Task: View logs of Anti-Bot detections in SmartConsole.
Correct Answer:
See the Explanation.Explanation: 1- Go to Logs & Monitor. 2- Use search filter: blade:"Anti-Bot" and time range = last 24 hours. 3- View events showing Botnet communication attempts. 4- Double-click logs to review source, domain contacted, and action taken. 5- Save filtered logs as report if needed.
Question 7
Task: Clone an existing profile to use for mobile endpoints and modify AV scanning.
Correct Answer:
See the Explanation.Explanation: 1- Go to Threat Prevention > Profiles. 2- Select the base profile (e.g., Optimized), right-click > Clone. 3- Name it Mobile_Profile. 4- Edit Anti-Virus settings to use Detect instead of Prevent for medium threats. 5- Save and assign to mobile VPN policy rule.
Question 8
Which is NOT an available setting under Custom Policy Tools?
Correct Answer: B
The correct answer is B. UserCheck . In SmartConsole, Custom Policy Tools are used to manage Threat Prevention policy objects and tuning components such as profiles, IPS protections, indicators, and protection categories. The official R81.20 guide shows Custom Policy Tools > Profiles for profile creation, editing, and cloning, and Custom Policy Tools > IPS Protections for managing IPS protection behavior. The same guide also shows Custom Policy Tools > Indicators as the location used to configure external IoC feeds. Malicious Activity Detection is represented through Threat Prevention protection types: the Protections Browser displays protection types, and the guide states that Malicious Activity and Unusual Activity protection types contain lists of protections. UserCheck, however, is not itself a Custom Policy Tools setting. It is a user interaction and notification mechanism configured inside relevant blade/profile settings, such as Anti-Bot or Zero Phishing UserCheck messages. Therefore, among the choices, UserCheck is the item that does not belong as an available Custom Policy Tools setting. Reference topics: Custom Policy Tools, IPS Protections, Indicators, Threat Prevention Profiles, Protections Browser, UserCheck settings.
Question 9
What type of layer is the threat Prevention?
Correct Answer: D
The correct answer is D. Ordered . Threat Prevention policy uses ordered policy layers. Check Point documentation states that you can create a Threat Prevention Rule Base with multiple Ordered Layers , and that Ordered Layers help organize the Rule Base according to organizational needs, such as services or networks. Each Policy Layer calculates its action separately from other layers, and when there is one layer in the policy package, the first matched rule is enforced. This is a core certification distinction. Access Control can use ordered and inline layers, but Threat Prevention is treated as an ordered layer policy model. The policy evaluates rules in order and applies the appropriate Threat Prevention profile, blades, protection behavior, and tracking according to rule matching. Option C describes when Threat Prevention is applied in the traffic flow-after Access Control accepts the connection-but it does not answer the question about the layer type. Option A is incorrect because Threat Prevention is not both ordered and inline in this context. Option B is incorrect because inline layers are not the Threat Prevention layer type being tested here. Reference topics: Threat Prevention Policy Layers, Ordered Layers, first-match behavior, policy-layer calculation, Threat Prevention Rule Base.
Question 10
Task: Configure inspection settings for mobile VPN users.
Correct Answer:
See the Explanation.Explanation: 1- Go to Threat Prevention > Inspection Settings. 2- Add a new exception group for mobile user IP pool. 3- Set reduced inspection sensitivity for this group. 4- Save, publish, and test VPN user traffic. 5- Ensure logs still show critical threats being detected.