CheckPoint 156-215.13 Exam Overview:
| Certification Vendor: | Check Point |
|---|---|
| Exam Name: | Check Point Certified Security Administrator (CCSA) - GAiA |
| Exam Number: | 156-215.13 |
| Available Languages: | English |
| Exam Format: | Scenario-based Questions, Multiple Choice |
| Related Certifications: | Check Point Certified Security Administrator (CCSA) Check Point Certified Security Expert (CCSE) |
| Real Exam Qty: | 90 - 100 |
| Certificate Validity Period: | 2 years |
| Exam Price: | USD 250 (approx.) |
| Exam Duration: | 90 minutes |
| Passing Score: | 70% - 75% (approx.) |
| Sample Questions: | CheckPoint 156-215.13 Sample Questions |
| Exam Way: | Online or test center (proctored) |
| Pre Condition: | Basic networking knowledge recommended; no formal prerequisites required |
| Official Syllabus URL: | https://www.checkpoint.com/certifications/ |
CheckPoint 156-215.13 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Security Policy Management | - Security policies and rulebase configuration - Network Address Translation (NAT) |
| Monitoring, Logging, and Troubleshooting | - SmartConsole logging and SmartView tools - Troubleshooting firewall and connectivity issues |
| Check Point Security Fundamentals | - Check Point Security solutions overview - Network security principles and architecture |
| Firewall and Traffic Management | - Access Control policies - Traffic inspection and packet flow |
| GAiA Operating System | - GAiA OS installation and configuration - System management and CLI/GUI tools |
| VPN and Remote Access | - Site-to-Site VPN configuration - Remote access VPN concepts |
CheckPoint Check Point Certified Security Administrator - GAiA Sample Questions:
To check the Rule Base, some rules can be hidden so they do not distract the administrator from the unhidden rules. Assume that only rules accepting HTTP or SSH will be shown. How do you accomplish this?
- A. In SmartDashboard, right-click in the column field Service > Query Column. Then, put the services HTTP and SSH in the list. Do the same in the field Action and select Accept here.
- B. Ask your reseller to get a ticket for Check Point SmartUse and deliver him the Security Management Server cpinfo file.
- C. This cannot be configured since two selections (Service, Action) are not possible.
- D. In SmartDashboard menu, select Search > Rule Base Queries. In the window that opens, create a new Query, give it a name (e.g. "HTTP_SSH") and define a clause regarding the two services HTTP and SSH. When having applied this, define a second clause for the action Accept and combine them with the Boolean operator AND.
Correct Answer: D 🗳️
Central license management allows a Security Administrator to perform which of the following functions?
1.Check for expired licenses.
2.Sort licenses and view license properties.
3.Attach both R76 Central and Local licesnes to a remote module.
4.Delete both R76 Local Licenses and Central licenses from a remote module.
5.Add or remove a license to or from the license repository.
6.Attach and/or delete only R76 Central licenses to a remote module (not Local licenses).
- A. 2, 3, 4, & 5
- B. 2, 5, & 6
- C. 1, 2, 5, & 6
- D. 1, 2, 3, 4, & 5
Correct Answer: D 🗳️
All of the following are Security Gateway control connections defined by default implied rules, EXCEPT:
- A. Communication with server types, such as RADIUS, CVP, UFP, TACACS, and LDAP.
- B. Exclusion of specific services for reporting purposes.
- C. Acceptance of IKE and RDP traffic for communication and encryption purposes.
- D. Specific traffic that facilitates functionality, such as logging, management, and key exchange.
Correct Answer: B 🗳️
Which of these Security Policy changes optimize Security Gateway performance?
- A. Putting the least-used rule at the top of the Rule Base.
- B. Using groups within groups in the manual NAT Rule Base.
- C. Use Automatic NAT rules instead of Manual NAT rules whenever possible.
- D. Using domain objects in rules when possible.
Correct Answer: C 🗳️
An internal router is sending UDP keep-alive packets that are being encapsulated with GRE and sent through your R76 Security Gateway to a partner site. A rule for GRE traffic is configured for ACCEPT/LOG. Although the keep-alive packets are being sent every minute, a search through the SmartView Tracker logs for GRE traffic only shows one entry for the whole day (early in the morning after a Policy install).
Your partner site indicates they are successfully receiving the GRE encapsulated keep-alive packets on the 1-minute interval.
If GRE encapsulation is turned off on the router, SmartView Tracker shows a log entry for the UDP keep-alive packet every minute.
Which of the following is the BEST explanation for this behavior?
- A. The setting Log does not capture this level of detail for GRE. Set the rule tracking action to Audit since certain types of traffic can only be tracked this way.
- B. The Log Server is failing to log GRE traffic properly because it is VPN traffic. Disable all VPN configuration to the partner site to enable proper logging.
- C. The Log Server log unification process unifies all log entries from the Security Gateway on a specific connection into only one log entry in the SmartView Tracker. GRE traffic has a 10 minute session timeout, thus each keep-alive packet is considered part of the original logged connection at the beginning of the day.
- D. The log unification process is using a LUUID (Log Unification Unique Identification) that has become corrupt. Because it is encrypted, the R75 Security Gateway cannot distinguish between GRE sessions. This is a known issue with GRE. Use IPSEC instead of the nonstandard GRE protocol for encapsulation.
Correct Answer: C 🗳️

We're so confident of our products that we provide no hassle product exchange.


By Magee


