{"id":21619,"date":"2026-09-25T06:29:57","date_gmt":"2026-09-25T06:29:57","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21619"},"modified":"2026-09-25T06:29:57","modified_gmt":"2026-09-25T06:29:57","slug":"checkpoint-156-536-practice-test-questions-and-exam-dumps-parta20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/checkpoint-156-536-practice-test-questions-and-exam-dumps-parta20-q381-400\/","title":{"rendered":"Checkpoint 156-536 Practice Test Questions and Exam Dumps Parta20 Q381-400"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/156-536-exam-dumps\"><b>Checkpoint 156-536 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 381. What is a main benefit of an external Endpoint Policy Server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypts endpoint disks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduces management-server communication load<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replaces Active Directory<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creates malware signatures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Reduces management-server communication load<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An external Endpoint Policy Server handles much of the frequent communication between Endpoint Security clients and the Endpoint Security Management Server. This reduces load on the management server and can also reduce bandwidth requirements between remote sites and the central management location. The Endpoint Policy Server can process heartbeat and synchronization requests, policy downloads, package downloads, Anti-Malware updates, and endpoint logs. Check Point recommends distributed deployments with external Endpoint Policy Servers when environments contain remote sites or large numbers of clients.<\/span><\/p>\n<p><b>Question 382. How many secondary management servers are supported with Endpoint Security?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unlimited<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Four<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Two<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. One<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Check Point R81.20 Endpoint Security supports one Secondary Security Management Server in a Management High Availability deployment. The primary and secondary servers synchronize management information so the secondary server can take over if the primary becomes unavailable or requires maintenance. High Availability protects both Network Security Management and Endpoint Security management data because the Endpoint Security Management Server is integrated with the Security Management Server. Additional Endpoint Policy Servers can be deployed separately for scalability, but only one secondary management server is supported for Endpoint Security.<\/span><\/p>\n<p><b>Question 383. What does Management High Availability provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Redundancy and database backup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Malware sandboxing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL filtering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Redundancy and database backup<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management High Availability provides redundancy and database backup for management servers. Synchronized primary and secondary servers maintain the same policies, rules, objects, user definitions, and system settings. If the primary server fails or is taken offline for maintenance, the secondary server can assume management responsibilities. In an Endpoint Security deployment, this architecture protects the Endpoint Security Management database as well as the broader Security Management database. High Availability is therefore a management-resilience feature rather than an endpoint threat-prevention capability.<\/span><\/p>\n<p><b>Question 384. Which server usually handles client heartbeats in a distributed deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active Directory server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Policy Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Endpoint Policy Server<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In a distributed Endpoint Security deployment, the Endpoint Policy Server handles common and bandwidth-intensive client communication, including heartbeat and synchronization requests. It can also provide policy downloads, MSI or EXE packages, Anti-Malware updates, and log handling without forwarding every request to the central Endpoint Security Management Server. This design reduces central-server load and improves performance for remote or large sites. The Policy Server still forwards certain database-dependent information and monitoring data to the management server when required.<\/span><\/p>\n<p><b>Question 385. How does a client choose among multiple Policy Servers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It selects the closest or fastest server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It always selects the primary manager<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It uses DNS round robin only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It chooses randomly<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It selects the closest or fastest server<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When multiple Endpoint Policy Servers are available, each Endpoint Security client analyzes the available servers and automatically communicates with the server that is considered closest or fastest for communication. This behavior improves scalability and reduces unnecessary cross-site traffic. It also means administrators do not need to manually map every endpoint to a Policy Server under normal conditions. Check Point recommends placing Policy Servers strategically, especially at remote sites, so clients can obtain policy, packages, updates, and log services efficiently.<\/span><\/p>\n<p><b>Question 386. What server type becomes an Endpoint Policy Server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active Directory Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Log Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Log Server<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Endpoint Policy Server is installed by first deploying a Check Point Log Server and then configuring that server to operate as an Endpoint Policy Server. Check Point recommends using dedicated external Policy Servers in distributed environments. At least one Policy Server is recommended for each remote site, while larger sites may benefit from several servers to improve performance and distribute communication load. This architecture allows the central Endpoint Security Management Server to focus more heavily on management tasks instead of handling every client transaction directly.<\/span><\/p>\n<p><b>Question 387. What identifier is entered for a new Endpoint Policy Server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User SID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FQDN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MAC address only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. FQDN<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When defining an Endpoint Policy Server in SmartEndpoint, the administrator enters the server&#8217;s Fully Qualified Domain Name, or FQDN, in the server wizard. Using the FQDN provides a clear network identity for the server and supports communication between managed clients, Policy Servers, and the Endpoint Security Management environment. The configuration workflow begins under Manage &gt; Endpoint Servers and allows administrators to create or edit server definitions. Correct server identity and name resolution are important for reliable distributed endpoint communication.<\/span><\/p>\n<p><b>Question 388. What is recommended for every remote site?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One domain controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One Harmony Appliance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> At least one Endpoint Policy Server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One secondary management server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. At least one Endpoint Policy Server<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Check Point recommends installing at least one external Endpoint Policy Server for each remote site in a distributed deployment. The purpose is to keep frequent client communication local whenever possible and reduce bandwidth usage between remote locations and central management. Larger sites can use multiple Policy Servers to further distribute client traffic and improve performance. A remote site does not require its own secondary management server because Management High Availability uses only one secondary management server for the overall Endpoint Security environment.<\/span><\/p>\n<p><b>Question 389. What does an Endpoint Policy Server download to clients?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only DNS records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only encryption keys<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only user accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policies and installation packages<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Policies and installation packages<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Policy Servers can handle policy downloads and software package downloads for managed clients. Supported package delivery includes both dynamic executable packages and Windows Installer MSI packages. They can also provide Anti-Malware updates and handle endpoint logs. Because these operations are frequent and can consume significant bandwidth, moving them away from the central Endpoint Security Management Server improves scalability. Certain component-specific information, such as Full Disk Encryption recovery data, still needs to reach the central management database.<\/span><\/p>\n<p><b>Question 390. What must match for local MSI deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deployment-rule and local-package versions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User and computer names<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS and gateway addresses<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encryption and malware policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Deployment-rule and local-package versions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For deployment from local paths or URLs, the client package version defined in the Deployment Policy must match the version of the MSI file stored locally. If the Deployment rule specifies a different version from the locally available package, the client is not deployed. Check Point also warns that a mismatch between the package on the management server and the local package can generate an error. Version consistency is therefore essential when administrators use local package distribution to reduce network bandwidth or speed deployment.<\/span><\/p>\n<p><b>Question 391. What can happen if no local MSI is found?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint is automatically deleted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FDE starts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The client can fall back to the management server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The policy is removed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The client can fall back to the management server<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrators can enable a fallback option called Enable Deployment from Server when no MSI was found in local paths. With this setting enabled, an endpoint that cannot locate the required package in the configured local path or URL checks the Endpoint Security Management Server for the deployment package. This improves reliability while still allowing organizations to use local distribution as the preferred method. Without the fallback option, missing local packages can prevent deployment from completing successfully.<\/span><\/p>\n<p><b>Question 392. What happens if <\/b><b>Clock skew too great<\/b><b> appears?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reinstall Anti-Malware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Synchronize system clocks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable Full Disk Encryption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the endpoint object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Synchronize system clocks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A <\/span><span style=\"font-weight: 400;\">Clock skew too great<\/span><span style=\"font-weight: 400;\"> message during Active Directory authentication indicates that the clocks of the Endpoint Security server, client, and Active Directory server are too far out of synchronization. Check Point recommends correcting time synchronization and ensuring daylight-saving settings are consistent across the systems. Kerberos authentication depends on reasonably synchronized clocks to reduce replay and credential-abuse risks. Although Check Point documents a configurable clock-skew tolerance, increasing that value is presented as a workaround rather than the preferred solution.<\/span><\/p>\n<p><b>Question 393. What is the default authentication clock skew?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 3600 seconds<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 60 seconds<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 300 seconds<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 86400 seconds<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. 3600 seconds<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The documented default Endpoint Security authentication clock-skew value is 3600 seconds. Administrators can change the allowed value using the <\/span><span style=\"font-weight: 400;\">authentication.clockSkew.secs<\/span><span style=\"font-weight: 400;\"> property in the Endpoint Security server configuration, but Check Point does not recommend using a larger tolerance as the primary solution to synchronization problems. Time synchronization among clients, Endpoint Security servers, and Active Directory should be corrected instead. Accurate system clocks support secure Kerberos authentication and help prevent authentication failures related to ticket validity.<\/span><\/p>\n<p><b>Question 394. What should fix an incorrect key version error?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change the heartbeat interval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reinstall the firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Run Appscan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Update the key version number<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Update the key version number<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If the authentication log reports that the key version number for a principal in the key table is incorrect, Check Point instructs administrators to update the key version number in the Active Directory SSO Configuration window. This condition can occur when the user mapped to the <\/span><span style=\"font-weight: 400;\">ktpass<\/span><span style=\"font-weight: 400;\"> service has changed. Because Kerberos relies on matching keys and versions between systems, an incorrect key version prevents proper authentication even when connectivity is otherwise functional. Reviewing the server authentication log provides the evidence needed to identify this specific issue.<\/span><\/p>\n<p><b>Question 395. What command restarts the Endpoint Security server process?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">fw stop ; fw start<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">uepm_stop ; uepm_start<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">cpwd_admin restart<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">epm restart<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. <\/b><b>uepm_stop ; uepm_start<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Check Point documents <\/span><span style=\"font-weight: 400;\">uepm_stop ; uepm_start<\/span><span style=\"font-weight: 400;\"> as the command sequence used to restart the Endpoint Security server process during certain troubleshooting procedures. For example, administrators use it after enabling or disabling detailed Kerberos authentication debugging and for some authentication-log errors. The command should be run from Expert mode on the Endpoint Security server. Restarting the service can interrupt endpoint-management functions temporarily, so administrators should use it intentionally and preferably during an appropriate maintenance window.<\/span><\/p>\n<p><b>Question 396. Which file stores Endpoint Management proxy settings?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">local.properties<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">objects_5_0.C<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">fwauth.NDB<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">database.conf<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. <\/b><b>local.properties<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Proxy settings for the Endpoint Security Management Server are configured in the <\/span><span style=\"font-weight: 400;\">local.properties<\/span><span style=\"font-weight: 400;\"> file under the Endpoint management engine configuration path. Administrators can define the proxy host, listening port, username, and password when basic authentication is required. Check Point instructs administrators to stop services before editing the file and start services again afterward. Proxy configuration can be necessary when the management environment requires outbound access through a corporate proxy for supported functions or services.<\/span><\/p>\n<p><b>Question 397. What command stops Check Point services before proxy edits?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">fw unloadlocal<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">uepm_stop<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">reboot<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">cpstop<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. <\/b><b>cpstop<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Check Point&#8217;s documented proxy-configuration procedure instructs administrators to run <\/span><span style=\"font-weight: 400;\">cpstop<\/span><span style=\"font-weight: 400;\"> before editing the Endpoint Security Management Server&#8217;s <\/span><span style=\"font-weight: 400;\">local.properties<\/span><span style=\"font-weight: 400;\"> file. After the proxy host, port, username, and password values are saved, administrators restart the Check Point services with <\/span><span style=\"font-weight: 400;\">cpstart<\/span><span style=\"font-weight: 400;\">. Stopping the services before configuration changes helps ensure that the management processes do not continue using stale values while the file is being modified. These commands require command-line access and Expert mode privileges.<\/span><\/p>\n<p><b>Question 398. What must secondary HA peers show after synchronization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Successfully synced<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Pending reboot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detect mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restricted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Successfully synced<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After synchronizing Endpoint Security Management Servers in a Management High Availability environment, the peer status should show Successfully synced. Synchronization ensures that the primary and secondary management systems contain consistent management information and can support failover. Check Point&#8217;s R81.20 upgrade and HA procedures instruct administrators to verify communication, install the management database, and then synchronize the peers. A failed or incomplete synchronization should be resolved before relying on the secondary server as a valid backup management system.<\/span><\/p>\n<p><b>Question 399. What must work between HA management servers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat Extraction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Secure Internal Communication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anti-Ransomware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Secure Internal Communication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Internal Communication, or SIC, must function correctly between the primary and secondary management servers in a Management High Availability deployment. Check Point instructs administrators to test SIC status and confirm that it shows Communicating before continuing with database installation and synchronization. SIC uses certificates and Check Point&#8217;s internal trust mechanisms to authenticate communication between management systems. Without working SIC, the servers cannot reliably exchange the management information required for synchronization and failover.<\/span><\/p>\n<p><b>Question 400. What BEST improves a large multi-site Endpoint deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one central server for every task<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy external Policy Servers near clients<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable heartbeats<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove package repositories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Deploy external Policy Servers near clients<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For large or geographically distributed environments, external Endpoint Policy Servers improve scalability by handling frequent client communication closer to the endpoints. Check Point recommends at least one Policy Server for each remote site and multiple servers at larger locations when needed. These servers process heartbeats, synchronization, policy downloads, client packages, Anti-Malware updates, and logs, reducing both central management load and wide-area bandwidth consumption. This distributed architecture is specifically aligned with the large-scale deployment objectives in the Check Point Harmony Endpoint Specialist course for exam 156-536.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps. Question 381. What is a main benefit of an external Endpoint Policy Server? Encrypts endpoint disks Reduces management-server communication load Replaces Active Directory Creates malware signatures Correct Answer: 2. Reduces management-server communication load Explanation: An external Endpoint Policy Server handles much of the frequent communication [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21619"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21619"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21619\/revisions"}],"predecessor-version":[{"id":21620,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21619\/revisions\/21620"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}