Want to pass your Check Point Certified Security Administrator 156-215.75 exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
A Web server behind the Security Gateway is set to Automatic Static NAT. Client side NAT is enabled in the Global Properties. A client on the Internet initiates a session to the Web Server. On the initiating packet, NAT occurs on which inspection point?
A. I
B. O
C. o
D. i
You just installed a new Web server in the DMZ that must be reachable from the Internet. You create a manual Static NAT rule as follows:
"web_public_IP" is the node object that represents the public IP address of the new Web server. "web_private_IP" is the node object that represents the new Web site's private IP address. You enable all settings from Global Properties > NAT.
When you try to browse the Web server from the Internet you see the error "page cannot be displayed". Which of the following is NOT a possible reason?
A. There is no NAT rule translating the source IP address of packets coming from the protected Web server.
B. There is no route defined on the Security Gateway for the public IP address to the private IP address of the Web server.
C. There is no ARP table entry for the public IP address of the protected Web server.
D. There is no Security Policy defined that allows HTTP traffic to the protected Web server.
John Adams is an HR partner in the ACME organization. ACME IT wants to limit access to HR servers to
designated IP addresses to minimize malware infection and unauthorized access risks. Thus, the gateway
policy permits access only from John's desktop which is assigned a static IP address 10.0.0.19.
John received a laptop and wants to access the HR Web Server from anywhere in the organization. The IT
department gave the laptop a static IP address, but that limits him to operating it only from his desk. The
current Rule Base contains a rule that lets John Adams access the HR Web Server from his laptop with a
static IP (10.0.0.19). He wants to move around the organization and continue to have access to the HR
Web Server.
To make this scenario work, the IT administrator:
1) Enables Identity Awareness on a gateway, selects AD Query as one of the Identity Sources installs the
policy.
2) Adds an access role object to the Firewall Rule Base that lets John Adams PC access the HR Web
Server from any machine and from any location.
John plugged in his laptop to the network on a different network segment and he is not able to connect.
How does he solve this problem?
A. John should lock and unlock the computer
B. Investigate this as a network connectivity issue
C. John should install the Identity Awareness Agent
D. The firewall admin should install the Security Policy