View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.
Question 1. What does Harmony Endpoint primarily protect?
- Network routers
- Cloud databases only
- Endpoint devices
- Physical switches
Correct Answer: 3. Endpoint devices
Explanation:
Harmony Endpoint is Check Point’s endpoint security solution for protecting user devices such as workstations and supported servers against malware, ransomware, exploits, malicious files, and other endpoint threats. The 156-536 exam is aligned with the Check Point Certified Harmony Endpoint Specialist R81.20 course, which covers deployment, endpoint management, data security, threat prevention, and troubleshooting. The solution combines several security capabilities under centralized endpoint management so administrators can define policies, monitor endpoints, investigate attacks, and respond to security incidents.
Question 2. Which console provides web-based Endpoint management?
- Endpoint Web Management Console
- Gaia Portal
- cpview
- SmartView Monitor
Correct Answer: 1. Endpoint Web Management Console
Explanation:
The Endpoint Web Management Console provides browser-based management for Harmony Endpoint environments. Administrators can use it to configure endpoint policies, deployment settings, global settings, and security protections. The R81.20 administration guide describes policy configuration directly through this web console, including Threat Prevention, Data Protection, and Deployment Policy settings. Web-based administration is especially useful for centralized operational management because administrators can manage protected endpoint groups and policy behavior without relying only on traditional desktop management interfaces.
Question 3. What does the Deployment Policy control?
- DNS forwarding
- Gateway routing
- Email filtering
- Endpoint component deployment
Correct Answer: 4. Endpoint component deployment
Explanation:
The Deployment Policy controls which Endpoint Security components are installed or deployed to protected computers. Administrators use deployment settings to determine what functionality each endpoint receives and can create deployment packages containing selected components. Check Point documentation identifies Deployment Policy as one of the major Endpoint policy components. During manual deployment, the exported installation package contains the selected component set and automatically installs the applicable components for the endpoint computer. This allows administrators to standardize endpoint security software according to organizational requirements.
Question 4. Which policy includes Web & Files Protection?
- Access Policy
- Threat Prevention
- Routing Policy
- NAT Policy
Correct Answer: 2. Threat Prevention
Explanation:
Threat Prevention includes Web & Files Protection as one of its principal protection areas. In the R81.20 Endpoint Web Management Console, Threat Prevention also includes Behavioral Protection and Analysis & Remediation. These capabilities are managed through a unified Threat Prevention policy in the web interface. Web & Files Protection helps protect endpoint users from dangerous downloads and malicious web content through technologies such as Threat Emulation and Threat Extraction. Administrators can create rules and select appropriate prevention settings according to the protected scope.
Question 5. What does Threat Emulation detect?
- Zero-day and unknown attacks
- Only known signatures
- Hardware failures
- License expiration
Correct Answer: 1. Zero-day and unknown attacks
Explanation:
Threat Emulation analyzes suspicious files in a sandbox to identify malicious behavior, including zero-day and previously unknown attacks. Files can be sent for emulation before users receive the original content, depending on policy configuration. Because the technology examines how files behave rather than relying only on known malware signatures, it can detect evasive threats that traditional signature-based approaches may miss. Harmony Endpoint supports Threat Emulation for many common document, archive, script, executable, and other file types.
Question 6. What is Threat Extraction designed to provide?
- Faster DNS resolution
- Endpoint inventory only
- Safe file content
- Firewall routing
Correct Answer: 3. Safe file content
Explanation:
Threat Extraction provides users with a safer version of a downloaded document while potentially dangerous elements are removed or neutralized. Depending on configuration, the system can remove active content such as macros or scripts while keeping the original file type, or it can convert supported documents into safer PDF content. This lets users access needed information quickly without waiting for every file to complete full threat analysis. Threat Extraction therefore complements Threat Emulation by reducing user exposure to potentially malicious content.
Question 7. Which feature protects against file encryption attacks?
- Appscan
- Anti-Ransomware
- LDAP
- URL categorization
Correct Answer: 2. Anti-Ransomware
Explanation:
Anti-Ransomware monitors endpoint files and processes for behavior associated with ransomware. Check Point describes the component as continuously watching for unusual activity and protecting files before malicious encryption can permanently damage them. The solution can back up files to a safe location and restore original content after the attack is stopped. It works closely with Behavioral Guard and Forensics capabilities to identify suspicious activity, remediate malicious elements, and provide analysis about what happened during the attack.
Question 8. What does Forensics mainly provide?
- Network address translation
- Password storage
- DNS filtering
- Attack analysis details
Correct Answer: 4. Attack analysis details
Explanation:
Forensics collects and organizes detailed information about malicious or suspicious activity on protected endpoints. It analyzes processes, file operations, network activity, and detections generated by other endpoint components. Check Point organizes the collected evidence into a Forensics Analysis Report so administrators can understand how an attack began, what actions occurred, which objects were affected, and how the threat progressed. This information supports investigation and remediation by giving administrators greater context than a simple malware alert.
Question 9. What should be configured before enabling a blade?
- Exclusions
- Static routes
- NAT rules
- VLANs
Correct Answer: 1. Exclusions
Explanation:
Check Point recommends adding appropriate exclusions before enabling relevant Harmony Endpoint Software Blades. Exclusions help prevent legitimate organizational software or workflows from being incorrectly blocked when a new security component begins operating. The recommended rollout process also includes enabling the blade first on a test group before extending it to the entire organization. This staged approach lets administrators identify false positives, compatibility problems, or performance issues before broad deployment. Check Point specifically lists exclusions as an important prerequisite for several blades.
Question 10. Where should a new blade be enabled first?
- Entire organization
- Test group
- Internet gateway only
- Domain controller only
Correct Answer: 2. Test group
Explanation:
Check Point recommends enabling new Software Blades and operating modes on a test group before enabling them across the entire organization. A test group lets administrators evaluate compatibility, false positives, system impact, and policy behavior on a controlled number of endpoints. After validating the protection in the test group, administrators can expand the configuration to the organization level. This gradual deployment strategy reduces the risk that a policy change disrupts large numbers of endpoints or business applications.
Question 11. Which blade should generally use Prevent mode first?
- Forensics organization-wide
- Anti-Exploit organization-wide immediately
- Anti-Malware on a test group
- URL Filtering without testing
Correct Answer: 3. Anti-Malware on a test group
Explanation:
Check Point’s recommended blade-enablement sequence begins with Anti-Malware in Prevent mode on a test group. After successful validation, the same protection can be expanded to the organization. Other components may initially be introduced in Detect mode before moving to Prevent mode. This phased approach recognizes that different protection technologies have different operational impacts. Starting Anti-Malware in Prevent mode on a controlled group provides direct protection while limiting the risk of unexpected application conflicts or false positives during initial testing.
Question 12. What does Application Control restrict?
- Disk encryption keys
- Endpoint application network access
- DNS zones
- Gateway clustering
Correct Answer: 2. Endpoint application network access
Explanation:
Application Control restricts network access for specified endpoint applications and processes. Administrators can define policies that allow, block, or terminate applications depending on organizational security requirements. An application can be terminated when it attempts to access the network or immediately when it starts, depending on the configured rule. This feature helps reduce the risk from unauthorized or unwanted software and gives administrators granular control over what endpoint applications are permitted to communicate across the network.
Question 13. Which tool inventories applications for Application Control?
- Appscan
- cpstat
- tcpdump
- cplic
Correct Answer: 1. Appscan
Explanation:
Appscan is used to generate a list of applications installed on a reference endpoint for Application Control configuration. Administrators first prepare a reference device with the typical applications used in their environment. Appscan then creates an XML file containing application details. That file is uploaded to the Endpoint Security Management Server, where administrators define how each application should be handled. This approach helps build an Application Control policy based on the software actually deployed in the organization.
Question 14. What format does Appscan generate?
- CSV
- JSON
- XML
Correct Answer: 3. XML
Explanation:
Appscan generates an XML file containing details about the applications discovered on the reference computer. The administrator uploads this XML file to Endpoint Security Management so the applications can be used when creating Application Control rules. Each application can then be assigned an appropriate action, such as allowed, blocked, or terminated. Using XML provides a structured way to transfer application inventory information from the reference endpoint into the management environment.
Question 15. Which dashboard shows critical endpoint violations?
- SmartView Tracker
- Operational Overview
- ThreatWiki
- Gaia Overview
Correct Answer: 2. Operational Overview
Explanation:
Operational Overview provides centralized monitoring information about endpoint deployment and policy status. Its Active Alerts area identifies endpoint computers that violate critical security rules. Examples include compliance warnings, failed deployments, encryption problems, and Anti-Malware issues. Monitoring this dashboard helps administrators quickly identify computers that are not receiving expected protection or that require remediation. Check Point emphasizes routine monitoring of endpoint deployment and security policy as an important part of day-to-day endpoint administration.
Question 16. Which problem can trigger an Active Alert?
- Failed deployment
- Successful login
- Normal heartbeat
- Policy installation success
Correct Answer: 1. Failed deployment
Explanation:
A failed deployment can trigger an Active Alert in the Operational Overview dashboard. Other examples include compliance warnings, encryption problems, and Anti-Malware issues. These alerts help administrators identify endpoints that may not have received required security components or policies. A failed deployment can leave an endpoint incompletely protected, so it should be investigated promptly. Monitoring Active Alerts gives administrators a central view of significant endpoint security and deployment problems that require attention.
Question 17. What is included in Data Protection?
- Threat Emulation
- Full Disk Encryption
- Anti-Bot
- Anti-Exploit
Correct Answer: 2. Full Disk Encryption
Explanation:
Full Disk Encryption is part of the Data Protection area of the Harmony Endpoint policy. It protects information stored on endpoint disks by encrypting the data so unauthorized users cannot easily read it if a device is lost, stolen, or accessed outside approved authentication controls. In the R81.20 Endpoint Web Management policy model, Data Protection includes Full Disk Encryption, while threat-focused capabilities are placed under Threat Prevention. This separation helps administrators manage data confidentiality controls independently from malware and threat-prevention settings.
Question 18. Which policy view is organized by protected scope?
- User-Based Policy
- Legacy Policy
- Computer-Based Policy
- ThreatWiki Policy
Correct Answer: 3. Computer-Based Policy
Explanation:
Computer-Based Policy organizes endpoint rules according to the protected computer scope. Each rule identifies the protected scope and the security blades activated for that scope. By contrast, User-Based Policy is arranged by blade and gives each blade its own rule set, similar to the SmartEndpoint view. Administrators can switch between these policy operation modes through Endpoint Settings. Computer-Based Policy is useful when security requirements are primarily determined by device groups rather than individual users.
Question 19. Which deployment method can use Microsoft Intune?
- Endpoint Security Client deployment
- Gateway clustering
- DNSSEC deployment
- SmartConsole upgrade
Correct Answer: 1. Endpoint Security Client deployment
Explanation:
Organizations that already manage devices through Microsoft Intune or Microsoft Endpoint Manager can use the same platform to deploy the Endpoint Security Client to managed endpoints. This gives administrators a familiar software-distribution mechanism and can simplify large-scale client rollout. Check Point includes documented procedures for deploying Harmony Endpoint through Intune as part of the R81.20 Endpoint management guidance. Third-party deployment tools are also supported for manually exported endpoint installation packages.
Question 20. What is included in a manual Endpoint package?
- Security Gateway image
- Gaia operating system
- SmartConsole only
- Initial Client
Correct Answer: 4. Initial Client
Explanation:
When an Endpoint Security package is downloaded for manual deployment, the Initial Client is already included, so administrators do not need to install it separately. The package can be distributed using third-party deployment software, shared network locations, email, or another suitable deployment mechanism. Administrators select the required components when creating the export package, and the installation program detects the computer type and installs the applicable components. Check Point notes that the Initial Client behavior described here applies to Endpoint Security packages and is not supported in the same way for Browser Security.