Checkpoint 156-536 Practice Test Questions and Exam Dumps Part2 Q21-40

View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.


Question 21. When does the Default Deployment Policy apply?

  1. Only to servers
  2. Only to laptops
  3. Only to domain controllers
  4. When no other deployment rule applies

Correct Answer: 4. When no other deployment rule applies

Explanation:

The Default Policy in Harmony Endpoint deployment applies to endpoint devices that do not match another rule in the deployment rulebase. Administrators can modify the default rule as needed and create more specific deployment rules for selected computers, organizational units, or virtual groups. This design ensures that endpoints still receive a defined component deployment configuration even when they do not satisfy a more specific rule. Deployment rules are used to control Endpoint Security component packages and updates across managed devices.

Question 22. Which object is unsupported in Deployment Rules?

  1. Computer
  2. User
  3. Organizational Unit
  4. Virtual Group

Correct Answer: 2. User

Explanation:

Harmony Endpoint deployment rules do not support user objects. Administrators can instead create rules based on criteria such as specific computers, organizational units, Active Directory nodes, and Endpoint Security Virtual Groups. This reflects the purpose of deployment policy, which controls which endpoint components are installed on managed devices rather than assigning packages according to the currently logged-in user. Check Point also provides predefined virtual groups such as All Laptops and All Desktops for convenient device-based targeting.

Question 23. What is a Virtual Group used for?

  1. Grouping endpoint devices
  2. Storing encryption keys
  3. Creating administrator roles
  4. Managing DNS zones

Correct Answer: 1. Grouping endpoint devices

Explanation:

Endpoint Security Virtual Groups provide a way to organize endpoint devices so policies or deployment rules can target related computers. Check Point provides predefined groups such as All Laptops and All Desktops, and administrators can create additional groups for their own organizational needs. Virtual groups are useful when devices share common deployment or security requirements but do not belong to the same Active Directory organizational unit. Deployment rules can reference these groups to control which endpoint component packages are deployed or updated on their members.

Question 24. What is the default heartbeat interval?

  1. 10 seconds
  2. 30 seconds
  3. 60 seconds
  4. 5 minutes

Correct Answer: 3. 60 seconds

Explanation:

Harmony Endpoint clients periodically send heartbeat messages to the Endpoint Security Management Server. Check Point documents the default heartbeat interval as 60 seconds. The heartbeat is used to confirm connectivity and report information such as policy and compliance status. Administrators can change the interval through Endpoint Connection Settings, but the value should be selected carefully. Shortening it increases management-server load, while making it significantly longer can cause logs, reports, and compliance information to become less current.

Question 25. What is updated at each heartbeat?

  1. Disk encryption key
  2. Compliance state
  3. BIOS version
  4. DNS record

Correct Answer: 2. Compliance state

Explanation:

The endpoint computer’s compliance state is updated whenever the client sends a heartbeat to the Endpoint Security Management Server. This lets management track whether the endpoint currently satisfies required compliance rules. Heartbeat timing also affects how long a non-compliant endpoint remains in the About to be restricted state before entering the Restricted state. Because compliance decisions depend on heartbeat communication, excessively long intervals can delay status updates and make monitoring less current.

Question 26. What can a shorter heartbeat interval cause?

  1. Lower disk encryption
  2. Fewer policies
  3. Slower malware scanning
  4. More management load

Correct Answer: 4. More management load

Explanation:

A shorter heartbeat interval causes endpoint clients to contact the Endpoint Security Management Server more frequently. Check Point warns that this can increase management-server load, particularly in environments with many endpoints. Although frequent heartbeats provide more current connectivity, policy, and compliance information, they also create additional communication and processing overhead. Administrators should therefore balance operational visibility with management capacity. A longer interval reduces heartbeat frequency but can result in less up-to-date logs, reports, and compliance information.

Question 27. What does the Warn compliance state allow?

  1. Continued network access
  2. Automatic client removal
  3. Complete network isolation
  4. Policy deletion

Correct Answer: 1. Continued network access

Explanation:

The Warn state indicates that an endpoint is not compliant, but the user is still permitted to access network resources. The user should take the necessary steps to resolve the compliance problem. This differs from the Restricted state, where access to network resources is limited according to the restricted policy. Compliance states help administrators apply graduated responses rather than immediately isolating every endpoint that violates a requirement. Check Point also supports states such as Compliant, About to be restricted, Observe, and Restricted.

Question 28. What does the Restricted state mean?

  1. The endpoint is fully compliant
  2. No policy is installed
  3. Network access is restricted
  4. Logging is disabled

Correct Answer: 3. Network access is restricted

Explanation:

A Restricted endpoint is non-compliant and has restricted access to network resources. Check Point allows administrators to configure restricted policies that automatically take effect when an endpoint reaches this state. Before restriction occurs, the endpoint can enter the About to be restricted state for a defined number of heartbeat intervals, giving the user or remediation process time to correct the problem. This approach lets organizations enforce security requirements while providing a controlled transition from detection of non-compliance to restricted access.

Question 29. What does the Observe compliance action do?

  1. Logs without restricting the user
  2. Immediately isolates the endpoint
  3. Deletes non-compliant files
  4. Disables Endpoint Security

Correct Answer: 1. Logs without restricting the user

Explanation:

Observe records that a compliance rule has not been met without placing restrictions on the user. Check Point notes that users do not know about the Observe compliance state and their network access remains unaffected. This mode is useful when administrators want to measure the impact of a compliance rule before enforcing stronger actions. After reviewing results, administrators can decide whether to move to Warn or Restrict. Observe therefore provides visibility into compliance violations without immediately affecting user productivity.

Question 30. What can a Remediation object run?

  1. A routing protocol
  2. A DNS server
  3. A firewall cluster
  4. A program or script

Correct Answer: 4. A program or script

Explanation:

A Remediation object can run a specified program or script when an endpoint fails a compliance requirement. Check Point allows administrators to define a custom file, such as an executable or batch file, and specify the local download path used before execution. Remediation can help automatically correct common compliance problems instead of requiring manual intervention on every affected endpoint. Compliance rules can combine checks, actions, and remediation objects so an endpoint can be warned or restricted while corrective steps are performed automatically.

Question 31. When can Restrict be enforced?

  1. After one login only
  2. After a reboot only
  3. After predefined heartbeats
  4. Only after manual approval

Correct Answer: 3. After predefined heartbeats

Explanation:

A Restrict compliance action can move a non-compliant endpoint into the Restricted state after a predefined number of heartbeats. During the transition, the endpoint appears as About to be restricted, giving time for remediation or user action. Check Point documentation describes five heartbeats as the default value for the Restrict action. Once the threshold is reached, restricted policies can be applied automatically. Because heartbeat timing controls this transition, both the heartbeat interval and the configured heartbeat count affect how quickly restriction occurs.

Question 32. What is the Exclusions Center used for?

  1. Creating administrator accounts
  2. Excluding trusted items from protections
  3. Changing gateway routes
  4. Managing licenses

Correct Answer: 2. Excluding trusted items from protections

Explanation:

The Exclusions Center lets administrators define trusted processes, files, folders, certificates, URLs, domains, hashes, and other supported objects that should be excluded from selected Harmony Endpoint security inspections or actions. Exclusions are commonly used to resolve false positives, compatibility problems, or performance issues involving legitimate software. They should be narrowly defined because excluding an object can reduce security visibility or prevention. Check Point recommends creating exclusions only when administrators are confident that the excluded process or object is trustworthy.

Question 33. What does a quarantine exclusion prevent?

  1. Policy installation
  2. Threat detection
  3. Log creation
  4. File quarantine

Correct Answer: 4. File quarantine

Explanation:

A quarantine exclusion prevents a matching file or process from being placed into quarantine even when malware is detected. Check Point allows quarantine exclusions based on criteria such as certificate, file, folder, MD5 hash, SHA1 hash, and file extension. This is useful when a known trusted file is repeatedly detected incorrectly, but the exclusion must be used carefully because the file will remain available even if a supported protection component identifies it as malicious. The exclusion affects quarantine behavior rather than preventing all detection.

Question 34. What happens when a trusted process is excluded from inspection?

  1. Its file or network operations are not scanned
  2. It is automatically deleted
  3. It becomes encrypted
  4. It loses network access

Correct Answer: 1. Its file or network operations are not scanned

Explanation:

When a trusted process is excluded from relevant inspection, its file or network operations are not scanned by the applicable protection. Check Point recommends using process exclusions only when the administrator is confident the process is not malware. Typical reasons include false-positive detections or significant performance degradation after Anti-Malware is installed. Because an exclusion creates a security blind spot around the trusted application, administrators should avoid broad exclusions and define only the minimum scope required to solve the problem.

Question 35. What does Endpoint Anti-Bot block?

  1. Windows updates
  2. Bot communication with C&C sites
  3. Disk encryption
  4. LDAP authentication

Correct Answer: 2. Bot communication with C&C sites

Explanation:

Endpoint Anti-Bot identifies systems infected with bot malware and blocks communication with command-and-control infrastructure. Check Point explains that the component uses ThreatCloud intelligence to identify C&C addresses and classify suspicious IP, URL, and DNS resources. Preventing C&C communication can stop attackers from controlling the infected endpoint, downloading additional instructions, or stealing sensitive information. Anti-Bot therefore focuses on the network behavior of compromised systems rather than only scanning files for traditional malware signatures.

Question 36. What does Anti-Bot query ThreatCloud for?

  1. Disk encryption keys
  2. User passwords
  3. Resource classification
  4. Endpoint licenses

Correct Answer: 3. Resource classification

Explanation:

Endpoint Anti-Bot uses ThreatCloud to classify unidentified IP addresses, URLs, and DNS resources. ThreatCloud contains threat intelligence about large numbers of destinations and botnet communication patterns. When an endpoint attempts to communicate with an unknown resource, Anti-Bot can use this intelligence to determine whether the destination is associated with malicious command-and-control activity. This cloud-assisted classification helps the component respond to rapidly changing botnet infrastructure that would be difficult to track with a static local list alone.

Question 37. What is the default remediation confidence level?

  1. Never
  2. Medium & High
  3. High only
  4. Always

Correct Answer: 2. Medium & High

Explanation:

Check Point’s current Analysis & Remediation documentation states that the default confidence level for file remediation is Medium & High. High confidence means the system is almost certain that a file is malicious, while medium confidence means it is very likely malicious. Administrators can configure remediation to operate at Always, High, Medium & High, or Never, depending on the desired balance between aggressive remediation and false-positive risk. The selected setting determines the confidence level at which malicious files are automatically remediated.

Question 38. How is a quarantined malicious file stored?

  1. As plain text
  2. On the DNS server
  3. In browser cache
  4. Encrypted and compressed

Correct Answer: 4. Encrypted and compressed

Explanation:

The Endpoint Security remediation service can quarantine a malicious file by terminating its running process, encrypting the file, compressing it, and storing it with associated metadata in a protected folder. This prevents normal execution or access while preserving information that may be needed for investigation or later management. Several Endpoint components can request quarantine through the common remediation service. The process is designed to contain malicious content while maintaining controlled administrative access to quarantine information.

Question 39. What does Server Optimization apply?

  1. New network routes
  2. Additional administrator accounts
  3. Predefined server-specific exclusions
  4. New DNS zones

Correct Answer: 3. Predefined server-specific exclusions

Explanation:

Endpoint for Server Optimization applies predefined exclusions and server-specific process settings appropriate to selected Windows server roles. Supported examples include domain controllers, Exchange servers, SQL servers, DNS servers, web servers, file servers, and several other roles. These optimizations are based on Check Point and Microsoft recommendations and are intended to help endpoint protection operate correctly without unnecessarily interfering with important server workloads. Administrators enable the feature for the relevant Threat Prevention policy rule and select the server roles requiring optimization.

Question 40. How do mixed OS deployment groups behave?

  1. Only applicable OS members are used
  2. The entire rule fails
  3. Only Windows members are used
  4. Only macOS members are used

Correct Answer: 1. Only applicable OS members are used

Explanation:

When a deployment group contains both Windows and macOS objects, the rule intersects the group with the members applicable to that rule. This lets administrators work with mixed groups without requiring every rule to apply identically to every operating system. Check Point deployment rules support Windows and macOS endpoint clients, while Linux is not supported by this deployment-rule mechanism in the referenced R81.20 documentation. Understanding how mixed groups are evaluated helps administrators predict which devices receive a particular component package or update.