CheckPoint 156-315-81 practice test

Check Point Certified Security Expert - R81.20

Last exam update: Nov 18 ,2025
Page 1 out of 42. Viewing questions 1-15 out of 628

Question 1

Identify the API that is not supported by Check Point currently.

  • A. R81 Management API-
  • B. Identity Awareness Web Services API
  • C. Open REST API
  • D. OPSEC SDK
Mark Question:
Answer:

C


Explanation:
Check Point currently supports four types of APIs: R81 Management API, Identity Awareness Web
Services API, OPSEC SDK, and Gaia REST API. The Open REST API is not a valid
option. Reference:
Check Point APIs

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

SandBlast Mobile identifies threats in mobile devices by using on-device, network, and cloud-based
algorithms and has four dedicated components that constantly work together to protect mobile
devices and their dat
a. Which component is NOT part of the SandBlast Mobile solution?

  • A. Management Dashboard
  • B. Gateway
  • C. Personal User Storage
  • D. Behavior Risk Engine
Mark Question:
Answer:

C


Explanation:
SandBlast Mobile has four components: Management Dashboard, Gateway, Behavior Risk Engine,
and On-Device Network Protection. Personal User Storage is not part of the SandBlast Mobile
solution. Reference:
SandBlast Mobile Architecture

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

What are the different command sources that allow you to communicate with the API server?

  • A. SmartView Monitor, API_cli Tool, Gaia CLI, Web Services
  • B. SmartConsole GUI Console, mgmt_cli Tool, Gaia CLI, Web Services
  • C. SmartConsole GUI Console, API_cli Tool, Gaia CLI, Web Services
  • D. API_cli Tool, Gaia CLI, Web Services
Mark Question:
Answer:

B


Explanation:
You can communicate with the API server using three command sources: SmartConsole GUI
Console, mgmt_cli Tool, and Gaia CLI. Web Services are not a command source, but a way to access
the API server using HTTP requests. Reference:
Check Point Management APIs

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

What makes Anti-Bot unique compared to other Threat Prevention mechanisms, such as URL
Filtering, Anti-Virus, IPS, and Threat Emulation?

  • A. Anti-Bot is the only countermeasure against unknown malware
  • B. Anti-Bot is the only protection mechanism which starts a counter-attack against known Command & Control Centers
  • C. Anti-Bot is the only signature-based method of malware protection.
  • D. Anti-Bot is a post-infection malware protection to prevent a host from establishing a connection to a Command & Control Center.
Mark Question:
Answer:

D


Explanation:
Anti-Bot is a post-infection malware protection that detects and blocks botnet communications from
infected hosts to Command & Control servers. It is different from other Threat Prevention
mechanisms that prevent malware from entering the network or executing on the
hosts. Reference:
Anti-Bot Software Blade

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

Which TCP-port does CPM process listen to?

  • A. 18191
  • B. 18190
  • C. 8983
  • D. 19009
Mark Question:
Answer:

D


Explanation:
The CPM process is the core process of the Security Management Server that handles all
management operations. It listens to TCP-port 19009 by default. Reference:
CPM process

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

Which method below is NOT one of the ways to communicate using the Management API’s?

  • A. Typing API commands using the “mgmt_cli” command
  • B. Typing API commands from a dialog box inside the SmartConsole GUI application
  • C. Typing API commands using Gaia’s secure shell(clish)19+
  • D. Sending API commands over an http connection using web-services
Mark Question:
Answer:

D


Explanation:
The Management API supports three methods of communication: mgmt_cli command,
SmartConsole GUI dialog box, and Gaia CLI. Sending API commands over an http connection using
web-services is not a supported method. Reference:
Check Point Management APIs

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

Your manager asked you to check the status of SecureXL, and its enabled templates and features.
What command will you use to provide such information to manager?

  • A. fw accel stat
  • B. fwaccel stat
  • C. fw acces stats
  • D. fwaccel stats
Mark Question:
Answer:

B


Explanation:
The fwaccel stat command displays the status of SecureXL, and its enabled templates and features.
The other commands are either incorrect or incomplete. Reference: [SecureXL Commands]

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

SSL Network Extender (SNX) is a thin SSL VPN on-demand client that is installed on the remote user’s
machine via the web browser. What are the two modes of SNX?

  • A. Application and Client Service
  • B. Network and Application
  • C. Network and Layers
  • D. Virtual Adapter and Mobile App
Mark Question:
Answer:

B


Explanation:
SSL Network Extender (SNX) has two modes of operation: Network Mode and Application Mode.
Network Mode provides full network connectivity to the remote user, while Application Mode
provides access to specific applications on the corporate network. Reference: [SSL Network Extender]

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

Which command would disable a Cluster Member permanently?

  • A. clusterXL_admin down
  • B. cphaprob_admin down
  • C. clusterXL_admin down-p
  • D. set clusterXL down-p
Mark Question:
Answer:

C


Explanation:
The clusterXL_admin down -p command disables a Cluster Member permanently, meaning that it
will not rejoin the cluster even after a reboot. The other commands either disable a Cluster Member
temporarily or are invalid. Reference: [ClusterXL Administration Guide]

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

Which two of these Check Point Protocols are used by SmartEvent Processes?

  • A. ELA and CPD
  • B. FWD and LEA
  • C. FWD and CPLOG
  • D. ELA and CPLOG
Mark Question:
Answer:

D


Explanation:
SmartEvent Processes use two Check Point Protocols: ELA (Event Log Agent) and CPLOG (Check Point
Log). ELA collects logs from Security Gateways and forwards them to the Log Server. CPLOG is used
by the Log Server to communicate with the SmartEvent Server. Reference: [SmartEvent Architecture]

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

Fill in the blank: The tool _____ generates a R81 Security Gateway configuration report.

  • A. infoCP
  • B. infoview
  • C. cpinfo
  • D. fw cpinfo
Mark Question:
Answer:

C


Explanation:
The cpinfo tool generates a R81 Security Gateway configuration report that includes information
about the hardware, operating system, product version, patches, and configuration
settings. Reference:
cpinfo - Check Point Support Center

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

Which of these statements describes the Check Point ThreatCloud?

  • A. Blocks or limits usage of web applications
  • B. Prevents or controls access to web sites based on category
  • C. Prevents Cloud vulnerability exploits
  • D. A worldwide collaborative security network
Mark Question:
Answer:

D


Explanation:
The Check Point ThreatCloud is a worldwide collaborative security network that collects and analyzes
threat data from millions of sensors, security gateways, and other sources, and delivers real-time
threat intelligence and protection to Check Point products. Reference:
Check Point ThreatCloud

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

Automatic affinity means that if SecureXL is running, the affinity for each interface is automatically
reset every

  • A. 15 sec
  • B. 60 sec
  • C. 5 sec
  • D. 30 sec
Mark Question:
Answer:

B


Explanation:
Automatic affinity means that if SecureXL is running, the affinity for each interface is automatically
reset every 60 seconds based on the current traffic load. This ensures optimal performance and load
balancing of SecureXL instances. Reference:
SecureXL Mechanism

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

Which command will allow you to see the interface status?

  • A. cphaprob interface
  • B. cphaprob –I interface
  • C. cphaprob –a if
  • D. cphaprob stat
Mark Question:
Answer:

C


Explanation:
The cphaprob -a if command displays the interface status of all cluster members, including the
interface name, IP address, state, monitor mode, and sync status. Reference:
cphaprob - Check Point
Support Center

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

Which command can you use to enable or disable multi-queue per interface?

  • A. cpmq set
  • B. Cpmqueue set
  • C. Cpmq config
  • D. St cpmq enable
Mark Question:
Answer:

A


Explanation:
The cpmq set command enables or disables multi-queue per interface. Multi-queue is a feature that
allows distributing the network traffic among several CPU cores, improving the throughput and
performance of the Security Gateway. Reference:
Multi-Queue

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2