(40 Q&As Dumps, 30%OFF Special Discount: 30free)
NEW QUESTION NO: 15
When running the Threat Emulation first time wizard, which of these is NOT an option for file analysis location?
A. Locally on this Threat Emulation Appliance
B. ThreatCloud Emulation Service
C. tecli advanced remote
D. Other Threat Emulation Appliance
Answer: C
NEW QUESTION NO: 16
Anti-Bot uses the following detection/prevention features:
1. Reputation lookup of DNS/IP/URL access
2. Dynamic analysis for Bots
3. Outbound SPAM
4. Bot behavior signatures
A. 2 and 3
B. 1 and 3
C. 1, 2, and 3
D. 1, 3 and 4
Answer: D
NEW QUESTION NO: 17
You analyze your Threat Prevention events in SmartEvent and there is one specific event with a PDF- document you suspect being malicious. What is a typical behavior Threat Emulation would detect as malicious? When the PDF is opened in VM:
A. it tries to open in Acrobat Reader.
B. there are no changes to the registry.
C. it opens with Administrator privileges.
D. there is an outgoing network connection.
Answer: D
Explanation/Reference:
NEW QUESTION NO: 18
What is TRUE for SandBlast local emulation deployment?
1. Any Check Point gateway can perform local emulation.
2. SandBlast Appliance is required.
3. Existing gateway can collect files and forward to emulation.
A. 1 and 2 are correct
B. 1 and 3 are correct
C. 1, 2, and 3 are correct
D. 2 and 3 are correct
Answer: D
NEW QUESTION NO: 19
Which statements below are CORRECT regarding Threat Prevention profiles in SmartDashboard?
1. You can assign multiple profiles per gateway.
2. A profile can be assigned to one or more rules.
3. Only one profile per gateway is allowed.
4. A profile can be assigned to only one rule.
A. 2 and 3 are correct
B. 1 and 2 are correct
C. 1 and 4 are correct
D. 1, 2, 3 and 4 are correct
Answer: A
NEW QUESTION NO: 20
What's the password for the encrypted malicious file available via the Threat Emulation forensics report?
A. infected
B. password
C. forensics
D. malicious
Answer: B
NEW QUESTION NO: 21
A Threat Extraction license is always bundled with Threat Emulation.
A. False - they can be purchased separately.
B. True - it is part of the NGTP and EBP license.
C. True - it is part of the NGTX license.
D. False - Threat extraction is part of the basic NGFW license.
Answer: A
NEW QUESTION NO: 22
Which phase(s) is(are) NOT part of the Cyber Kill Chain?
A. Action and Objectives
B. Command and Control
C. Exploitation
D. Remediation
Answer: D