View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.
Question 41. What does Full Disk Encryption protect?
- DNS queries
- Browser bookmarks
- Local hard-disk data
- Gateway routing tables
Correct Answer: 3. Local hard-disk data
Explanation:
Full Disk Encryption protects data stored on endpoint hard disks by encrypting disk volumes and controlling access before the operating system starts. It combines disk encryption with boot protection and Smart Pre-boot authentication so unauthorized users cannot simply remove or access the drive to read protected information. Check Point positions Full Disk Encryption as a core Data Protection capability for desktop and laptop computers. It is especially important when devices are lost, stolen, or physically accessed by unauthorized people.
Question 42. What provides authentication before Windows starts?
- Smart Pre-boot
- Threat Emulation
- Appscan
- Anti-Bot
Correct Answer: 1. Smart Pre-boot
Explanation:
Smart Pre-boot provides authentication before the operating system starts on a computer protected by Full Disk Encryption. This prevents unauthorized users from accessing the encrypted operating-system volume simply by powering on the device. Only approved users who successfully authenticate can continue the boot process and access protected data. Check Point describes Full Disk Encryption as combining boot protection, Smart Pre-boot authentication, and disk encryption technologies. This layered design protects endpoint data even when an attacker has physical possession of the computer.
Question 43. What must a client send before FDE enforcement?
- Threat log
- Appscan XML
- Firewall policy
- Recovery file
Correct Answer: 4. Recovery file
Explanation:
Before Full Disk Encryption policy enforcement can begin, the endpoint must send a recovery file to the Endpoint Security Management Server. This is one of several requirements completed during the Full Disk Encryption deployment phase. Other requirements include communication with the server, receipt of the required policies, configured users, system-area preparation, and activation of Pre-boot. The recovery file is important because it allows administrators to recover protected data if normal boot or authentication fails later.
Question 44. What is the FDE Deployment Phase?
- Malware-scanning period
- Time before encryption policy enforcement
- Application inventory period
- Compliance-warning period
Correct Answer: 2. Time before encryption policy enforcement
Explanation:
The Full Disk Encryption Deployment Phase is the period between installation of the Full Disk Encryption component and the point at which its policy can be fully enforced. During this phase, the client must complete prerequisites such as contacting the management server, receiving policies, configuring users, sending the recovery file, creating the required system area, and preparing Pre-boot. Until these requirements are satisfied, Full Disk Encryption cannot fully protect the computer and Pre-boot cannot operate as intended.
Question 45. How much continuous free system space is required for FDE deployment?
- 32 MB
- 64 MB
- 256 MB
- 1 GB
Correct Answer: 1. 32 MB
Explanation:
Check Point documents a requirement for 32 MB of continuous free space on the client’s system volume during Full Disk Encryption deployment. The Full Disk Encryption service can automatically defragment the volume to create this continuous area when necessary. It also suspends Windows hibernation while disk encryption is underway. These preparation steps support creation of the required Full Disk Encryption system structures and help ensure that boot protection and encryption can be activated correctly.
Question 46. Which disk configuration is unsupported for FDE deployment?
- Standard local disk
- Single system volume
- Basic partition
- RAID
Correct Answer: 4. RAID
Explanation:
The referenced R81.20 Full Disk Encryption requirements state that clients must not use RAID for supported FDE deployment. Partitions that belong to stripe or volume sets are also listed as unsupported. These restrictions matter because Full Disk Encryption operates at a low level on disk structures and boot components. Administrators should verify endpoint storage configuration before deployment rather than assuming every disk arrangement is compatible. Unsupported storage layouts can prevent successful activation or create recovery risks.
Question 47. What is the default FDE encryption algorithm listed in R81.20?
- 3DES
- AES-CBC 256-bit
- Blowfish 256-bit
- XTS-AES 128-bit
Correct Answer: 2. AES-CBC 256-bit
Explanation:
The R81.20 Full Disk Encryption volume-encryption configuration lists AES-CBC with a 256-bit key as the default algorithm. Other supported options in that documentation include XTS-AES variants, Blowfish, CAST, and 3DES. The selected encryption algorithm determines how disk data is cryptographically protected. Administrators should normally follow Check Point guidance and organizational security requirements when choosing an algorithm rather than changing encryption settings without a defined technical or compliance reason.
Question 48. What does Custom Volume Encryption allow?
- Changing user passwords
- Scanning web downloads
- Selecting exact drives to encrypt
- Building application lists
Correct Answer: 3. Selecting exact drives to encrypt
Explanation:
Custom Volume Encryption allows administrators to specify exactly which drives or volumes Full Disk Encryption should protect. By default, Full Disk Encryption can encrypt detected local volumes, but some environments may require more selective handling. Administrators can also choose minimum encryption needed for Pre-boot or configure behavior for volumes discovered after the initial installation. These settings provide flexibility while preserving centralized policy control over which endpoint storage areas receive encryption protection.
Question 49. What does recovery media remove?
- Windows components
- User profiles
- Endpoint policies
- Disk encryption and boot protection
Correct Answer: 4. Disk encryption and boot protection
Explanation:
Full Recovery with Recovery Media decrypts the protected disk and removes Full Disk Encryption boot protection. Check Point states that recovery media restores the original boot procedure but does not remove Windows components. Recovery media contains only the information necessary to perform recovery and is based on a subset of the Full Disk Encryption database. This method is appropriate when the objective is to recover the encrypted disk fully and return its contents to a decrypted state.
Question 50. What is recovery media based on?
- A subset of the FDE database
- ThreatCloud
- An Appscan file
- A firewall log
Correct Answer: 1. A subset of the FDE database
Explanation:
Recovery media is a snapshot containing a subset of the Full Disk Encryption database on the client. It contains only the information required to perform the recovery procedure. Check Point notes that the recovery information is updated if additional volumes are encrypted or decrypted. Administrators use this recovery mechanism when normal boot access is unavailable and the disk must be decrypted and recovered. Protecting recovery information is therefore an important part of Full Disk Encryption administration.
Question 51. What does the Drive Slaving Utility provide?
- Threat prevention tuning
- Endpoint deployment
- Access to files on a failed encrypted disk
- Compliance monitoring
Correct Answer: 3. Access to files on a failed encrypted disk
Explanation:
The Full Disk Encryption Drive Slaving Utility allows administrators to access specified files and folders on a failed encrypted disk by attaching that disk to another supported host system. It can be used when the priority is obtaining data quickly rather than performing a complete disk recovery. After successful authentication, the unlocked protected disk can be accessed through Windows Explorer. If normal authentication does not work, a recovery file can be used to help unlock the disk.
Question 52. Which recovery method is generally faster for accessing files?
- Full recovery media
- Drive Slaving Utility
- Reinstalling Windows
- Threat Extraction
Correct Answer: 2. Drive Slaving Utility
Explanation:
Check Point notes that full recovery with recovery media takes more time than using the Full Disk Encryption Drive Slaving Utility when the goal is simply to access data quickly. Recovery media decrypts the failed disk and restores its boot procedure, while Drive Slaving allows administrators to unlock and access data from the disk through another host system. The appropriate choice depends on whether the administrator needs rapid file access or a complete recovery and decryption of the failed disk.
Question 53. What does Media Encryption protect?
- Removable storage data
- Router firmware
- DNS zones
- Gateway certificates
Correct Answer: 1. Removable storage data
Explanation:
Media Encryption protects sensitive information stored on removable storage devices by encrypting some or all of the device. Examples include USB storage, SD cards, external disks, and supported removable media. Organizations can use this protection to reduce data leakage risks when users copy business information to portable devices. Access can be controlled through authorization and policy settings, helping ensure that sensitive business information is not freely available if the removable media is lost or used on an unauthorized system.
Question 54. What does Port Protection control?
- Endpoint licensing
- Malware signatures
- Application inventory
- Access to physical ports and devices
Correct Answer: 4. Access to physical ports and devices
Explanation:
Port Protection controls access to physical endpoint ports and connected devices according to policy. Check Point documentation includes technologies such as USB and FireWire among the ports that can be controlled. Administrators can define which types of removable devices are permitted and which access rights apply. This helps prevent unauthorized devices from connecting to managed endpoint computers and reduces the risk of data leakage or unapproved removable-media usage. Port Protection works together with Media Encryption as part of the Data Protection feature set.
Question 55. How can encrypted removable media appear in Windows Explorer?
- As one hidden drive
- As two drives
- As a network share only
- As a browser extension
Correct Answer: 2. As two drives
Explanation:
Check Point describes encrypted removable media as appearing as two drives in Windows Explorer. One drive contains encrypted business data, while the other can remain unencrypted for non-business information. Policy rules can assign different access permissions to business and non-business areas. This arrangement lets organizations protect sensitive corporate information while still allowing approved general-purpose use of the removable device. The exact policy determines how the protected and unprotected areas can be accessed.
Question 56. What should be done before encrypting an external drive?
- Back up its data
- Disable Endpoint Security
- Delete all partitions
- Remove management policy
Correct Answer: 1. Back up its data
Explanation:
Check Point strongly recommends backing up files and data on an external storage device before applying Media Encryption. Media Encryption cannot detect hardware faults on the external drive, so an encrypted area could potentially be created on damaged storage. If that occurs, unexpected data loss can result. A current backup provides protection against this type of hardware-related failure. Encryption protects confidentiality, but it does not replace sound backup practices or protect against physical storage defects.
Question 57. Which protocol is used for Strong Authentication with Active Directory?
- RADIUS
- Kerberos
- TACACS+
- SNMP
Correct Answer: 2. Kerberos
Explanation:
Harmony Endpoint Strong Authentication with Active Directory uses the industry-standard Kerberos protocol. The endpoint client obtains an authentication ticket from Active Directory and sends that ticket to the Endpoint Security Management Server. The server then acknowledges successful authentication. This mode validates both the endpoint computer and the user rather than simply trusting them by name. Check Point states that Strong Authentication is available for endpoints that belong to Active Directory.
Question 58. When is Unauthenticated mode recommended?
- Production FDE only
- High-security deployments
- Evaluation purposes only
- Domain controllers only
Correct Answer: 3. Evaluation purposes only
Explanation:
In Unauthenticated mode, Endpoint Security clients and their users are trusted by name instead of being cryptographically authenticated with the management environment. Check Point recommends this mode for evaluation purposes only because it provides weaker identity assurance than Strong Authentication. In a production Active Directory environment, Strong Authentication uses Kerberos to verify clients and users connecting to the Endpoint Security Management Server. Organizations should therefore avoid treating Unauthenticated mode as the preferred production authentication architecture.
Question 59. What is required for FDE when Active Directory Authentication is used?
- The endpoint must join Active Directory
- The endpoint must use RAID
- Appscan must run first
- Threat Emulation must be disabled
Correct Answer: 1. The endpoint must join Active Directory
Explanation:
When Active Directory Authentication is used, Check Point states that Full Disk Encryption and Media Encryption & Port Protection are supported only on endpoint computers that are members of Active Directory. Endpoints outside Active Directory cannot use those protections under that authentication configuration. Administrators planning an environment with strong Active Directory authentication should therefore verify domain membership before deploying these Data Protection capabilities. This dependency is important during both architecture planning and troubleshooting.
Question 60. What should be installed before Media Encryption when scanner integration is required?
- Required directory scanner
- Appscan
- Threat Extraction
- Drive Slaving Utility
Correct Answer: 1. Required directory scanner
Explanation:
Check Point warns that the required Microsoft Entra ID or Active Directory scanner should be installed before Media Encryption when that scanner functionality is needed. If the scanner is installed after Media Encryption, functions such as Media Encryption, Remote Help, and automatic access may not operate correctly. Following the proper installation order prevents avoidable integration problems and supports correct identity-based access to removable media. Deployment planning should therefore include required directory-scanning components before Media Encryption is installed on endpoints.