
78 Q&As in UPDATED 156-590 Exam Questions Certification Test Engine to PDF
Get The Important Preparation Guide With 156-590 Dumps
NEW QUESTION # 41
What are the three IPS update options?
- A. Auto Update, Policy Update, Update Now
- B. Update Now, Schedule Update, Follow Protections
- C. Manual Update, Scheduled Update, Auto Update
- D. Update Now, Schedule Update, Follow policy
Answer: B
Explanation:
The correct answer is B. Update Now, Schedule Update, Follow Protections . Check Point IPS protection maintenance includes manual updating, scheduled updating, and a follow-up workflow for newly updated protections. The official IPS Protections documentation explains that administrators can immediately update IPS from Custom Policy Tools > Updates > IPS > Update Now , and that IPS protections can also be updated by configuring a schedule for automatic downloads. It also notes that IPS updates require Threat Prevention Policy installation for enforcement.
The same IPS Protections section describes Follow Up behavior for protections: administrators can mark protections for follow-up, filter on them later, and updated protections can be automatically marked for follow- up so they can be reviewed after update. In the course-question wording, this maps to "Follow Protections." The purpose is operational control: update now provides immediate package retrieval, scheduled update automates routine maintenance, and follow protections gives administrators a practical workflow to review newly added or changed IPS protections. The other options either use non-standard names or omit the protection-review workflow. Reference topics: IPS Protections, Update Now, Scheduling IPS Updates, Follow Up Protections, Threat Prevention Policy installation.
NEW QUESTION # 42
Which is NOT an available setting under Custom Policy Tools?
- A. UserCheck
- B. Malicious Activity Detection
- C. IPS Protections
- D. Indicators
Answer: A
Explanation:
The correct answer is B. UserCheck . In SmartConsole, Custom Policy Tools are used to manage Threat Prevention policy objects and tuning components such as profiles, IPS protections, indicators, and protection categories. The official R81.20 guide shows Custom Policy Tools > Profiles for profile creation, editing, and cloning, and Custom Policy Tools > IPS Protections for managing IPS protection behavior. The same guide also shows Custom Policy Tools > Indicators as the location used to configure external IoC feeds.
Malicious Activity Detection is represented through Threat Prevention protection types: the Protections Browser displays protection types, and the guide states that Malicious Activity and Unusual Activity protection types contain lists of protections. UserCheck, however, is not itself a Custom Policy Tools setting.
It is a user interaction and notification mechanism configured inside relevant blade/profile settings, such as Anti-Bot or Zero Phishing UserCheck messages. Therefore, among the choices, UserCheck is the item that does not belong as an available Custom Policy Tools setting. Reference topics: Custom Policy Tools, IPS Protections, Indicators, Threat Prevention Profiles, Protections Browser, UserCheck settings.
NEW QUESTION # 43
At what point is the Anti-Bot blade enforced?
- A. Pre-inspection
- B. Post-inspection
- C. Post-infection
- D. Pre-infection
Answer: C
Explanation:
The correct answer is B. Post-infection . Anti-Bot is the Threat Prevention blade focused on identifying and stopping bot-infected hosts after compromise indicators appear. Check Point documentation explicitly describes Anti-Bot as performing post-infection detection of bots on hosts and preventing bot damage by blocking command-and-control communications. The broader Threat Prevention guide also lists Anti-Bot as post-infection detection and explains that it uses ThreatCloud intelligence and multiple detection methods to identify bot activity.
This differs from IPS and Anti-Virus positioning. IPS and Anti-Virus are commonly understood as pre- infection controls because they attempt to block exploit traffic or malicious files before the host is compromised. Anti-Bot, by contrast, assumes the possibility that a host may already be infected and focuses on detecting outbound C & C communication, botnet behavior, malicious destinations, and other compromise evidence. Pre-inspection and post-inspection are not valid lifecycle categories for this blade in the exam context. In real operations, Anti-Bot is especially valuable for finding infected internal machines that bypassed earlier preventive controls or became infected off-network. Reference topics: Anti-Bot Software Blade, post-infection detection, Command and Control prevention, ThreatCloud intelligence, botnet behavior detection.
NEW QUESTION # 44
Task: Test action taken for suspected bot-infected host.
Answer:
Explanation:
See the Explanation.Explanation:
1- Generate outbound suspicious DNS request (e.g., using simulated botnet domain).
2- Review logs in SmartConsole > blade:"Anti-Bot".
3- Confirm whether the connection was blocked or allowed.
4- Validate host quarantine action, if configured.
5- Check endpoint if agent alerts were triggered.
NEW QUESTION # 45
Task: Confirm that Security Management Server is operational.
Answer:
Explanation:
See the Explanation.Explanation:
1- SSH into the Management Server.
2- Check processes: cpwd_admin list.
3- Validate services: cpstat mg.
4- Confirm GUI is accessible via SmartConsole.
5- Run: netstat -an | grep 19009 to ensure GUI port is open.
NEW QUESTION # 46
Task: View logs of Anti-Bot detections in SmartConsole.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Logs & Monitor.
2- Use search filter: blade:"Anti-Bot" and time range = last 24 hours.
3- View events showing Botnet communication attempts.
4- Double-click logs to review source, domain contacted, and action taken.
5- Save filtered logs as report if needed.
NEW QUESTION # 47
Task: Simulate a malicious file download and validate AV detection.
Answer:
Explanation:
See the Explanation.Explanation:
1- In test environment, download EICAR test file.
2- Monitor logs: blade:"Anti-Virus" AND action:"Prevented".
3- Confirm file type, source IP, and destination file path.
4- Check associated protection name.
5- Ensure AV blade action is set to "Prevent."
NEW QUESTION # 48
Protections with a High Protection Impact rating go through which path?
- A. CPASXL
- B. F2F
- C. SXL
- D. PXL
Answer: B
Explanation:
The correct answer is D. F2F . Protections with high inspection impact generally require deeper processing that cannot remain fully accelerated in SecureXL. In Check Point performance terminology, F2F means traffic is forwarded from SecureXL to the Firewall path for inspection. Performance tuning documentation describes F2F packets as packets that SecureXL forwarded to the Firewall in the slow path, while accelerated traffic remains in the fast path. Threat Prevention protections, especially high-impact IPS protections, can require deeper packet, stream, or protocol analysis and therefore increase the portion of traffic processed outside full SecureXL acceleration.
Check Point IPS documentation explains that Performance Impact is the measure of how much a protection affects gateway performance and warns that activated protections with higher performance impact can cause connectivity or performance issues. The IPS optimization guidance further explains that some protections require more system resources to inspect traffic and recommends focusing on lower-impact protections when reducing gateway resource use is necessary. SXL is the fully accelerated path, PXL is medium-path inspection with acceleration assistance, and CPASXL relates to active streaming acceleration. High Protection Impact aligns with F2F because the gateway must perform deeper inspection. Reference topics: IPS Performance Impact, SecureXL packet paths, F2F, PXL/SXL, IPS optimization.
NEW QUESTION # 49
Task: Add a comment in a Threat Prevention profile to indicate usage purpose.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open the custom profile (e.g., Corporate_TP_Strict).
2- Add a note in the description field: e.g., "Used for internal office users."
3- Save changes.
4- Optionally add version info or change history.
5- Use this for future auditing and documentation.
NEW QUESTION # 50
Task: Clone a built-in IPS profile and tailor it to internal services.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open Threat Prevention > Profiles.
2- Select "Optimized" > Right-click > Clone.
3- Rename it (e.g., "Internal_Services_Profile").
4- Disable protections unnecessary for internal traffic (e.g., HTTP-related).
5- Save, apply to Threat Prevention policy layer.
NEW QUESTION # 51
Task: Configure inspection settings for mobile VPN users.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Threat Prevention > Inspection Settings.
2- Add a new exception group for mobile user IP pool.
3- Set reduced inspection sensitivity for this group.
4- Save, publish, and test VPN user traffic.
5- Ensure logs still show critical threats being detected.
NEW QUESTION # 52
What information is provided by "fwaccel stats"?
- A. The command is used to examine traffic utilization statistics.
- B. You can check the percentage of F2F connections along with the reason why those connections could not be accelerated.
- C. This command is to enable acceleration on QoS packets.
- D. You can check the SecureXL status of your Security Gateway.
Answer: B
Explanation:
The correct answer is B. You can check the percentage of F2F connections along with the reason why those connections could not be accelerated . The command fwaccel stats is part of SecureXL performance analysis. It is used to inspect how traffic is distributed across acceleration paths and firewall paths, which is essential when Threat Prevention blades or deep inspection features push traffic away from full acceleration.
Check Point's Performance Tuning documentation shows that fwaccel stats -s provides a summary including accelerated packets, F2Fed packets, F2V packets, CPASXL packets, PSLXL packets, and related totals.
The same documentation explains that F2F packets are packets SecureXL forwarded to the Firewall kernel in the slow path. This makes the command directly useful when diagnosing performance issues caused by non- accelerated inspection, SecureXL violations, or traffic that must be inspected by firewall and Threat Prevention components. Option A is wrong because fwaccel stats does not enable QoS acceleration. Option C is too generic; the command is not merely utilization monitoring. Option D better describes fwaccel stat , which reports SecureXL status, accelerated interfaces, and accelerated features. Reference topics: SecureXL, fwaccel stats, F2F packets, accelerated path, firewall path, performance troubleshooting.
NEW QUESTION # 53
Task: Customize an existing IPS protection's severity and action.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open Threat Tools > IPS Protections.
2- Search and select the protection (e.g., MS-SQL buffer overflow).
3- Change "Action" to Prevent and set Severity to Critical.
4- Assign it to the custom IPS profile.
5- Publish changes and install the policy.
NEW QUESTION # 54
Task: Check if IPS blade is inspecting encrypted traffic.
Answer:
Explanation:
See the Explanation.Explanation:
1- Confirm HTTPS Inspection is enabled on the gateway.
2- Navigate to Threat Prevention > Protections.
3- Check protections related to SSL/TLS.
4- Confirm visibility of SSL payloads in logs.
5- Use HTTPS test traffic and review detection.
NEW QUESTION # 55
Task: Configure automatic IPS updates via SmartConsole.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open SmartConsole > Threat Prevention > Updates.
2- Enable "Check for updates automatically."
3- Set schedule (e.g., daily at 2:00 AM).
4- Enable "Install updates automatically" for production or testing only.
5- Click OK and publish changes.
NEW QUESTION # 56
IPS stands for?
- A. Intrusion Prevention Software
- B. Intrusion Prevention System
- C. Invasion Prevention Software
- D. Invasion Prevention System
Answer: B
Explanation:
The correct answer is B. Intrusion Prevention System . In Check Point terminology, IPS is the Software Blade responsible for inspecting and analyzing packets and data for numerous risk types. The official Check Point Threat Prevention documentation identifies IPS as Intrusion Prevention System and describes IPS protections as part of the Threat Prevention Software Blade framework.
IPS is more than a simple signature engine. It provides vulnerability-oriented and exploit-oriented protections, including protections mapped to CVEs, protocol anomalies, command injection patterns, server-side attacks, client-side attacks, and other known or unknown exploitation behaviors. Check Point also describes IPS as delivering proactive intrusion prevention with thousands of signatures, behavioral protections, and preemptive protections, adding another layer of security above firewall enforcement.
The incorrect options misuse the term "Invasion" or replace "System" with "Software." Although IPS is implemented as a Check Point Software Blade, the acronym itself expands to Intrusion Prevention System .
In policy design, IPS is treated as a pre-infection prevention capability that stops exploitation before compromise, rather than as a post-infection malware-detection control. Reference topics: IPS Software Blade, Intrusion Prevention System definition, IPS protections, CVE-based protections, proactive intrusion prevention.
NEW QUESTION # 57
Task: Configure a policy to log only "Detect" events for Anti-Bot scanning on internal users.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Threat Prevention > Policy.
2- Add a rule: Source = Internal Networks, Dest = Internet.
3- Assign a profile where Anti-Bot action is set to "Detect."
4- Track = Log, Action = Accept.
5- Publish and install the policy.
NEW QUESTION # 58
Task: Enable automatic email alerts for critical IPS events.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open SmartEvent or SmartConsole > Logs & Monitor.
2- Go to Automatic Reactions > New Reaction.
3- Set condition: blade=IPS AND severity=Critical.
4- Choose Action: Send Email > Configure recipient.
5- Save and test by generating a trigger.
NEW QUESTION # 59
......
Prepare With Top Rated High-quality 156-590 Dumps For Success in Exam: https://examtorrent.dumpsactual.com/156-590-actualtests-dumps.html
