View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.
Question 141. Which are the two predefined Access Zones?
- Internal and External
- LAN and WAN
- Private and Public
- Trusted and Internet
Correct Answer: 4. Trusted and Internet
Explanation:
Harmony Endpoint Firewall uses two predefined Access Zones: the Trusted Zone and the Internet Zone. The Trusted Zone contains network locations the organization explicitly considers trusted, while network locations not included there automatically belong to the Internet Zone. Administrators should configure Access Zones before creating Firewall policy rules because the zones can be referenced as source or destination objects. Access Zones provide a convenient way to classify network locations without creating separate Firewall logic for every individual address.
Question 142. Where are untrusted network locations placed automatically?
- Local Zone
- Internet Zone
- Management Zone
- VPN Zone
Correct Answer: 2. Internet Zone
Explanation:
Any network object or location that is not explicitly included in the Trusted Zone is automatically considered part of the Internet Zone. This behavior simplifies Firewall policy because administrators primarily define which networks should be trusted, while everything else receives the less-trusted Internet classification. The Trusted Zone should therefore contain only network resources that endpoint applications genuinely need to communicate with under trusted conditions. Incorrectly adding broad networks to the Trusted Zone can weaken endpoint Firewall restrictions.
Question 143. Access Zones rules are primarily what type?
- Computer-centric
- User-centric
- Application-centric
- Gateway-centric
Correct Answer: 1. Computer-centric
Explanation:
Access Zones rules are computer-centric rather than user-centric. This means the zone configuration applies according to the endpoint computer rather than the individual user logged into that computer. Administrators define which network objects are considered trusted for the protected endpoint, and the Firewall policy can then use those zones when deciding whether traffic should be allowed or blocked. This distinction is important when designing policies because user identity does not determine which Access Zone applies to the endpoint device.
Question 144. If multiple Trusted Zones apply, which one is enforced?
- First zone
- Largest zone
- Last applicable zone
- All zones together
Correct Answer: 3. Last applicable zone
Explanation:
A computer can have only one enforced Trusted Zone. If more than one Access Zones policy rule applies and several Trusted Zones could therefore affect the same endpoint, Check Point states that only the last applicable Trusted Zone is enforced. Administrators should consider rule ordering carefully when several policies can match the same computer. Unexpected Trusted Zone behavior can result if a later rule overrides the zone administrators expected to be active. Reviewing the Access Zones rulebase is therefore an important troubleshooting step.
Question 145. What is LocalMachine_Loopback?
- 127.0.0.1
- 0.0.0.0
- 255.255.255.255
- 169.254.0.1
Correct Answer: 1. 127.0.0.1
Explanation:
LocalMachine_Loopback represents the endpoint computer’s loopback address, 127.0.0.1. Check Point notes that the endpoint must always have access to its own loopback address. Local applications frequently use this interface for communication between processes on the same computer. Software that changes or hides the normal loopback address, such as some personal proxy tools, can interfere with expected behavior. The loopback object is therefore an important built-in component of the Endpoint Firewall and Access Zones configuration.
Question 146. What do inbound Firewall rules control?
- Outgoing DNS only
- Application installation
- Disk encryption
- Traffic reaching the endpoint
Correct Answer: 4. Traffic reaching the endpoint
Explanation:
Inbound Firewall rules determine which network traffic is permitted to reach the endpoint computer. The endpoint is effectively the local destination for every inbound rule. Administrators can allow all inbound traffic or limit incoming connections to trusted zones and required connectivity services. Check Point can automatically create the rules needed for the selected inbound action, while administrators can further modify the rulebase when more granular behavior is necessary. Inbound controls help protect endpoints from unsolicited or unauthorized network connections.
Question 147. Why is there no Destination column in classic inbound rules?
- Destination is unknown
- Destination is always the endpoint
- Only DNS is allowed
- Destination is always Internet
Correct Answer: 2. Destination is always the endpoint
Explanation:
In the classic R81.20 inbound Firewall rulebase, there is no separate Destination column because the destination of inbound traffic is always the endpoint computer itself, also called localhost in the documentation. Administrators instead focus on the source, network service, action, and tracking behavior. This simplifies inbound rule configuration because the protected computer is already understood to be the target. Outbound rules have the opposite structure: their source is always the endpoint computer.
Question 148. Why is there no Source column in outbound rules?
- Source is Internet
- Source is hidden
- Source is always the endpoint
- Source is the gateway
Correct Answer: 3. Source is always the endpoint
Explanation:
Outbound Firewall rules control traffic leaving the protected endpoint. Because the endpoint itself is always the source of outbound traffic, the classic outbound rulebase does not require a separate Source column. Administrators instead specify destinations, services, actions, and tracking options. Check Point provides actions that can allow all outbound traffic or permit traffic to trusted zones together with common Internet protocols. Additional rules can be added when more specific outbound restrictions are required.
Question 149. What does the restrictive default outbound option allow?
- No outbound traffic
- Internet traffic only
- Trusted traffic only
- Trusted zones and common Internet protocols
Correct Answer: 4. Trusted zones and common Internet protocols
Explanation:
Check Point provides an outbound action that permits all traffic to Trusted Zones while allowing common Internet protocols toward the Internet. This offers tighter control than simply allowing any outbound connection. The automatically generated rulebase implements the selected behavior, and administrators can review or modify individual rules if necessary. This approach lets normal business communication continue while reducing unrestricted network access from endpoint computers. More specific rules can be added for applications or services that require exceptions.
Question 150. What does Firewall Track = Log do?
- Records rule enforcement
- Blocks the endpoint
- Disables the rule
- Shows no event
Correct Answer: 1. Records rule enforcement
Explanation:
The Log tracking option records Firewall rule enforcement in the Endpoint Client Log Viewer. Logging gives administrators evidence about which traffic matched a rule and can help diagnose unexpected connectivity or verify that policy is working correctly. Check Point advises against enabling logging on broad rules that accept or drop all traffic because doing so can generate unnecessarily large volumes of logs. Client Settings must also permit log upload when centralized log collection is required.
Question 151. What does Firewall Track = Alert do?
- Drops traffic silently
- Disables logging
- Shows a message and records the event
- Changes the Trusted Zone
Correct Answer: 3. Shows a message and records the event
Explanation:
The Alert tracking option displays a message on the endpoint computer and records the rule enforcement in the Endpoint Client Log Viewer. It is useful when administrators want the user to be made aware that specific network behavior has triggered a Firewall rule. Check Point notes that the relevant Network Protection alert setting in Client Settings must permit Firewall alerts for this functionality. Alerting should be used selectively so users are not overwhelmed by frequent messages generated from routine traffic.
Question 152. What does Firewall Track = None create?
- Alert only
- No log or alert
- Log only
- Quarantine event
Correct Answer: 2. No log or alert
Explanation:
When Track is set to None, the Firewall rule is enforced without creating log or alert messages. This can be appropriate for routine rules where administrators do not need detailed visibility and want to avoid unnecessary logging overhead. The rule’s Allow or Drop action still applies normally. By comparison, Log records enforcement in the Endpoint Client Log Viewer, while Alert both records the event and displays a notification on the endpoint when the required client alert settings are enabled.
Question 153. What must be enabled for client Firewall log uploads?
- Enable log upload
- Full Disk Encryption
- Threat Extraction
- Password Reuse Protection
Correct Answer: 1. Enable log upload
Explanation:
To use centralized Firewall logs, the Client Settings policy must have Enable log upload selected in the Log Upload action. Firewall tracking can generate local events, but centralized collection depends on the appropriate upload configuration. Check Point also requires the Firewall alert option under Network Protection Alerts when administrators want endpoint alert messages. Correctly configuring these supporting Client Settings is important when troubleshooting situations where Firewall rules work but expected logs or user alerts do not appear.
Question 154. What does “Allow wireless connections when connected to the LAN” permit?
- VPN only
- IPv6 only
- Hotspot registration only
- Simultaneous wireless connectivity
Correct Answer: 4. Simultaneous wireless connectivity
Explanation:
When this setting is selected, endpoint users can connect to wireless networks while the endpoint is also connected to the LAN. Clearing the setting prevents simultaneous wireless connectivity while a LAN connection exists. This control is intended to reduce the possibility that a device connected to a trusted corporate wired network is simultaneously exposed to an untrusted wireless network. Administrators should decide whether simultaneous connectivity is necessary for business operations or whether the additional network path creates an unacceptable security risk.
Question 155. What does “Allow hotspot registration” do?
- Blocks public Wi-Fi
- Bypasses Firewall for hotspot connection
- Enables Full Disk Encryption
- Disables browsers
Correct Answer: 2. Bypasses Firewall for hotspot connection
Explanation:
Allow hotspot registration lets users connect through public hotspots such as those found in hotels or airports. Check Point explains that the Firewall is bypassed as necessary to let the user complete hotspot network registration. Without this option, the Firewall could prevent the initial captive-portal communication required before normal Internet connectivity becomes available. Administrators should enable the setting only when users legitimately need public hotspot access, because bypassing normal Firewall restrictions temporarily changes how network traffic is handled.
Question 156. What does “Block IPv6 network traffic” do?
- Blocks IPv4 only
- Blocks DNS only
- Blocks IPv6 traffic to endpoints
- Blocks LAN authentication
Correct Answer: 3. Blocks IPv6 traffic to endpoints
Explanation:
The Block IPv6 network traffic setting controls whether IPv6 traffic is blocked to protected endpoint devices. When selected, IPv6 traffic is blocked; clearing the setting permits IPv6 traffic. This control is useful in organizations that do not intentionally use IPv6 and want to reduce exposure through a protocol that may otherwise bypass IPv4-focused policies or monitoring. Administrators should verify their network requirements before blocking IPv6 because modern systems and applications may rely on it in some environments.
Question 157. What is the default Remote Access Firewall policy source?
- Desktop Security Policy
- Above Endpoint Firewall policy
- Internet Zone only
- Local Windows Firewall
Correct Answer: 2. Above Endpoint Firewall policy
Explanation:
When Remote Access is in use, the default setting is to enforce the Firewall policy from the Endpoint Firewall policy described above in the Harmony Endpoint configuration. Check Point also provides the option to use a Remote Access Desktop Security Policy, which can be useful for environments that previously used Endpoint Security VPN and want to retain a legacy Desktop Policy. Understanding which policy source is active is important when troubleshooting VPN-connected endpoints that appear to enforce different network rules than expected.
Question 158. What is the default Connection Awareness mode?
- Connected to router
- Connected to DNS
- Connected to website
- Connected to management
Correct Answer: 4. Connected to management
Explanation:
The default Connection Awareness mode considers an endpoint Connected when it can communicate with the Endpoint Security Management Servers. Administrators can alternatively define other network targets, such as a router or web server, and determine connected status from reachability to those targets. Connection Awareness influences whether the endpoint enforces its Connected or Disconnected policy. It should not be confused with whether the computer itself is simply online or offline; the feature evaluates connectivity to defined management or network targets.
Question 159. How often can Connection Awareness send HTTP GET checks?
- Every 5 seconds
- Every 10 seconds
- Every 30 seconds
- Every 5 minutes
Correct Answer: 3. Every 30 seconds
Explanation:
Check Point documents that Connection Awareness can trigger HTTP GET requests to the configured server at intervals of 30 seconds when determining whether the endpoint should be treated as Connected or Disconnected. Administrators can configure a network target such as a web server or router instead of relying only on connectivity to Endpoint Security Management. The resulting connection state determines policy assignment. Connection Awareness is supported on specified minimum Harmony Endpoint client versions, so administrators should verify client compatibility before using it.
Question 160. If a configured Connection Awareness target is reachable, what is the status?
- Connected
- Restricted
- Disconnected
- Quarantined
Correct Answer: 1. Connected
Explanation:
When Connection Awareness is configured to use specified network targets, successful connectivity to one of those targets causes the endpoint to be considered Connected. If the endpoint cannot reach the required target, its status becomes Disconnected and the applicable disconnected policy can be enforced. This mechanism lets organizations define connectivity based on access to an internal router, web server, or another relevant network component rather than solely on communication with Endpoint Security Management. The feature controls policy assignment, not the endpoint’s general online or offline state.