Checkpoint 156-536 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.


Question 321. What is a Super Node?

  1. A secondary management server
  2. A client acting as an update proxy
  3. A dedicated firewall
  4. An Active Directory controller

Correct Answer: 2. A client acting as an update proxy

Explanation:

A Super Node is a Windows endpoint running a specially configured Harmony Endpoint client with proxy-like capabilities. It downloads signatures from configured sources, stores local copies, and serves those updates to other Endpoint Security clients. This reduces bandwidth usage and server workload, especially at remote sites. Check Point also notes that Super Nodes can support offline-update scenarios because only the Super Node requires direct connectivity to the update sources. The capability is available in both domain and workgroup environments.

Question 322. Which port does a Super Node use for proxying by default?

  1. 22
  2. 443
  3. 8080
  4. 3128

Correct Answer: 4. 3128

Explanation:

Check Point documents port 3128 as a default proxy port used by the Super Node. A Super Node also listens on port 4434 as part of its update-distribution functionality. The client acts as a lightweight proxy based on NGINX and provides cached signature updates to other endpoint clients. If one Super Node is unavailable, clients can try another configured Super Node before falling back to the original update source. This design improves scale and reduces repeated external update traffic.

Question 323. What is a key Super Node benefit?

  1. Reduced site bandwidth usage
  2. Stronger disk encryption
  3. More Active Directory users
  4. Larger endpoint logs

Correct Answer: 1. Reduced site bandwidth usage

Explanation:

One of the primary advantages of Super Nodes is reduced site bandwidth consumption. Instead of every endpoint downloading the same signatures independently from external update sources, a Super Node downloads them once and distributes them locally. Check Point also lists reduced server workload, lower infrastructure cost, and improved scalability as important Super Node advantages. This makes the feature particularly valuable at branch offices or locations with many endpoints sharing constrained WAN connectivity.

Question 324. What happens if all Super Nodes fail?

  1. Updates stop permanently
  2. The client is uninstalled
  3. The client uses the configured update source
  4. The endpoint reboots

Correct Answer: 3. The client uses the configured update source

Explanation:

When an Endpoint Security client needs an update, it first selects a Super Node from the configured list. If that node fails, the client tries another Super Node. If all configured Super Nodes fail, the client falls back to the update source defined in policy. This provides resilience and avoids making Super Nodes a single point of failure. Administrators can therefore reduce bandwidth while still allowing endpoints to retrieve updates directly when local distribution is unavailable.

Question 325. What does an Endpoint Policy Server reduce?

  1. Load on the management server
  2. Disk encryption strength
  3. User authentication quality
  4. Malware-signature accuracy

Correct Answer: 1. Load on the management server

Explanation:

External Endpoint Policy Servers handle much of the routine communication between endpoint clients and the Endpoint Security Management Server. This reduces management-server workload and lowers bandwidth requirements between sites. They can process heartbeats, synchronization requests, policy downloads, package downloads, Anti-Malware updates, and client logs. The management server remains responsible for central management and database-related functions, while policy servers offload frequent client communication.

Question 326. What should large remote sites use?

  1. More browser extensions
  2. Additional Full Disk Encryption users
  3. More uninstall tokens
  4. Multiple Endpoint Policy Servers

Correct Answer: 4. Multiple Endpoint Policy Servers

Explanation:

Check Point recommends at least one Endpoint Policy Server for each remote site and multiple Endpoint Policy Servers for larger sites when additional performance is needed. These servers reduce the amount of endpoint communication that must traverse the WAN to the central management server. They also help distribute frequently requested services such as policy downloads, updates, package delivery, heartbeats, and logging. This architecture improves scalability in large Harmony Endpoint deployments.

Question 327. What is an Endpoint Policy Server based on?

  1. Security Gateway
  2. Log Server
  3. Domain Controller
  4. Super Node

Correct Answer: 2. Log Server

Explanation:

An Endpoint Policy Server is implemented by installing a Check Point Log Server and configuring it to operate as an Endpoint Policy Server. It sits between endpoint clients and the Endpoint Security Management Server and handles much of their routine communication. Because it is also configured as a Log Server, client logs can be handled locally. This architecture lets organizations scale endpoint communication without requiring every request to reach the central management server directly.

Question 328. How does a client choose among multiple Policy Servers?

  1. Alphabetically
  2. By administrator name
  3. It selects the closest or fastest server
  4. Randomly forever

Correct Answer: 3. It selects the closest or fastest server

Explanation:

When several Endpoint Policy Servers exist, each Endpoint Security client analyzes which server is closest or fastest for communication and automatically connects to that server. This helps optimize communication paths and reduce unnecessary WAN traffic. The client does not require administrators to manually assign every endpoint to one policy server. The distributed model improves scalability by allowing endpoints to use the most efficient available policy server for routine communication.

Question 329. Which request can a Policy Server handle locally?

  1. Full Disk Encryption recovery database updates
  2. Primary-server installation
  3. SIC initialization
  4. Policy downloads

Correct Answer: 4. Policy downloads

Explanation:

Endpoint Policy Servers directly handle several frequent client requests without forwarding them to the Endpoint Security Management Server. These include heartbeat and synchronization requests, policy downloads, MSI and dynamic package downloads, Anti-Malware updates, and endpoint client logs. Database-specific messages such as Full Disk Encryption recovery information still need to reach central management. This division of responsibility is what allows Policy Servers to improve performance in large environments.

Question 330. What does Management High Availability provide?

  1. Redundancy and database backup
  2. Application scanning
  3. Threat Extraction
  4. Media encryption

Correct Answer: 1. Redundancy and database backup

Explanation:

Management High Availability provides redundancy and database backup for Check Point management servers. Synchronized servers maintain the same policies, rules, user definitions, objects, and system configuration information. If the primary management server fails or is taken offline for maintenance, the secondary server can take over. Endpoint Security integrates with this management HA architecture, allowing both network and endpoint management databases to benefit from the same redundancy model.

Question 331. How many Secondary servers are supported with Endpoint Security?

  1. Unlimited
  2. Two
  3. One
  4. Four

Correct Answer: 3. One

Explanation:

Check Point R81.20 documentation states that only one Secondary Endpoint Security Management Server is supported in an Endpoint Security High Availability environment. The first management server installed is the primary, and the additional supported secondary server provides redundancy. If the primary becomes unavailable, the secondary can become active. Because the supported architecture is limited to one secondary server, administrators should plan HA sizing and placement accordingly.

Question 332. What establishes trust between HA management servers?

  1. LDAP
  2. SIC
  3. ThreatCloud
  4. Appscan

Correct Answer: 2. SIC

Explanation:

Secure Internal Communication, or SIC, establishes trusted communication between Check Point management servers. When configuring a secondary Endpoint Security Management Server, administrators initialize SIC using the activation key created during configuration. The resulting trust allows the primary and secondary servers to communicate securely and synchronize management information. If trust initialization fails, administrators can use Test SIC Status to troubleshoot the connection.

Question 333. What must complete before Endpoint Policy Management is enabled on the Secondary?

  1. First database synchronization
  2. Appscan
  3. Full disk decryption
  4. Browser extension installation

Correct Answer: 1. First database synchronization

Explanation:

When adding a secondary management server, administrators first configure communication and install the management database without initially enabling Endpoint Policy Management on the secondary server. They must wait for peer initialization and full synchronization to finish. Only afterward should Endpoint Policy Management be enabled and the database installed again. This sequence ensures that the secondary server is correctly synchronized before it begins functioning as part of the Endpoint Security management architecture.

Question 334. Which files require manual HA synchronization?

  1. Only browser history
  2. Only log files
  3. Only policy text
  4. MSI packages and drivers

Correct Answer: 4. MSI packages and drivers

Explanation:

MSI files, dynamic packages, and Endpoint-related drivers are not automatically synchronized between management servers in an HA environment because they can be large. Administrators must manually copy the relevant files to standby servers whenever new packages or drivers are downloaded. Database synchronization alone is therefore not enough to keep all endpoint deployment resources consistent across the HA pair. Failing to copy these files can cause deployment problems after a failover.

Question 335. What can happen after HA failover with an old PAT version?

  1. Policies stop updating on clients
  2. Full Disk Encryption turns off
  3. ThreatCloud stops globally
  4. Every endpoint uninstalls

Correct Answer: 2. Policies stop updating on clients

Explanation:

After a standby management server becomes active, its Policy Assignment Table version can be older than the version already stored on clients. If the server’s PAT version is lower than the client’s PAT version, clients do not download new policy updates. Check Point provides the uepm patver get and uepm patver set commands to check and correct the server value. Administrators can also retrieve the last PAT version from a client if the original active server is unavailable.

Question 336. Which command reads the server PAT version?

  1. fw stat
  2. cpview
  3. uepm patver get
  4. vpn tu

Correct Answer: 3. uepm patver get

Explanation:

The command uepm patver get displays the current Policy Assignment Table version on the Endpoint Security Management Server. This is particularly useful after an HA failover when administrators need to verify that the new active server’s PAT version is not lower than the version already known by endpoint clients. If correction is required, uepm patver set can be used to update the value. PAT version consistency is important because clients can otherwise refuse policy updates.

Question 337. What deployment method is recommended for Windows clients?

  1. Manual email only
  2. Automatic Deployment Rules
  3. Drive Slaving
  4. Recovery media

Correct Answer: 2. Automatic Deployment Rules

Explanation:

For Windows endpoints, Check Point recommends automatic deployment using Deployment Rules. These rules allow preconfigured Endpoint Security packages to be downloaded and installed automatically on managed computers. Deployment status can then be monitored through management reporting. Manual deployment remains available through exported packages, third-party deployment tools, shared paths, or email, but Check Point identifies automatic deployment as the recommended strategy for managed Windows environments.

Question 338. When is manual deployment status visible?

  1. Before package creation
  2. Before installation starts
  3. When the package is emailed
  4. After successful installation

Correct Answer: 4. After successful installation

Explanation:

With manual endpoint deployment, management can see deployment status only after the package has been successfully installed on the endpoint. Manual distribution can use third-party deployment software, network shares, email, or other mechanisms, so the management server cannot track the package before the endpoint installation actually completes. This differs from automatic deployment workflows where management controls package delivery more directly.

Question 339. What is required to repair a Windows client locally?

  1. Original EPS.msi and PreUpgrade.exe
  2. ThreatCloud credentials
  3. Appscan XML
  4. Recovery media only

Correct Answer: 3. Original EPS.msi and PreUpgrade.exe

Explanation:

For local Windows client repair, Check Point requires the original EPS.msi and PreUpgrade.exe files to be present on the endpoint. The administrator then uses Programs and Features, selects Check Point Endpoint Security, and chooses Repair. Administrator privileges are required. Repair can also be initiated through Push Operations. This procedure is useful when installed client components are damaged but a complete uninstall and reinstall is not necessary.

Question 340. What should NOT happen during a client upgrade?

  1. Restarting before the upgrade finishes
  2. Updating policies afterward
  3. Using the server update schedule
  4. Clicking Update Now manually

Correct Answer: 1. Restarting before the upgrade finishes

Explanation:

Check Point explicitly warns users not to restart the endpoint while an Endpoint Security client upgrade is still in progress. The upgrade should be allowed to complete fully before rebooting. Clients normally receive updates automatically from the server and can also request updates manually through Update Now. During a policy update, only policies that changed since the previous update are downloaded. Interrupting an upgrade with an early restart can leave client components in an inconsistent or incomplete state.