Checkpoint 156-536 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.


Question 201. What does the Endpoint Security Management Server store?

  1. Only DNS records
  2. Only malware signatures
  3. Only gateway routes
  4. Endpoint policies and databases

Correct Answer: 4. Endpoint policies and databases

Explanation:

The Endpoint Security Management Server contains endpoint policy management functions and the Endpoint Security database. The database stores policies enforced on endpoint clients, computer and user objects, licensing information, and endpoint monitoring data. The management server also communicates with managed clients to provide policies, component updates, and protection information. It is therefore the central management element of an on-premises Endpoint Security environment rather than simply a logging or malware-signature repository.

Question 202. What does the Directory Scanner obtain?

  1. Malware samples
  2. Active Directory structure and contents
  3. Firewall logs
  4. Encryption keys

Correct Answer: 2. Active Directory structure and contents

Explanation:

The Directory Scanner obtains the organizational structure and contents of Active Directory for use by Endpoint Security. This information allows administrators to work with directory-based users, computers, groups, and organizational structures when assigning security policy. It is part of the Endpoint Security Management Server architecture and supports integration with the organization’s existing directory. Rather than manually recreating every user and computer object, Endpoint Security can use synchronized directory information for policy targeting and administration.

Question 203. What does an Endpoint Policy Server reduce?

  1. Management Server communication load
  2. Disk encryption strength
  3. Threat Emulation coverage
  4. User authentication

Correct Answer: 1. Management Server communication load

Explanation:

External Endpoint Policy Servers reduce the communication workload placed on the Endpoint Security Management Server. They sit between endpoint clients and central management and handle many frequent or bandwidth-intensive requests locally. This leaves the main management server more available for other management tasks and can also reduce bandwidth consumption between remote locations and the central site. Check Point recommends distributed deployments with dedicated Endpoint Policy Servers, particularly for remote or larger sites where many clients communicate with management.

Question 204. What is an Endpoint Policy Server based on?

  1. Security Gateway
  2. Domain Controller
  3. Log Server
  4. SmartConsole workstation

Correct Answer: 3. Log Server

Explanation:

An Endpoint Policy Server is implemented by installing a Check Point Log Server and configuring it to operate as an Endpoint Policy Server. It then provides endpoint-specific communication services such as policy downloads, heartbeat processing, client package delivery, Anti-Malware updates, and client log handling. This architecture allows endpoint communication to be distributed without requiring every request to be processed directly by the Endpoint Security Management Server.

Question 205. What does an Endpoint Policy Server handle locally?

  1. Full Disk Encryption recovery only
  2. Heartbeats and synchronization
  3. Active Directory creation
  4. Gateway NAT rules

Correct Answer: 2. Heartbeats and synchronization

Explanation:

Endpoint Policy Servers handle frequent client requests such as heartbeat and synchronization messages without forwarding each one to the central Endpoint Security Management Server. They also handle policy downloads, endpoint installation package downloads, Anti-Malware updates, and client logs. Processing these requests locally reduces WAN bandwidth and central management load. Information that must be stored centrally, such as certain component-specific database information and monitoring data, is still forwarded to the management server.

Question 206. What can clients download from a Policy Server?

  1. Active Directory database
  2. Security Gateway image
  3. Gaia operating system
  4. Endpoint policies and packages

Correct Answer: 4. Endpoint policies and packages

Explanation:

Endpoint Policy Servers can provide policy downloads and Endpoint Security client packages to managed endpoints. Check Point specifically identifies dynamic EXE packages and Windows Installer MSI packages among the files that can be delivered through an Endpoint Policy Server. This reduces the need for every endpoint to retrieve large installation or policy data directly from the central management server, which is particularly useful for remote sites with many clients.

Question 207. How does a client choose among multiple Policy Servers?

  1. It selects the closest server
  2. It always uses the oldest server
  3. It selects randomly
  4. It uses the Domain Controller

Correct Answer: 1. It selects the closest server

Explanation:

When several Endpoint Policy Servers are available, each Endpoint Security client analyzes the available servers and automatically communicates with the server considered closest, meaning the one expected to provide the fastest communication. This behavior improves performance and helps reduce unnecessary traffic across remote network links. It also allows organizations with several sites to distribute endpoint communication without manually assigning every individual client to a specific Policy Server.

Question 208. What does Check Point recommend for each remote site?

  1. One Security Gateway only
  2. One Domain Controller only
  3. At least one Endpoint Policy Server
  4. One SmartConsole per user

Correct Answer: 3. At least one Endpoint Policy Server

Explanation:

Check Point recommends installing at least one external Endpoint Policy Server for each remote site in a distributed Endpoint Security deployment. For larger locations, multiple Policy Servers can be deployed to improve performance and distribute communication load. This design reduces bandwidth requirements between remote endpoints and the central management location while keeping the Endpoint Security Management Server available for policy management, database functions, and other central tasks.

Question 209. What happens if no external Policy Server exists?

  1. Management Server handles client communication
  2. Endpoint clients stop working
  3. Policies cannot be installed
  4. Active Directory is disabled

Correct Answer: 1. Management Server handles client communication

Explanation:

If no external Endpoint Policy Servers are configured, the Endpoint Security Management Server manages all endpoint client requests and communication itself. The management server includes an Endpoint Policy Server function by default, so an external server is not mandatory for basic operation. External Policy Servers become valuable as the environment grows or includes remote locations because they distribute the communication workload and reduce traffic to central management.

Question 210. Which policy view is arranged by protected scope?

  1. User-Based Policy
  2. Threat Prevention view
  3. Legacy view
  4. Computer-Based Policy

Correct Answer: 4. Computer-Based Policy

Explanation:

Computer-Based Policy arranges the Endpoint Security policy according to protected computer scope. Each rule contains the scope to be protected and the endpoint blades enabled for that scope. User-Based Policy instead organizes configuration by individual security blade, with each blade having its own rules. Administrators can change between these policy operation modes in Endpoint Settings. Computer-Based Policy is useful when endpoint security requirements are primarily determined by groups of computers or devices.

Question 211. Which policy view is arranged by blade?

  1. Deployment Policy
  2. Computer-Based Policy
  3. User-Based Policy
  4. Global Settings

Correct Answer: 3. User-Based Policy

Explanation:

User-Based Policy organizes Endpoint Security policy by security blade. Each blade has its own rule set, similar to the policy organization used in SmartEndpoint. Computer-Based Policy instead organizes rules around the protected device scope. These two views provide different ways to manage the same endpoint protection environment depending on whether administrators prefer a blade-oriented or device-oriented policy workflow. The selected operation mode can be changed through Endpoint Settings.

Question 212. Where is Policy Operation Mode changed?

  1. SmartView Monitor
  2. Endpoint Settings
  3. Gaia Portal
  4. ThreatCloud

Correct Answer: 2. Endpoint Settings

Explanation:

Administrators switch between User-Based Policy and Computer-Based Policy through Endpoint Settings under the Policy Operation Mode configuration. Changing the mode changes how policy rules are presented and organized in the Endpoint Web Management Console. User-Based mode groups rules by blade, while Computer-Based mode groups them by protected computer scope. Understanding where this setting resides is useful when administrators encounter a policy interface that looks different from the expected SmartEndpoint-style organization.

Question 213. Which component is computer-only by default and design?

  1. URL Filtering
  2. Compliance
  3. Application Control
  4. Full Disk Encryption

Correct Answer: 4. Full Disk Encryption

Explanation:

Full Disk Encryption policy is enforced at the computer level rather than per user. This makes sense because disk encryption protects the physical storage volumes of the device itself, regardless of which individual user is currently signed in. Check Point’s Endpoint Security rule-type documentation identifies Full Disk Encryption as computer-only. Other components, such as Anti-Malware, URL Filtering, Compliance, Firewall, and Application Control, can support computer-based or user-based rule handling depending on policy configuration.

Question 214. Which component is user-only?

  1. OneCheck User Settings
  2. Full Disk Encryption
  3. Anti-Ransomware
  4. Forensics

Correct Answer: 1. OneCheck User Settings

Explanation:

OneCheck User Settings uses user-only rule assignment. Unlike Full Disk Encryption, which is computer-only, OneCheck settings are associated specifically with users. Check Point’s rule-type matrix shows that other protections can vary between user and computer rule types, but OneCheck User Settings is explicitly user-oriented. Understanding rule types is important when troubleshooting why a policy applies according to a user identity rather than the endpoint computer object.

Question 215. Which components are computer-only?

  1. Firewall and URL Filtering
  2. Anti-Ransomware, Behavioral Guard, and Forensics
  3. Application Control and Compliance
  4. Media Encryption only

Correct Answer: 2. Anti-Ransomware, Behavioral Guard, and Forensics

Explanation:

Check Point identifies Anti-Ransomware, Behavioral Guard, and Forensics as computer-only components in the Endpoint Security rule-type matrix. Their protections monitor and analyze activity occurring on the endpoint device itself, so policy is tied to the computer rather than to an individual user. By contrast, several other components can use either computer-based or user-based rules depending on administrator configuration. Recognizing the supported rule type prevents administrators from attempting unsupported user-based targeting for these behavioral protection components.

Question 216. What does Connected Policy represent?

  1. Policy for online managed clients
  2. Policy for deleted endpoints
  3. Policy for unmanaged browsers
  4. Policy for gateways only

Correct Answer: 3. Policy for online managed clients

Explanation:

Endpoint Security supports policy types based on the connection state of the endpoint. A Connected policy applies when the endpoint client is considered connected to the management environment. Check Point notes that a Connected policy can be defined for all Endpoint Security components, while certain components can also support Disconnected and Restricted policies. This lets administrators apply different security behavior depending on whether an endpoint can communicate with management or whether compliance restrictions are in effect.

Question 217. What does Connection Awareness determine?

  1. Malware signature age
  2. Whether a client is connected or disconnected
  3. Encryption algorithm
  4. Appscan output format

Correct Answer: 2. Whether a client is connected or disconnected

Explanation:

Connection Awareness allows administrators to configure criteria that determine whether endpoint clients should be considered connected or disconnected. Based on this connectivity state, Harmony Endpoint can change the policy type applied to the device. This capability was added to the R81.20 Harmony Endpoint Web UI and helps organizations define connectivity based on their own network environment rather than relying only on a fixed assumption about client reachability.

Question 218. What does the management database store?

  1. Only Active Directory passwords
  2. Only malware files
  3. Only browser history
  4. Endpoint monitoring data

Correct Answer: 4. Endpoint monitoring data

Explanation:

The Endpoint Security database stores several categories of management information, including endpoint policies, user and computer objects, licensing information, and endpoint monitoring data. This monitoring information helps administrators understand the status of managed endpoint devices while central policy data determines what protections those clients should enforce. The database therefore supports both configuration and operational monitoring rather than functioning only as a policy repository.

Question 219. What can a Domain object define in Firewall policy?

  1. A host or DNS domain by name
  2. A disk volume
  3. A malware signature
  4. A user password

Correct Answer: 3. A host or DNS domain by name

Explanation:

Harmony Endpoint Firewall supports Domain objects that identify a host or DNS domain by name without requiring administrators to specify the corresponding IP address manually. Domain objects can be used in the source and destination columns of Firewall policy. This is useful for services whose IP addresses may change over time while their DNS names remain consistent. Administrators can also group reusable network objects to simplify Firewall rule management and reduce repetitive configuration.

Question 220. What BEST improves a large remote-site deployment?

  1. Deploy Endpoint Policy Servers near clients
  2. Send all traffic to one distant server
  3. Remove Policy Servers
  4. Disable client heartbeats

Correct Answer: 1. Deploy Endpoint Policy Servers near clients

Explanation:

A distributed architecture with Endpoint Policy Servers close to endpoint clients improves scalability and reduces communication load across remote links. Policy Servers handle heartbeats, synchronization, policy downloads, installation packages, Anti-Malware updates, and client logs locally. Check Point recommends at least one Policy Server for each remote site and multiple servers for larger sites. This approach reduces bandwidth requirements and keeps the central Endpoint Security Management Server more available for policy, database, and management operations.