Our pass rate is high to 98.9% and the similarity percentage between our 156-115.77 study guide and real exam is 90% based on our seven-year educating experience. Do you want achievements in the Check Point 156-115.77 exam in just one try? I am currently studying for the Check Point 156-115.77 exam. Latest Check Point 156-115.77 Test exam practice questions and answers, Try Check Point 156-115.77 Brain Dumps First.

Q105. - (Topic 11) 

What type(s) of VTI interfaces do Edge gateways support? 

A. Both numbered and unnumbered 

B. Unnumbered interfaces 

C. Numbered interfaces 

D. Neither numbered and unnumbered 

Answer:


Q106. - (Topic 10) 

How do you disable IPv6 on an IPSO gateway? 

A. Run $FWDIR/scripts/fwipv6_enable off and reboot. 

B. Remove the IPv6 license from the gateway. 

C. You cannot disable IPv6. 

D. In IPSO go to System Management > System Configuration, set IPv6 Support to off, and click Apply. 

Answer:


Q107. - (Topic 11) 

You would like to configure unnumbered VTIs and your environment uses load sharing clustering. Would this clustering technology be supported by your unnumbered VTI’s? 

A. No, unnumbered VTIs only support VRRP HA active-passive mode. 

B. Yes, unnumbered VTIs only support clustering load sharing. 

C. Yes, all HA modes are supported. 

D. No, unnumbered VTIs do not support any HA modes. 

Answer:


Q108. - (Topic 5) 

What do the ‘F’ flags mean in the output of fwaccel conns? 

A. Forward to firewall 

B. Flag set for debug 

C. Fast path packets 

D. Flow established 

Answer:


Q109. - (Topic 7) 

Which command displays FireWall internal statistics about memory and traffic? 

A. fw getifs 

B. cpstat os –f memory 

C. fw ctl pstat 

D. cpstat os –f cpu 

Answer:

Topic 8, Enable CoreXL 


Q110. - (Topic 6) 

If you need to use a Domain object in the Rule Base, where should this rule be located? 

A. No higher than the 2nd rule. 

B. The first rule in the Rule Base. 

C. The last rule before the clean up rule. 

D. The last rule after the clean up rule. 

Answer:


Q111. - (Topic 4) 

You want to run VPN debug that will generate both ike.elg and vpn.elg files. What is the best command that can be used to achieve this goal? 

A. vpn debug ikeon 

B. vpn debug on TDERR_ALL_ALL=5 

C. vpn debug trunc 

D. vpn debug trunc 

Answer:


Q112. - (Topic 5) 

A new packet has arrived to a firewall's interface. The packet was compared with the connection table and there is no match. What process does the firewall start with that connection? 

A. The packet will be then forwarded to the outbound interface for handling. 

B. The new packet represents a new flow and requires a new connection table entry. 

C. The packet will be rejected by the kernel firewall. 

D. The packet will be forwarded to the firewall to apply the Security Policy. 

Answer: