have installed the correct IPS license on the gateways.

C.

In a ClusterXL deployment, the IPS Blade must be activated on the individual cluster nodes.

D.

The IPS Blade must be activated on the individual Security Gateway object.

Question 17

What action is taken by Threat Prevention for traffic that does not match any Threat Prevention rules?

Options:

A.

Reject

B.

Drop

C.

Accept

D.

Detect

Question 18

Who owns and maintains the CVE program and database?

Options:

A.

Check Point

B.

US Department of Homeland Security (DHS)

C.

MITRE Corporation

D.

National Institute of Standards and Technology (NIST)

Question 19

What is the recommended setting for Anti-Virus and why?

Options:

A.

Background because it is Post-infection

B.

Hold because it is Pre-infection and inspects a limited subset of traffic

C.

Hold because it inspects a limited subset of traffic

D.

Background because it inspects a large subset of traffic

Question 20

What is the maximum number of patterns/observables are supported in R81.20 IOC Files?

Options:

A.

Unlimited

B.

1 Million

C.

Limited by available memory

D.

2 Million

Question 21

What is true concerning the Threat Prevention Policy?

Options:

A.

Multiple Threat Prevention Policies can be assigned to one Security Gateway.

B.

The Threat Prevention Policy can override an Access Control Policy Drop or Reject.

C.

In a case of a conflict, the Threat Prevention Policy takes precedence over an Access Control Policy.

D.

The Threat Prevention Policy is only applied after traffic is accepted by Access Control Policy.

Question 22

What are the logical components of a SNORT rule?

Options:

A.

Rule Header / rule body

B.

Rule Header and Rule Options

C.

Rule start / rule stop

D.

Rule start / rule options

Page: 1 / 6
Total 75 questions