View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.
Question 381. What is a main benefit of an external Endpoint Policy Server?
- Encrypts endpoint disks
- Reduces management-server communication load
- Replaces Active Directory
- Creates malware signatures
Correct Answer: 2. Reduces management-server communication load
Explanation:
An external Endpoint Policy Server handles much of the frequent communication between Endpoint Security clients and the Endpoint Security Management Server. This reduces load on the management server and can also reduce bandwidth requirements between remote sites and the central management location. The Endpoint Policy Server can process heartbeat and synchronization requests, policy downloads, package downloads, Anti-Malware updates, and endpoint logs. Check Point recommends distributed deployments with external Endpoint Policy Servers when environments contain remote sites or large numbers of clients.
Question 382. How many secondary management servers are supported with Endpoint Security?
- Unlimited
- Four
- Two
- One
Correct Answer: 4. One
Explanation:
Check Point R81.20 Endpoint Security supports one Secondary Security Management Server in a Management High Availability deployment. The primary and secondary servers synchronize management information so the secondary server can take over if the primary becomes unavailable or requires maintenance. High Availability protects both Network Security Management and Endpoint Security management data because the Endpoint Security Management Server is integrated with the Security Management Server. Additional Endpoint Policy Servers can be deployed separately for scalability, but only one secondary management server is supported for Endpoint Security.
Question 383. What does Management High Availability provide?
- Redundancy and database backup
- Malware sandboxing
- URL filtering
- Application inventory
Correct Answer: 1. Redundancy and database backup
Explanation:
Management High Availability provides redundancy and database backup for management servers. Synchronized primary and secondary servers maintain the same policies, rules, objects, user definitions, and system settings. If the primary server fails or is taken offline for maintenance, the secondary server can assume management responsibilities. In an Endpoint Security deployment, this architecture protects the Endpoint Security Management database as well as the broader Security Management database. High Availability is therefore a management-resilience feature rather than an endpoint threat-prevention capability.
Question 384. Which server usually handles client heartbeats in a distributed deployment?
- Active Directory server
- Security Gateway
- Endpoint Policy Server
- DNS server
Correct Answer: 3. Endpoint Policy Server
Explanation:
In a distributed Endpoint Security deployment, the Endpoint Policy Server handles common and bandwidth-intensive client communication, including heartbeat and synchronization requests. It can also provide policy downloads, MSI or EXE packages, Anti-Malware updates, and log handling without forwarding every request to the central Endpoint Security Management Server. This design reduces central-server load and improves performance for remote or large sites. The Policy Server still forwards certain database-dependent information and monitoring data to the management server when required.
Question 385. How does a client choose among multiple Policy Servers?
- It selects the closest or fastest server
- It always selects the primary manager
- It uses DNS round robin only
- It chooses randomly
Correct Answer: 1. It selects the closest or fastest server
Explanation:
When multiple Endpoint Policy Servers are available, each Endpoint Security client analyzes the available servers and automatically communicates with the server that is considered closest or fastest for communication. This behavior improves scalability and reduces unnecessary cross-site traffic. It also means administrators do not need to manually map every endpoint to a Policy Server under normal conditions. Check Point recommends placing Policy Servers strategically, especially at remote sites, so clients can obtain policy, packages, updates, and log services efficiently.
Question 386. What server type becomes an Endpoint Policy Server?
- DNS Server
- Active Directory Server
- Security Gateway
- Log Server
Correct Answer: 4. Log Server
Explanation:
An Endpoint Policy Server is installed by first deploying a Check Point Log Server and then configuring that server to operate as an Endpoint Policy Server. Check Point recommends using dedicated external Policy Servers in distributed environments. At least one Policy Server is recommended for each remote site, while larger sites may benefit from several servers to improve performance and distribute communication load. This architecture allows the central Endpoint Security Management Server to focus more heavily on management tasks instead of handling every client transaction directly.
Question 387. What identifier is entered for a new Endpoint Policy Server?
- User SID
- FQDN
- MAC address only
- License key
Correct Answer: 2. FQDN
Explanation:
When defining an Endpoint Policy Server in SmartEndpoint, the administrator enters the server’s Fully Qualified Domain Name, or FQDN, in the server wizard. Using the FQDN provides a clear network identity for the server and supports communication between managed clients, Policy Servers, and the Endpoint Security Management environment. The configuration workflow begins under Manage > Endpoint Servers and allows administrators to create or edit server definitions. Correct server identity and name resolution are important for reliable distributed endpoint communication.
Question 388. What is recommended for every remote site?
- One domain controller
- One Harmony Appliance
- At least one Endpoint Policy Server
- One secondary management server
Correct Answer: 3. At least one Endpoint Policy Server
Explanation:
Check Point recommends installing at least one external Endpoint Policy Server for each remote site in a distributed deployment. The purpose is to keep frequent client communication local whenever possible and reduce bandwidth usage between remote locations and central management. Larger sites can use multiple Policy Servers to further distribute client traffic and improve performance. A remote site does not require its own secondary management server because Management High Availability uses only one secondary management server for the overall Endpoint Security environment.
Question 389. What does an Endpoint Policy Server download to clients?
- Only DNS records
- Only encryption keys
- Only user accounts
- Policies and installation packages
Correct Answer: 4. Policies and installation packages
Explanation:
Endpoint Policy Servers can handle policy downloads and software package downloads for managed clients. Supported package delivery includes both dynamic executable packages and Windows Installer MSI packages. They can also provide Anti-Malware updates and handle endpoint logs. Because these operations are frequent and can consume significant bandwidth, moving them away from the central Endpoint Security Management Server improves scalability. Certain component-specific information, such as Full Disk Encryption recovery data, still needs to reach the central management database.
Question 390. What must match for local MSI deployment?
- Deployment-rule and local-package versions
- User and computer names
- DNS and gateway addresses
- Encryption and malware policies
Correct Answer: 1. Deployment-rule and local-package versions
Explanation:
For deployment from local paths or URLs, the client package version defined in the Deployment Policy must match the version of the MSI file stored locally. If the Deployment rule specifies a different version from the locally available package, the client is not deployed. Check Point also warns that a mismatch between the package on the management server and the local package can generate an error. Version consistency is therefore essential when administrators use local package distribution to reduce network bandwidth or speed deployment.
Question 391. What can happen if no local MSI is found?
- The endpoint is automatically deleted
- FDE starts
- The client can fall back to the management server
- The policy is removed
Correct Answer: 3. The client can fall back to the management server
Explanation:
Administrators can enable a fallback option called Enable Deployment from Server when no MSI was found in local paths. With this setting enabled, an endpoint that cannot locate the required package in the configured local path or URL checks the Endpoint Security Management Server for the deployment package. This improves reliability while still allowing organizations to use local distribution as the preferred method. Without the fallback option, missing local packages can prevent deployment from completing successfully.
Question 392. What happens if Clock skew too great appears?
- Reinstall Anti-Malware
- Synchronize system clocks
- Disable Full Disk Encryption
- Delete the endpoint object
Correct Answer: 2. Synchronize system clocks
Explanation:
A Clock skew too great message during Active Directory authentication indicates that the clocks of the Endpoint Security server, client, and Active Directory server are too far out of synchronization. Check Point recommends correcting time synchronization and ensuring daylight-saving settings are consistent across the systems. Kerberos authentication depends on reasonably synchronized clocks to reduce replay and credential-abuse risks. Although Check Point documents a configurable clock-skew tolerance, increasing that value is presented as a workaround rather than the preferred solution.
Question 393. What is the default authentication clock skew?
- 3600 seconds
- 60 seconds
- 300 seconds
- 86400 seconds
Correct Answer: 1. 3600 seconds
Explanation:
The documented default Endpoint Security authentication clock-skew value is 3600 seconds. Administrators can change the allowed value using the authentication.clockSkew.secs property in the Endpoint Security server configuration, but Check Point does not recommend using a larger tolerance as the primary solution to synchronization problems. Time synchronization among clients, Endpoint Security servers, and Active Directory should be corrected instead. Accurate system clocks support secure Kerberos authentication and help prevent authentication failures related to ticket validity.
Question 394. What should fix an incorrect key version error?
- Change the heartbeat interval
- Reinstall the firewall
- Run Appscan
- Update the key version number
Correct Answer: 4. Update the key version number
Explanation:
If the authentication log reports that the key version number for a principal in the key table is incorrect, Check Point instructs administrators to update the key version number in the Active Directory SSO Configuration window. This condition can occur when the user mapped to the ktpass service has changed. Because Kerberos relies on matching keys and versions between systems, an incorrect key version prevents proper authentication even when connectivity is otherwise functional. Reviewing the server authentication log provides the evidence needed to identify this specific issue.
Question 395. What command restarts the Endpoint Security server process?
- fw stop ; fw start
- uepm_stop ; uepm_start
- cpwd_admin restart
- epm restart
Correct Answer: 2. uepm_stop ; uepm_start
Explanation:
Check Point documents uepm_stop ; uepm_start as the command sequence used to restart the Endpoint Security server process during certain troubleshooting procedures. For example, administrators use it after enabling or disabling detailed Kerberos authentication debugging and for some authentication-log errors. The command should be run from Expert mode on the Endpoint Security server. Restarting the service can interrupt endpoint-management functions temporarily, so administrators should use it intentionally and preferably during an appropriate maintenance window.
Question 396. Which file stores Endpoint Management proxy settings?
- local.properties
- objects_5_0.C
- fwauth.NDB
- database.conf
Correct Answer: 3. local.properties
Explanation:
Proxy settings for the Endpoint Security Management Server are configured in the local.properties file under the Endpoint management engine configuration path. Administrators can define the proxy host, listening port, username, and password when basic authentication is required. Check Point instructs administrators to stop services before editing the file and start services again afterward. Proxy configuration can be necessary when the management environment requires outbound access through a corporate proxy for supported functions or services.
Question 397. What command stops Check Point services before proxy edits?
- fw unloadlocal
- uepm_stop
- reboot
- cpstop
Correct Answer: 4. cpstop
Explanation:
Check Point’s documented proxy-configuration procedure instructs administrators to run cpstop before editing the Endpoint Security Management Server’s local.properties file. After the proxy host, port, username, and password values are saved, administrators restart the Check Point services with cpstart. Stopping the services before configuration changes helps ensure that the management processes do not continue using stale values while the file is being modified. These commands require command-line access and Expert mode privileges.
Question 398. What must secondary HA peers show after synchronization?
- Successfully synced
- Pending reboot
- Detect mode
- Restricted
Correct Answer: 1. Successfully synced
Explanation:
After synchronizing Endpoint Security Management Servers in a Management High Availability environment, the peer status should show Successfully synced. Synchronization ensures that the primary and secondary management systems contain consistent management information and can support failover. Check Point’s R81.20 upgrade and HA procedures instruct administrators to verify communication, install the management database, and then synchronize the peers. A failed or incomplete synchronization should be resolved before relying on the secondary server as a valid backup management system.
Question 399. What must work between HA management servers?
- Threat Extraction
- Secure Internal Communication
- Anti-Ransomware
- Application Control
Correct Answer: 3. Secure Internal Communication
Explanation:
Secure Internal Communication, or SIC, must function correctly between the primary and secondary management servers in a Management High Availability deployment. Check Point instructs administrators to test SIC status and confirm that it shows Communicating before continuing with database installation and synchronization. SIC uses certificates and Check Point’s internal trust mechanisms to authenticate communication between management systems. Without working SIC, the servers cannot reliably exchange the management information required for synchronization and failover.
Question 400. What BEST improves a large multi-site Endpoint deployment?
- Use one central server for every task
- Deploy external Policy Servers near clients
- Disable heartbeats
- Remove package repositories
Correct Answer: 2. Deploy external Policy Servers near clients
Explanation:
For large or geographically distributed environments, external Endpoint Policy Servers improve scalability by handling frequent client communication closer to the endpoints. Check Point recommends at least one Policy Server for each remote site and multiple servers at larger locations when needed. These servers process heartbeats, synchronization, policy downloads, client packages, Anti-Malware updates, and logs, reducing both central management load and wide-area bandwidth consumption. This distributed architecture is specifically aligned with the large-scale deployment objectives in the Check Point Harmony Endpoint Specialist course for exam 156-536.