Paul has just joined the MegaCorp security administration team. Natalie, the administrator, creates a new administrator account for Paul in SmartDashboard and installs the policy. When Paul tries to login it fails. How can Natalie verify whether Paul’s IP address is predefined on the security management server?
A. Access the WEBUI on the Security Gateway, and verify whether Paul’s IP address is listed as a GUI client.
B. Login to Smart Dashboard, access Properties of the SMS, and verify whether Paul’s IP address is listed.
C. Login in to Smart Dashboard, access Global Properties, and select Security Management, to verify whether Paul’s IP address is listed.
D. Type cpconfig on the Management Server and select the option “GUI client List” to see if Paul’s IP address is listed.
400-151 exam Correct Answer: D

MultiCorp has bought company OmniCorp and now has two active AD domains. How would you deploy Identity Awareness in this environment?
A. Identity Awareness can only manage one AD domain.
B. Only Captive Portal can be used.
C. Only one ADquery is necessary to ask for all domains.
D. You must run an ADquery for every domain.
Correct Answer: D

Which of the following is the preferred method for adding static routes in Gaia?
A. In the CLI via sysconfig
B. In Web Portal, under Network Management > IPv4 Static Routes
C. In the CLI with the command “route add”

D. In SmartDashboard under Gateway Properties > Topology
400-151 dumps Correct Answer: B

Which command will erase all CRL’s?
A. vpn crl_zap
B. vpn flush
C. cpstop/cpstart
D. vpn crladmin
Correct Answer: A

Which component functions as the Internal Certificate Authority for R76?
A. Security Gateway
B. Management Server
C. Policy Server
D. SmartLSM
400-151 pdf Correct Answer: C

Control connections between the Security Management Server and the Gateway are not encrypted by the VPN Community. How are these connections secured?
A. They are encrypted and authenticated using SIC.
B. They are not encrypted, but are authenticated by the Gateway
C. They are secured by PPTP
D. They are not secured.
Correct Answer: A

If Bob wanted to create a Management High Availability configuration, what is the minimum number of Security Management servers required in order to achieve his goal?
A. Three
B. Two
C. Four
D. One

400-151 vce Correct Answer: B

David wants to manage hundreds of gateways using a central management tool. What tool would David use to accomplish his goal?
A. SmartProvisioning
B. SmartBlade
C. SmartDashboard
D. SmartLSM
Correct Answer: A

From the following output of cphaprob state, which ClusterXL mode is this?

A. New mode
B. Multicast mode
C. Legacy mode
D. Unicast mode
400-151 exam Correct Answer: D

Which of the following is NOT a feature of ClusterXL?
A. Enhanced throughput in all ClusterXL modes (2 gateway cluster compared with 1 gateway)
B. Transparent failover in case of device failures
C. Zero downtime for mission-critical environments with State Synchronization
D. Transparent upgrades
Correct Answer: C

In which case is a Sticky Decision Function relevant?
A. Load Sharing – Unicast
B. Load Balancing – Forward
C. High Availability
D. Load Sharing – Multicast

400-151 dumps Correct Answer: D

You configure a Check Point QoS Rule Base with two rules: an HTTP rule with a weight of 40, and the Default Rule with a weight of 10. If the only traffic passing through your QoS Module is HTTP traffic, what percent of bandwidth will be allocated to the HTTP traffic?
A. 80%
B. 40%
C. 100%
D. 50%
Correct Answer: C

When an 802.11 station operating in Power Save mode with a ReceiveDTIMs parameter of TRUE receives a beacon containing a DTIM indicating queued broadcast traffic, what task does the 802.11 standard require the client station to perform?
A. The client station must send an ATIM frame to the access point if the station is the first AID in the DTIM list.
B. The client station must arbitrate for the medium and immediately issue an RTS directed to the access point with the NAV set to a value of 32,768.
C. To remain awake to receive the broadcast frame(s) to follow the beacon that contains the DTIM.
D. The client station must broadcast a CTS-to-Self frame indicating the station need to control the medium long enough to receive all of the broadcast frames.
E. The client station must send a CF-Poll Response frame to the access point with the Reason Code set to 0x00.
F. The client station must send a PS-Poll frame to the access point for every broadcast frame it receives with the More Data bit set to one.
400-151 pdf Answer: C

Given the screenshot shown, choose the statement that accurately describes what is being seen by this protocol analyzer.
A. One wireless station sent an Echo Request (PING) to another wireless station through an access point.
B. The BSSID has been randomly generated.
C. The Duration field value’s 164 microseconds is sufficient to reserve the RF medium for only the following frames: SIFS, ACK.
D. Bits (0-14) of the Duration/ID field in this frame indicates the AID of the source station
Answer: B

Given the displayed wireless protocol analyzer trace, which of the following is true?
A. Both 00:40:96:A1:9A:F9 and 00:0D:ED:A5:4F:70 are operating in Ad Hoc mode using WPA compliant 802.1X/EAP authentication.
B. 00:0D:ED:A5:4F:70 is a client station sending unicast data frames to a network node on the wired LAN.
C. 00:40:96:A1:9A:F9 is a client station performing a successful 802.1X/EAPreauthentication.
D. 00:40:96:A1:9A:F9 is a station sending encrypted broadcast data using an encryption key generated by the authenticator.
E. FF:FF:FF:FF:FF:FF is the access point, and data encrypted with static WEP is being sent from a wired station to the wireless station 00:40:96:A1:9A:F9.
400-151 vce Answer: D

In the 802.11b standard, the PLCP header Service field has a Modulation Selection bit. Which of the following are true regarding use of the Modulation Selection bit?
A. The Modulation Selection bit is used by the access point in CF-End frames to note which modulation will be used for Data frames in the contention period to follow.
B. Based on the setting of the Modulation Selection bit and the value in the Signal field, the modulation to be used can be uniquely determined.
C. Based on the Modulation Selection bit in received Data frames, the receiving station can determine which modulation to use when sending acknowledgements.
D. The Modulation Selection bit is used to determine whether CCK or PBCC is in use for any speed where either could be used.
E. The Modulation Selection bit is used to determine which modulation will be used to send the entire PPDU.

Answer: B,D

What is an advantage of being able to fragment MSDUs and MMPDUs on a wireless network?
A. Increased throughput due to interference from other 802.11 stations.
B. Decreased translation time between 802.3 and 802.11 networks at the access point.
C. Increased throughput in an 802.11b/g mixed mode environment.
D. Decreased number of 802.11 control and management frames required for transmission.
E. Increased throughput in a clean RF environment
F. Decreased retransmission overhead in a noisy RF environment.
400-151 exam Answer: F

In compliance with the 802.11g standard, access points may provide which services to increase overall network performance in an OFDM-only environment?
A. Arbitrary Beacon Spacing
B. DownstreamQoS
C. Short Slot Time
D. Short PLCP Preamble support
E. Fast Sleep Recovery
Answer: C

Which features of a wireless LAN protocol analyzer allow troubleshooters to monitor network events that are happening while the troubleshooters are not watching the analyzer user interface?
A. Event Triggers
B. Node Statistics
C. Notifications
D. Peer Map
E. Trending Analysis
F. Alarms
400-151 dumps Answer: A,C,F

The 802.11 standard allows for frame fragmentation due to an unreliable medium. Which two fields in the 802.11 frame are involved in numbering data frame fragments and notifying the receiving station when all of the fragments of a data frame have been received?
A. Ordered Service field
B. Sequence Control field
C. Frame Control field
D. ERP Information field
E. Capability Information field
F. DS Parameter field
Answer: B,C

What 802.11 MAC layer function is illustrated by the following diagram?
A. Sequential Fragmentation
B. PCF mode polling
C. Fragment Bursting
D. Sequential Acknowledgements
E. CP Regulated Spacing
400-151 pdf Answer: C

When operating in an 802.11b/g mixed mode environment in which both 802.11b and 802.11g client stations are present and transmitting data on the network, which of the statements below are accurate concerning the 802.11g access point responsibilities in the Basic Service Set?
A. The access point will alternate transmitting beacons using long and short preambles so that client stations using either preamble length can associate.

B. The access point may transmit beacons using a short preamble only if all of the client stations in the BSS have indicated support for short preambles.
C. If beacons are transmitted using short preambles, all associated client stations are required to transmit all data frames using short preambles.
D. The access must transmit beacons using a short preamble in a mixed mode environment. Client stations not supporting short preambles will not be able to associate.
Answer: B

The More Fragments subfield is found in which 802.11 frame field?
A. Protocol Order field
B. Frame Control field
C. MAC Service Data Unit field
D. Sequence Control field
E. Fragmentation Control field
400-151 vce Answer: B

You have pushed a policy to your firewall and you are not able to access the firewall. What command will allow you to remove the current policy from the machine?
A. fw purge policy
B. fw fetch policy
C. fw purge active
D. fw unloadlocal
Correct Answer: D

How do you verify the Check Point kernel running on a firewall?
A. fw ctl get kernel
B. fw ctl pstat
C. fw kernel
D. fw ver -k
400-151 exam Correct Answer: D

Match the following commands to their correct function. Each command has one function only listed.
A. C1>F2; C2>F1; C3>F6; C4>F4
B. C1>F4; C2>F6; C3>F3; C4>F2
C. C1>F2; C2>F4; C3>F1; C4>F5
D. C1>F6; C2>F4; C3>F2; C4>F5
Correct Answer: D

Which command displays the installed Security Gateway version?
A. fw ver
B. fw stat
C. fw printver
D. cpstat -gw
400-151 dumps Correct Answer: A

