Exam Details

  • Exam Code
    :156-915.65
  • Exam Name
    :Accelerated CCSE NGX R65
  • Certification
    :CheckPoint Certification
  • Vendor
    :CheckPoint
  • Total Questions
    :204 Q&As
  • Last Updated
    :Mar 10, 2025

CheckPoint CheckPoint Certification 156-915.65 Questions & Answers

  • Question 51:

    You are establishing a ClusterXL environment, with the following topology: VIP internal cluster IP =

    172.16.10.3; VIP external cluster IP = 192.168.10.3 ClusterMember1:4NICs,3enabled: hme():

    192.168.10.1/24, hmel: 10.10.10.1/24, qfe2:

    172.16.10.1/24 Cluster Member 2: 5 NICs, 3 enabled; hme3: 192.168.10.2/24, hmel:

    10.10.10.2/24, hme2: 172.16.10.2/24 External interfaces 192.168.10.1 and 192.168.10.2 connect to a

    VLAN switch. The upstream router connects to the same VLAN switch. Internal interfaces 172.16.10.1 and

    172.16.10.2 connect to a hub. 10.10.10.0 is the synchronization network. The SmartCenter Server is located on the internal network with IP 172.16.10.3. What is the problem with this configuration?

    A. There is an IP address conflict.

    B. Cluster members cannot use the VLAN switch. They must use hubs.

    C. The Cluster interface names must be identical across all cluster members.

    D. The SmartCenter Server must be in the dedicated synchronization network, not the internal network.

  • Question 52:

    When synchronizing clusters, which of the following statements is NOT true?

    A. User Authentication connections will be lost by the cluster.

    B. Only cluster members running on the same OS platform can be synchronized.

    C. In the case of a failover, accounting information on the failed member may be lost despite a properly working synchronization

    D. An SMTP resource connection using CVP will be maintained by the cluster.

  • Question 53:

    Which of the following is TRUE concerning unnumbered VPN Tunnel Interfaces (VTIs)?

    A. VTIs cannot be assigned a proxy interface

    B. Local IP addresses are not configured, remote IP addresses are configured

    C. VTIs are only supported on SecurePlatform

    D. VTI specific additional local and remote IP addresses are not configured

  • Question 54:

    Which of the following commands is a CLI command for VPN-1 NGX R65?

    A. fw shutdown

    B. fwprint

    C. fw tab -u

    D. fw merge

  • Question 55:

    Which of the following statements about the Port Scanning feature of SmartDefense is TRUE?

    A. When a port scan is detected, only a log is issued ?never an alert.

    B. The Port Scanning feature actively blocks the scanning, and sends an alert to SmartView Monitor.

    C. A typical scan detection is when more than 500 open inactive ports are open for a period of 120 seconds.

    D. Port Scanning does not block scanning, it detects port scans with one of three levels of detection sensitivity

  • Question 56:

    Match the ClusterXL Modes with their configurations

    A. A2.B3.C4.D 1

    B. A2.B3.C 1.D4

    C. A3,B2,C4,D 1

    D. A3.B2.C 1.D4

  • Question 57:

    You are preparing computers for a new ClusterXL deployment. For your cluster, you plan to use four

    machines with the following configurations: Cluster Member 1: OS:

    SecurePlatform, NICs: QuadCard, memory: 512 MB, Security Gateway only, and version:

    VPN-1 NGX R65

    Cluster Member 2: OS: SecurePlatform, NICs: 4 Intel 3Com, memory: 512 MB, Security Gateway only, and

    version: VPN-1 NGX R65 Cluster Member 3: OS: SecurePlatform, NICs: 4 other manufacturers, memory:

    256 MB, Security Gateway only, and version: VPN- 1 NGX R65 SmartCenter Server: MS Windows 2000,

    NIC: Intel NIC (1), Security Gateway and primary SmartCenter Server installed, version: VPN-1 NGX R65

    Are these machines correctly configured for a ClusterXL deployment?

    A. No, Cluster Member 3 does not have the required memory.

    B. NO, the Security Gateway cannot be installed on the SmartCenter Pro Server.

    C. Yes, these machines are configured correctly for a ClusterXL deployment.

    D. NO, the SmartCenter Pro Server is not running the same operating system as the cluster members.

  • Question 58:

    An NGXR65 HA cluster contains two members with external interfaces 172.28.108.1 and 172.28.108.2. The internal interfaces are 10.4.8.1 and 10.4.8.2. The external cluster VIP address is 172.28.108.3 and the internal cluster VIP address is 10.4.8.3. The synchronization interfaces are 192.168.1.1 and 192.168.1.2. The Security Administrator discovers State Synchronization is not working properly. The cphaprob if command output displays shows:What is causing the State Synchronization problem?

    A. The synchronization network has been defined as "Network Objective: Cluster + 1st sync" with an IP address 192.168.1.3 defined in the NGX cluster object's topology. This configuration is supported in NGX and therefore the above screenshot is not relevant to the sync problem.

    B. The synchronization interface on the individual NGX cluster member object's Topology tab is enabled with "Cluster Interface". Disable this setting.

    C. The synchronization network has a cluster VIP address (192.168.1.3) defined in the NGX cluster object's topology. Remove the 192.168.1.3 VIP interface from the cluster topology.

    D. Another cluster is using 192.168.1.3 as one of the unprotected interfaces.

  • Question 59:

    Central License management allows a Security Administrator to perform which of the following functions? (1)Check for expired licenses.

    (2)Sort licenses and view license properties.

    (3)Attach both NGX Central and Local licenses to a remote module.

    (4)Delete both NGX Local licenses and Central licenses from a remote module.

    (5)Add or remove a license to or from the license repository.

    (6)Attach

    and/or delete only NGX Central licenses to a remote module (not Local licenses).

    A.

    1,2,3,4,and5

    B.

    1.2.5.and6

    C.

    2,3,4,and5

    D.

    2,5,and6

  • Question 60:

    If you are experiencing LDAP issues, which of the following should you check?

    A. Connectivity between the NGX gateway and LDAP server

    B. Secure Internal Communications (SIC)

    C. VPN Load Balancing

    D. Overlapping VPN Domains

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-915.65 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.