CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Certifications And Exams > CCSA (Check Point Certified Security Administrator) > CCSA NGX Exam 156-215.1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #21 (permalink)  
Old 2006-09-21
Member
 
Join Date: 2006-06-03
Posts: 33
Rep Power: 0
dean7711 has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

Yes thats great thanks.

So what your saying is the answer to QUESTION NO: 77 is E not C?


---------------------------------------------
You are a Security Administrator configuring Static NAT on an internal host-node
object. You clear the box "Translate destination on client side", accessed from
Global Properties > NAT settings > Automatic NAT. Assuming all other Global
Properties NAT settings are selected, what else must be configured for automatic
Static NAT to work?
A. The NAT IP address must be added to the anti-spoofing group of the external
Gateway interface
B. Two address-translation rules in the Rule Base
C. No extra configuring needed
D. A proxy ARP entry, to ensure packets destined for the public IP address will reach the
Security Gateway's external interface
E. A static route, to ensure packets destined for the public NAT IP address will reach the
Gateway's internal interface
Reply With Quote
  #22 (permalink)  
Old 2006-09-21
Junior Member
 
Join Date: 2006-06-23
Posts: 21
Rep Power: 0
firewalz has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

Yes, I think the answer is E.
That senerio is right out of the pdf's, look at pg.88 and 89 of the "Firewall and Smart Defense" NGX R61 pdf.
Those who are saying to look at the pdf's are giving good advice, the trick is to narrow it down to the relevent sections so you dont have to dig through 1000's of pdf pages.
Reply With Quote
  #23 (permalink)  
Old 2006-09-21
Junior Member
 
Join Date: 2006-06-23
Posts: 21
Rep Power: 0
firewalz has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

sorry, thats pg.97-98
Reply With Quote
  #24 (permalink)  
Old 2006-09-24
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Testking Wrong answers. Identify here!!

Quote:
Originally Posted by dean7711 View Post
Guys for "Translate Destination on Client Side" Im having problems understanding this..

When we are talking about client side do we mean the internet facing side of the firewall or the lan side?
When it comes to connections (remember that VPN-1 is very connection-oriented), I've always believed that the "client-side" meant on the side of the connection closer to the initiator of the IP connection. The "server-side" is the opposite. All that matters is which IP host initiates; that's the client side.
Reply With Quote
  #25 (permalink)  
Old 2006-09-25
Junior Member
 
Join Date: 2006-09-22
Location: India
Posts: 4
Rep Power: 0
ratanjai has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

[quote=prasad;7408]Hi ,

Bhasakar plz send me the right answers for Testking dump....
if u have. ratanjaidubey@indiatimes.com
Reply With Quote
  #26 (permalink)  
Old 2006-11-30
Junior Member
 
Join Date: 2006-11-26
Posts: 19
Rep Power: 0
nazim has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

Can you pleasse send the correct answers to me @ nazim.inamdar@gmail.com


FYI, I sent in a correct answer to feedback@testking.com and they gave me a 3 dollar credit towards my next TestKing purchase. It's not much be at least it was something. I also sent an update to some of the wording on one of the answers. Both changes showed up in the next update which was only a few days later. Kinda cool. Of coarse this doesn't help those who haven't purchased the material and are not able to receive the updates, but if you are serious about your career, the amount you have to pay for the TestKing is not really that much. Especially if you are lucky enough to have an employer that will reimburse you for things like that. :)[/quote]
Reply With Quote
  #27 (permalink)  
Old 2006-12-08
Junior Member
 
Join Date: 2006-12-08
Posts: 3
Rep Power: 0
janshack has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

QUESTION NO: 71
Tess King's main internal network 10.10.10.0/24 allows all traffic to the Internet using Hide NAT. Tess King also has a small network 10.10-.20.0/24 behind the internal router. Tess wants to configure the kernel to translate the source address only when network 10.10.20.0 tries to access the Internet for HTTP, SMTP, and FTP services.
Which of the following configurations will allow this network to access Internet?

A. Automatic Static NAT on network 10.10.20.0/24
B. Manual Hide NAT rules for HTTP, FTP, and SMTP services for network
10.10.20.0/24.
C. Manual Static NAT rules for network 10.10.20.0/24,
D. Automatic Hide NAT for network 10.10.20.0/24.
E. No change is necessarey.

TestKing answer is A, I think the correct answer is B.
Reply With Quote
  #28 (permalink)  
Old 2007-01-17
Member
 
Join Date: 2006-08-21
Posts: 30
Rep Power: 0
usmanshaikh has an average reputation (10+)
Default Re: Testking Wrong answers. Identify here!!

Quote:
Originally Posted by firewalz View Post
No.115
When you hide a rule in the rule base, how can you disable the rule
they say A.
"Open the rule menue and select hide and view hidden rules, select the rule,right click, and select disable."

I tried this and it does not work, unless you clear hidden rules, the disable rule(s) optin is grayed out

Answer should be E. I have demonstrated that this works, on R61.
Not B. B will only let you see the hidden rules but rules are still in hidden state so it will not let you disale it.So its definitely E

Usman

Last edited by usmanshaikh; 2007-01-17 at 14:48.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:07.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0