Checkpoint 156-536 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.


Question 61. What does Anti-Exploit Prevent mode do?

  1. Logs only
  2. Updates signatures
  3. Scans removable media
  4. Stops the attack and suspends the application

Correct Answer: 4. Stops the attack and suspends the application

Explanation:

Anti-Exploit protects vulnerable applications from exploitation, including attacks that may use previously unknown vulnerabilities or techniques. In Prevent mode, Harmony Endpoint blocks the detected exploit attempt and suspends the application being attacked. This is different from Detect mode, which records information about the attack but does not stop it. Check Point recommends testing Anti-Exploit first in Detect mode before moving to Prevent mode across the organization. This staged deployment helps administrators identify legitimate applications that might require exclusions before enforcement becomes more restrictive.

Question 62. What does Anti-Exploit Detect mode do?

  1. Deletes the application
  2. Logs the attack without preventing it
  3. Encrypts suspicious files
  4. Blocks all processes

Correct Answer: 2. Logs the attack without preventing it

Explanation:

Anti-Exploit Detect mode identifies exploit activity and records information about the event, but it does not prevent the attack from proceeding. Detect mode is useful when administrators want to evaluate how the protection behaves in their environment before enabling stronger enforcement. Check Point’s recommended rollout begins Anti-Exploit in Detect mode on a test group, expands Detect mode to the organization, and then moves through Prevent testing before organization-wide prevention. This phased approach helps identify compatibility issues and false positives before enforcement affects all users.

Question 63. What does Behavioral Guard monitor?

  1. Suspicious process behavior
  2. DNS routing tables
  3. License usage
  4. Disk partitions

Correct Answer: 1. Suspicious process behavior

Explanation:

Behavioral Guard monitors endpoint activity for suspicious behavior that can indicate malicious processes or attack techniques. This is useful for identifying threats that may not yet have a known malware signature. Behavioral protection can work together with Anti-Ransomware and Forensics so suspicious activity can be detected, analyzed, and remediated. Check Point recommends initially enabling Anti-Ransomware and Behavioral Guard in Detect mode on a test group before moving toward Prevent mode. Behavioral analysis therefore adds another defensive layer beyond simple signature matching.

Question 64. What is the default Anti-Ransomware backup limit?

  1. 100 MB
  2. 500 MB
  3. 1 GB
  4. 10 GB

Correct Answer: 3. 1 GB

Explanation:

Harmony Endpoint Anti-Ransomware uses protected backup storage so files affected by ransomware can potentially be restored after malicious encryption is stopped. Check Point documents a default maximum Anti-Ransomware backup size of 1 GB on the endpoint disk. Administrators can adjust the maximum storage amount according to organizational requirements. The backup mechanism works together with behavioral detection and remediation capabilities to reduce the impact of ransomware. Backup storage should be considered when planning disk usage across large endpoint deployments.

Question 65. What is the default ransomware backup interval?

  1. 15 minutes
  2. 60 minutes
  3. 4 hours
  4. 24 hours

Correct Answer: 2. 60 minutes

Explanation:

The default Anti-Ransomware backup time interval is 60 minutes. Within this interval, each file is backed up only one time even if it changes several times. This reduces unnecessary backup activity while still maintaining protected copies that may be needed after ransomware activity. Administrators can modify the interval when required by organizational needs. The backup mechanism complements Anti-Ransomware prevention because the goal is not only to stop malicious encryption but also to help restore legitimate files affected during an attack.

Question 66. What is the default maximum backed-up file size?

  1. 5 MB
  2. 10 MB
  3. 20 MB
  4. 25 MB

Correct Answer: 4. 25 MB

Explanation:

Check Point documents 25 MB as the default maximum file size for files included in Anti-Ransomware backups. Administrators can change this value in the backup settings when larger business files need protection. Backup settings also let administrators modify which file types are included. These controls help balance ransomware recovery coverage with endpoint disk-space usage. Very broad backup settings can consume more storage, while settings that are too restrictive may leave important files without recoverable copies.

Question 67. How much disk space does Forensics use by default?

  1. Up to 1 GB
  2. Up to 100 MB
  3. Up to 10 GB
  4. Unlimited space

Correct Answer: 1. Up to 1 GB

Explanation:

Harmony Endpoint Forensics uses up to 1 GB of disk space on the endpoint by default for forensic information. The component collects detailed security activity that can later be analyzed as part of an attack investigation. Because forensic telemetry can consume local storage, administrators should understand the default usage when planning endpoint capacity. The collected information helps reconstruct attack sequences and understand files, processes, and actions involved in malicious activity. Forensics therefore provides deeper investigation context beyond the initial detection event.

Question 68. What can automatically start Forensics analysis?

  1. Successful login
  2. Policy installation
  3. Malicious event detection
  4. Normal shutdown

Correct Answer: 3. Malicious event detection

Explanation:

Forensics analysis can start automatically when another protection component detects a malicious event or file. Check Point specifically identifies sources such as Anti-Ransomware, Behavioral Guard, Check Point gateways, and some third-party security products. After the analysis completes, Harmony Endpoint can present the entire attack sequence in a Forensics Analysis Report. This automated relationship lets an initial security detection lead directly into deeper investigation without requiring an administrator to manually begin every forensic analysis.

Question 69. Why run periodic Anti-Malware scans?

  1. Find and treat suspicious files
  2. Update firewall routes
  3. Create encryption keys
  4. Inventory applications

Correct Answer: 1. Find and treat suspicious files

Explanation:

Periodic Anti-Malware scans check endpoint computers at regular intervals for suspicious or malicious files. Detected items can then be treated, quarantined, or deleted according to the configured policy. Check Point allows administrators to schedule these scans daily, weekly, or monthly. Periodic scanning supplements real-time on-access protection by providing recurring checks of endpoint storage. Check Point also recommends scheduling scans during non-active periods to reduce user impact and system load.

Question 70. Why randomize Anti-Malware scan times?

  1. Increase malware signatures
  2. Encrypt scan results
  3. Disable real-time protection
  4. Avoid many endpoints scanning together

Correct Answer: 4. Avoid many endpoints scanning together

Explanation:

Randomizing periodic Anti-Malware scan start times prevents large numbers of managed computers from beginning their scans simultaneously. If many endpoints start resource-intensive scanning at the same moment, network and infrastructure performance may be affected. Administrators can define a time window during which individual endpoints begin the scan at randomized times. This spreads scanning activity across the selected period and helps maintain more consistent performance while still ensuring that scheduled malware inspection occurs.

Question 71. Why are malware signatures updated regularly?

  1. To change user roles
  2. To rebuild deployment packages
  3. To detect newer threats
  4. To encrypt endpoints

Correct Answer: 3. To detect newer threats

Explanation:

Anti-Malware retrieves updated malware signatures at regular intervals so endpoint scanning can recognize recently identified threats. Check Point supports update intervals such as every two or four hours, with clients requesting malware signatures and scanning-engine updates from configured sources. Regular signature updates are important because malware evolves continuously and outdated detection databases may fail to identify newer known threats. Signature-based protection works together with behavioral and cloud-based technologies to provide broader protection against both known and unknown attacks.

Question 72. What is scanned by default on file access?

  1. Executables only
  2. All files opened or used
  3. Email only
  4. Archives only

Correct Answer: 2. All files opened or used

Explanation:

By default, Anti-Malware scans files when they are opened or used. This provides real-time protection by checking content when users or applications interact with it. Administrators can configure trusted processes as exceptions, but Check Point advises excluding a process only when it is fully trusted and known not to be malware. On-access scanning complements scheduled scans by continuously checking activity during ordinary endpoint use rather than waiting for the next periodic inspection.

Question 73. What does Detect Unusual Activity use?

  1. Disk encryption
  2. Static routing
  3. Application inventory
  4. Behavioral detection methods

Correct Answer: 4. Behavioral detection methods

Explanation:

The Detect Unusual Activity option uses behavioral detection methods to help protect endpoints from new threats that may not yet be represented in malware databases. Instead of relying only on known signatures, it looks for behavior that could indicate malicious activity. Check Point notes that this feature does not monitor trusted processes, which is another reason administrators should create trusted-process exceptions carefully. Behavioral analysis provides an additional defensive layer against emerging and previously unknown threats.

Question 74. What do Cloud Reputation Services improve?

  1. Scanning precision
  2. Disk capacity
  3. Active Directory replication
  4. Application deployment

Correct Answer: 1. Scanning precision

Explanation:

Cloud Reputation Services use cloud-based information to improve the precision of Anti-Malware scanning and monitoring. Reputation information can help classify files, web resources, and processes based on broader threat intelligence than is available locally. Check Point allows administrators to configure the connection timeout used when requesting reputation information. Reducing the timeout can improve performance but may also reduce security because the client may not receive a reputation verdict in time for a newly discovered malicious item.

Question 75. What does Anti-Malware Web Protection block?

  1. Full Disk Encryption
  2. Suspicious sites and malicious scripts
  3. Kerberos authentication
  4. Endpoint heartbeats

Correct Answer: 2. Suspicious sites and malicious scripts

Explanation:

Anti-Malware Web Protection helps prevent access to suspicious websites and execution of malicious scripts. It also scans files and packed executable content transferred over HTTP and can alert users when malicious content is found. This extends malware protection beyond files already stored on the endpoint by examining threats encountered through web activity. It should not be confused with the broader Harmony Endpoint URL Filtering policy, although both features contribute to safer web access.

Question 76. What does URL Filtering Prevent mode do?

  1. Logs without blocking
  2. Disables browser protection
  3. Blocks the site and logs the event
  4. Allows every category

Correct Answer: 3. Blocks the site and logs the event

Explanation:

When URL Filtering operates in Prevent mode, access to a site identified by the configured URL Filtering policy is blocked and the event is logged. This differs from Detect mode, where the event is logged but access is allowed. Administrators choose categories and can also maintain explicit deny-list entries for particular domains or URLs. Prevent mode is therefore appropriate when the organization wants URL classification decisions to be actively enforced rather than monitored only.

Question 77. What does URL Filtering Detect mode do?

  1. Blocks and deletes the browser
  2. Logs but allows access
  3. Encrypts the session
  4. Disables logging

Correct Answer: 2. Logs but allows access

Explanation:

URL Filtering Detect mode records activity that matches the configured URL policy but does not block the user from accessing the site. This is useful during policy evaluation because administrators can see which sites would have been affected before moving to Prevent mode. Check Point’s recommended rollout for URL Filtering begins with Detect mode on a test group and then the organization before moving through Prevent testing. This staged approach reduces the chance of unexpectedly blocking legitimate business websites.

Question 78. What does Network URL Filtering extend filtering to?

  1. Only Chrome
  2. Only email
  3. Only downloaded files
  4. URLs used by applications and processes

Correct Answer: 4. URLs used by applications and processes

Explanation:

When Enable Network URL Filtering is selected, Harmony Endpoint verifies and filters URLs accessed by applications and processes, not only URLs opened through a browser. Without this setting, URL Filtering applies to browser-based URL activity. Network URL Filtering therefore broadens coverage to software that communicates directly with web services or remote destinations. This can be important because malicious or unwanted applications may access URLs without using a traditional browser interface.

Question 79. Which wildcards are supported in the URL Deny List?

  1. % and _
  2. # and @
  3. * and ?
  4. + and –

Correct Answer: 3. * and ?

Explanation:

The Harmony Endpoint URL Deny List supports the * and ? wildcard characters. An asterisk can represent a string of characters, while a question mark represents a single character when used in a matching pattern. Administrators can add deny-list entries manually or import lists from CSV files. Deny-list entries automatically block the specified URLs or domains while other web traffic remains subject to the normal URL Filtering rules.

Question 80. What does Zero Phishing Prevent mode do?

  1. Blocks phishing sites and creates a log
  2. Logs only
  3. Disables web inspection
  4. Allows every suspicious site

Correct Answer: 1. Blocks phishing sites and creates a log

Explanation:

Zero Phishing checks website characteristics to determine whether a site is impersonating another site or attempting to steal personal information. In Prevent mode, users are blocked from accessing a site determined to be phishing, and a log is created for the malicious site. Detect mode logs the activity without blocking access, while Off disables phishing prevention. Administrators can also configure options such as whether users may dismiss the phishing alert and continue to the site.