Checkpoint 156-536 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.


Question 361. What does an Endpoint Policy Server mainly reduce?

  1. Endpoint disk usage
  2. Management server load
  3. Encryption strength
  4. Active Directory size

Correct Answer: 2. Management server load

Explanation:

An external Endpoint Policy Server reduces the workload placed on the Endpoint Security Management Server and can also reduce bandwidth usage between remote sites. It sits between endpoint clients and the central management server and handles many routine client communications locally. Check Point recommends external Endpoint Policy Servers for distributed or large environments because they let the central management server concentrate on management and database tasks instead of processing every heartbeat, policy request, update, and client log directly.

Question 362. What is an Endpoint Policy Server installed as first?

  1. Security Gateway
  2. Directory Scanner
  3. Domain Controller
  4. Log Server

Correct Answer: 4. Log Server

Explanation:

Check Point states that an Endpoint Policy Server is created by installing a Log Server and then configuring it to operate as an Endpoint Policy Server. The Endpoint Policy Server performs frequent endpoint communication tasks and is also configured as a Log Server by default. Administrators define these servers through SmartEndpoint under the Endpoint Servers management area. This architecture lets organizations scale endpoint communication without requiring every client to communicate directly with the central Endpoint Security Management Server for routine operations.

Question 363. What server should each remote site have?

  1. At least one Endpoint Policy Server
  2. One domain controller only
  3. One Security Gateway cluster
  4. One Threat Emulation appliance

Correct Answer: 1. At least one Endpoint Policy Server

Explanation:

Check Point recommends installing at least one external Endpoint Policy Server for each remote site in a distributed deployment. Larger sites may benefit from multiple Policy Servers to improve performance and distribute communication load. Local Policy Servers reduce the amount of routine endpoint traffic that must traverse slower or expensive WAN links toward the central management location. They can handle heartbeat traffic, policy downloads, package distribution, Anti-Malware updates, and endpoint logs locally while forwarding required management and monitoring information to the central server.

Question 364. How does a client choose among multiple Policy Servers?

  1. Randomly
  2. By alphabetical name
  3. By closest communication performance
  4. By user account

Correct Answer: 3. By closest communication performance

Explanation:

When several Endpoint Policy Servers exist, an Endpoint Security client analyzes the available servers and automatically communicates with the one considered closest or fastest for communication. This behavior distributes client load and helps optimize performance in geographically distributed environments. Administrators therefore do not normally need to manually assign every client to a particular Policy Server. The design helps large organizations scale endpoint management while reducing unnecessary WAN traffic and central management-server load.

Question 365. Which request can a Policy Server handle locally?

  1. Heartbeat requests
  2. Domain creation
  3. SmartConsole licensing
  4. Gateway routing

Correct Answer: 1. Heartbeat requests

Explanation:

Endpoint Policy Servers handle heartbeat and synchronization requests without forwarding each request to the Endpoint Security Management Server. They also handle policy downloads, client package downloads, Anti-Malware updates, and endpoint client logs. These are among the most frequent and bandwidth-intensive communications in an Endpoint Security environment. Processing them through external Policy Servers reduces central-server load and improves scalability, particularly when many endpoints are distributed across remote locations.

Question 366. Which data must a Policy Server forward centrally?

  1. Every Anti-Malware update
  2. Every heartbeat
  3. Every MSI package
  4. Full Disk Encryption recovery data

Correct Answer: 4. Full Disk Encryption recovery data

Explanation:

Component-specific information that must be stored in the central Endpoint Security database is forwarded from the Endpoint Policy Server to the Endpoint Security Management Server. Check Point gives Full Disk Encryption recovery information as a specific example. The Policy Server can handle many routine requests locally, but database-dependent data and central monitoring information still need to reach the management server. This division of responsibilities provides scalability without separating critical endpoint recovery and management information from the authoritative central database.

Question 367. What does a Directory Scanner import?

  1. Firewall rules
  2. AD users, groups, OUs, and computers
  3. Malware signatures
  4. Endpoint logs

Correct Answer: 2. AD users, groups, OUs, and computers

Explanation:

The Active Directory Directory Scanner imports organizational objects from Microsoft Active Directory into Endpoint Security management. Supported objects include users, groups, organizational units, and computers. Once these objects are present in Endpoint management, administrators can use the directory structure for policy assignment and endpoint organization. The scanner reproduces the relevant Active Directory hierarchy in the management database rather than forcing administrators to recreate every organizational object manually.

Question 368. What permissions does the Directory Scanner account need?

  1. Domain Admin only
  2. Write access to every object
  3. Full read access to required AD objects
  4. No directory permissions

Correct Answer: 3. Full read access to required AD objects

Explanation:

The user account associated with a Directory Scanner needs full read permissions to the Active Directory root, child containers and objects, and the Deleted Objects container. These permissions allow Endpoint Security to accurately discover the directory structure and identify changes between scans. The scanner does not require permission to modify normal directory objects simply to import their structure. Proper read access is important because incomplete permissions can result in missing users, computers, groups, or organizational units in Endpoint management.

Question 369. Which AD group type is not scanned?

  1. Security
  2. Domain Local
  3. Universal
  4. Distribution

Correct Answer: 4. Distribution

Explanation:

Check Point documentation states that the Active Directory Scanner does not scan groups of type Distribution. Administrators should therefore not expect Distribution groups to appear as normal scanned objects for Endpoint Security policy assignment. The scanner is intended to import supported directory objects that are useful for Endpoint management and policy targeting. Understanding these limitations helps administrators avoid troubleshooting an apparently missing group that is excluded by design rather than missing because of a connectivity or permission problem.

Question 370. What can one scanner instance cover?

  1. A full domain or part of a domain
  2. Only one computer
  3. Only deleted objects
  4. Only domain controllers

Correct Answer: 1. A full domain or part of a domain

Explanation:

A Directory Scanner instance defines the Active Directory path that should be scanned and how frequently the scan occurs. One instance can cover an entire Active Directory domain or only a specific portion, such as an organizational unit. If an organization needs to scan multiple domains or unrelated sections, multiple scanner instances can be configured. Administrators should avoid overlapping scanner definitions because Check Point prevents conflicting scans that cover the same directory area.

Question 371. What should be used for two separate AD domains?

  1. One overlapping OU scan
  2. A browser extension
  3. Separate scanner instances
  4. One malware policy

Correct Answer: 3. Separate scanner instances

Explanation:

When an organization needs to scan more than one Active Directory domain, Check Point recommends creating a separate Directory Scanner instance for each domain. For example, HOME and OFFICE domains would each have their own scanner instance. This lets each scanner use the correct directory path, credentials, domain controller details, and synchronization schedule. Separate instances also prevent ambiguity about which scan owns a particular part of the directory structure.

Question 372. What is Organization Distributed Scan by default?

  1. Disabled
  2. Enabled
  3. Unsupported
  4. Manual only

Correct Answer: 2. Enabled

Explanation:

Organization Distributed Scan is enabled by default in Endpoint Web Management. In this mode, each endpoint client reports its own directory path to the Security Management Server instead of relying on one dedicated client to scan the entire Active Directory. This method is simple and requires less scanner configuration, although only devices that already have Endpoint Security installed report their paths. Administrators can replace this model with Full Active Directory Sync when they need a more complete directory view.

Question 373. How often does a client report its path by default?

  1. Every 120 minutes
  2. Every 10 minutes
  3. Every 24 hours
  4. Every 30 seconds

Correct Answer: 1. Every 120 minutes

Explanation:

With Organization Distributed Scan, each Endpoint client sends its Active Directory path to the Security Management Server every 120 minutes by default. This allows Endpoint management to build organizational information from managed devices without configuring a dedicated full-directory scanner. A limitation is that only systems with Endpoint Security installed can report their information. Devices without the client are therefore not discovered through this distributed method.

Question 374. What happens when a new full AD scanner is created?

  1. All policies are deleted
  2. Strong Authentication is disabled
  3. Endpoint clients uninstall
  4. Organization Directory Scan is disabled

Correct Answer: 4. Organization Directory Scan is disabled

Explanation:

When a new Active Directory scanner is created for Full Active Directory Sync, the existing Organization Directory Scan is automatically disabled. The environment then relies on the configured scanner to collect directory information and send it to management. Full synchronization is useful when administrators need visibility beyond machines that already have Endpoint Security installed. The scanner configuration includes the selected scanner computer, AD credentials, domain controller, LDAP path, security settings, and synchronization interval.

Question 375. What is recommended for scanner-to-DC communication?

  1. Telnet
  2. SSL
  3. FTP
  4. TFTP

Correct Answer: 2. SSL

Explanation:

Check Point recommends enabling SSL communication between the Active Directory scanner and the Domain Controller. SSL protects the directory synchronization connection and reduces the risk of exposing authentication or directory information across the network. The scanner configuration provides a specific Use SSL communication option alongside the domain-controller address, port, LDAP path, credentials, and synchronization interval. Secure communication is especially important when directory information crosses network segments or remote-site links.

Question 376. What does automatic Windows deployment use?

  1. Browser extensions
  2. Recovery media
  3. Deployment rules
  4. Threat Extraction

Correct Answer: 3. Deployment rules

Explanation:

For Windows clients, Check Point identifies automatic deployment through Deployment rules as the recommended deployment strategy. Administrators first add client packages to the Endpoint Security Management Server repository and then use deployment rules to control which package is automatically downloaded and installed on selected endpoint computers. Deployment status can be monitored centrally. Manual deployment remains available when third-party software distribution, shared paths, email, or other delivery methods are preferred.

Question 377. What must be done before automatic client deployment?

  1. Add packages to the Repository
  2. Disable Active Directory
  3. Remove all policies
  4. Enable FDE recovery

Correct Answer: 2. Add packages to the Repository

Explanation:

Before deploying Endpoint Security clients through normal automatic deployment, administrators must add the required client packages to the Repository on the Endpoint Security Management Server. Deployment rules then reference those package versions and determine which endpoints receive them. Keeping the appropriate package in the repository ensures the management infrastructure can provide the expected client software. If the required version is unavailable, deployment cannot proceed normally.

Question 378. What must match for local-path deployment?

  1. User and hostname
  2. Scanner and domain
  3. Policy name and OU
  4. Deployment-rule and local-package versions

Correct Answer: 4. Deployment-rule and local-package versions

Explanation:

When deploying from a locally stored package, the client version specified in the Deployment rule must match the version of the package available at the configured local path or URL. Check Point states that if the versions do not match, the client is not deployed. This requirement prevents the rule from unintentionally installing a different Endpoint Security version from the one approved by policy. Administrators should therefore synchronize the package repository, deployment rule, and local package versions when designing local-distribution workflows.

Question 379. What can happen if no local MSI is found?

  1. FDE is disabled
  2. The endpoint is deleted
  3. The client can fall back to the server
  4. AD synchronization stops

Correct Answer: 3. The client can fall back to the server

Explanation:

Harmony Endpoint can be configured to fall back to the Endpoint Security Management Server when the expected MSI package is not found in the configured local paths or URLs. The option is called Enable Deployment from Server when no MSI was found in local paths. This fallback provides resilience when local distribution storage is unavailable or incorrectly populated, while still allowing organizations to use local package distribution to reduce WAN usage under normal conditions.

Question 380. What is a major benefit of local package deployment?

  1. Reduced central bandwidth usage
  2. Stronger disk encryption
  3. More AD permissions
  4. Longer heartbeat intervals

Correct Answer: 1. Reduced central bandwidth usage

Explanation:

Local package deployment allows Endpoint Security installation files and patches to be stored close to endpoint computers instead of requiring every device to download them directly from the central management server. This can reduce WAN bandwidth consumption and improve deployment efficiency in large or geographically distributed organizations. Administrators still upload matching packages to the central repository and create the appropriate Deployment Policy rule, while local paths or URLs provide the actual nearby software source.