1.
What must a Security Administrator do to comply with a management requirement to log all traffic accepted through the perimeter Security gateway?
2.
You have configured Automatic Static NAT on an internal host-node object. You clear the box Translate destination on client site from Global Properties / NAT. Assuming all other NAT settings in Global Properties are selected, what else must be configured so that a host on the Internet can initiate an inbound connection to this host?
3.
Cara wants to monitor the top services on her Security Gateway (fw-chicago), but she is getting an error message. Other Security Gateways are reporting the information except a new Security Gateway that was just recently deployed. Analyze the error message from the output below and determine what Cara can do to correct the problem.
4.
What happens if Web Server is checked?
5.
Security Administrator, Anna has done the following: What will happen when she recreates the firewall object?
6.
The SIC certificate is stored in the________ directory.
7.
Nancy has lost SIC communication with her Security Gateway and she needs to re-establish SIC. What would be the correct order of steps needed to perform this task?
1) Create a new activation key on the Security Gateway, then exit cpconfig.
2) Click the Communication tab on the Security Gateway object, and then click Reset.
3) Run the cpconfig tool, and then select Secure Internal Communication to reset.
4) Input the new activation key in the Security Gateway object, and then click initialize
5) Run the cpconfig tool, then select source Internal Communication to reset.
8.
You just installed a new Web server in the DMZ that must be reachable from the Internet. You create a manual Static NAT rule as follows:
web_public_IP is the node object that represents the new Web servers public IP address.
web_private_IP is the node object that represents the new Web sites private IP address. You enable all settings from Global Properties > NAT.
When you try to browse the Web server from the Internet, you see the error page cannot be displayed.
Which statements are possible reasons for this?
i). There is no route defined on the Security Gateway for the public IP address to the Web servers private IP address.
ii) There is no Security Policy defined that allows HTTP traffic to the protected Web server.
iii) There is an ARP entry on the Gateway but the settings Merge Manual proxy ARP and Automatic ARP configuration are enabled in Global Properties. The Security Gateway ignores manual ARP entries.
iv) There is no ARP table entry for the protected Web server's public IP address.
9.
You just installed a new Web server in the DMZ that must be reachable from the Internet. You create a manual Static NAT rule as follows:
web_public_IP is the node object that represents the public IP address of the new Web server.
web_private_IP is the node object that represents the new Web sites private IP address. You enable all
settings from Global Properties > NAT.
When you try to browse the Web server from the Internet you see the error page cannot be displayed.
Which of the following is NOT a possible reason?
10.
You have created a Rule Base for firewall, websydney. Now you are going to create a new policy package with security and address translation rules for a second Gateway. What is TRUE about the new packages NAT rules?