CheckPoint 156-215.71 Exam Overview:
| Certification Vendor: | Check Point |
| Exam Name: | Check Point Certified Security Administrator R71 |
| Exam Number: | 156-215.71 |
| Real Exam Qty: | 90 - 100 |
| Related Certifications: | Check Point Certified Security Expert (CCSE) |
| Exam Duration: | 90 minutes |
| Passing Score: | 70% - 75% |
| Certificate Validity Period: | 3 years |
| Available Languages: | English |
| Exam Format: | Multiple choice, Scenario-based questions |
| Recommended Training: | Check Point CCSA Training |
| Exam Registration: | Check Point Certification Portal Pearson VUE Check Point Exams |
| Sample Questions: | CheckPoint 156-215.71 Sample Questions |
| Exam Way: | Administered via Pearson VUE testing centers or online proctored exam |
| Pre Condition: | No formal prerequisite required, but basic networking knowledge is recommended. |
| Official Syllabus URL: | https://www.checkpoint.com |
CheckPoint 156-215.71 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| User Management and Authentication | - LDAP integration basics - User authentication methods |
| Security Architecture and Concepts | - Firewall fundamentals - Check Point Security Platform Overview - Packet flow and inspection |
| Monitoring, Logging and Troubleshooting | - Basic troubleshooting tools - Traffic monitoring - Log analysis in SmartView Tracker |
| Security Policy Management | - NAT configuration - Rule base configuration - SmartConsole / SmartDashboard usage |
| Network Address Translation (NAT) and VPN | - IPSec VPN concepts - Remote access VPN basics - Static and dynamic NAT |
CheckPoint Check Point Certified Security Administrator R71 Sample Questions:
1. What can NOT be selected for VPN tunnel sharing?
A) One tunnel per VPN domain pair
B) One tunnel per subnet pair
C) One tunnel per pair of hosts
D) One tunnel per Gateway pair
2. How can you most quickly reset Secure Internal Communications (SIC) between a Security Management Server and Security Gateway?
A) From the Security Management Server's command line, Type fw putkey -p <shared key> < IP Address of security Gateway>.
B) Run the command fwm sic-reset to initialize the Internal Certificate Authority (ICA) of the Security Management Server. Then retype the activation key on the Security Gateway from SmartDashboard.
C) Use SmartDashboard to retype the activation key on the Security Gateway. This will automatically Sync SIC to both the Security Management Server and Gateway.
D) From cpconfig on the Gateway, choose the Secure Internal Communication option and retype the activation key. Next, retype the same key in the Gateway object in SmartDashboard and reinitialize Secure Internal Communications (SIC).
3. Looking at an fw monitor capture in Wireshark, the initiating packet in Hide NAT translates on________.
A) O
B) o
C) i
D) I
4. Which of the following commands can provide the most complete restore of an R71 configuration?
A) fwm dbimport -p
B) Upgrade_import
C) cpinfo -recover
D) Cpconfig
5. Why should the upgrade_export configuration file (.tgz) be deleted after you complete the import process?
A) SmartUpdate will start a new installation process if the machine is rebooted.
B) It will conflict with any future upgrades when using SmartUpdate.
C) It will prevent a future successful upgrade_export since the .tgz file cannot be overwritten.
D) It contains your security configuration, which could be exploited.
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: D | Question # 3 Answer: A | Question # 4 Answer: B | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Mick

