Official Bank 0/159

Check Point Certified Security Master – R80 Exam (156-115) - Checkpoint Exam Questions

Last updated on June 22, 2026

97% Exam Compliance
159 Total Questions
1
Question
John works for ABC Corporation. They have enabled CoreXL on their firewall. John would like to identify the cores on which the SND runs and the cores on which the firewall instance is running.

Which command should John run to view the CPU role allocation?
Options
A fw ctl affinity –v
B fwaccel stat –l
C fw ctl cores
D fw ctl affinity –l
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
You suspect that IPS protections may be dropping legitimate traffic by mistake. To reduce the false positives, what GuiDBedit parameter could you enable to work with fw ctl zdebug drop to generate a more elaborate drop message for these packets?
Options
A enable_inspect_debug_ips_compilation
B inspect_ips_debug_inspection
C enable_inspect_debug_ips
D enable_inspect_debug_compilation
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
If certain services should not use the Cluster Object IP Address, but requires the use of the individual
Cluster Member IPs, what steps would be required for configuration?
Options
A Create Manual NAT rules in the Security Policy
B The configuration is not possible
C Edit the fwkern.conf on each Cluster Member
D Edit the table.def file on the Management Server
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
What does the command “vpn shell tunnels delete all ike” do?
Options
A Deletes all IKE and IPSEC SA’s
B Deletes all IKE configuration on the Gateway
C Delete only outbound_SPI tables
D Deletes all IKE SA’s
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
An administrator is creating a new site-to-site VPN connection. The agreed settings are AES256 and SHA256. If Elliptic Curve type transforms are required then what can be specifically configured to achieve this level of security?
Options
A Protocol 50 with AES
B Diffie-Hellman Group 20
C AH should replace ESP
D Perfect Forward Secrecy
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.