Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-315.80 All Questions

View all questions & answers for the 156-315.80 exam

Exam 156-315.80 topic 1 question 281 discussion

Actual exam question from Checkpoint's 156-315.80
Question #: 281
Topic #: 1
[All 156-315.80 Questions]

After trust has been established between the Check Point components, what is TRUE about name and IP-address changes?

  • A. Security Gateway IP-address cannot be changed without re-establishing the trust.
  • B. The Security Gateway name cannot be changed in command line without re-establishing trust.
  • C. The Security Management Server name cannot be changed in SmartConsole without re-establishing trust.
  • D. The Security Management Server IP-address cannot be changed without re-establishing the trust.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Kurp
Highly Voted 4 years, 5 months ago
I think the correct answer is C. Doesn't matter what the OS level hostname is. Only smartDashboard/ smartconsole name is relevant. IP addresses do not matter as SIC is name based "SIC is completely NAT tolerant, as the protocol is based on Certificates and SIC names, not on IP addresses. A NAT device between the Security Management Server and Security Gateway will not have any effect on the ability of a Check Point enabled entity to communicate using SIC."
upvoted 10 times
Anni_CCSA
3 years, 1 month ago
"Change the name of the Management Server object to the desired setting in SmartDashboard. (Unlike Security Gateways, this can be done without making any changes to SIC)." , this can be found in sk42071. So it's not C.
upvoted 1 times
dongayan
3 years ago
correct, should be D, if you change the ip address of the CMA new licenses also required, so reset SIC needed.
upvoted 1 times
...
...
...
Doris8000
Most Recent 1 year, 6 months ago
D is confirmed here: https://quizlet.com/au/509819782/ccsa-study-notes-flash-cards/
upvoted 1 times
...
Dako_Dakar
1 year, 11 months ago
C Because the hostname (name of the Security Management Server) has not been changed, SIC communication should not be affected, as long as the routing is correct
upvoted 1 times
...
auburnuy
2 years, 2 months ago
It's D. IP Address of the Internal Certificate Authority (ICA) of Security Management Server / Domain Management Server is automatically added to Check Point Registry file ($CPDIR/registry/HKLM_registry.data) on Security Gateway when SIC is first established (between Security Gateway and Management Server). If the IP Address of Security Management Server / Domain Management Server is changed, and SIC is never manually reset (between Security Gateway and Management Server), then the AutoRenewal of the Certificate will fail. https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103356
upvoted 1 times
...
Amathai1803
2 years, 8 months ago
Had this question today in exam. selected C
upvoted 2 times
...
andros
2 years, 9 months ago
I think C is correct. From CCSA pag 27. "Note: If the Security Management Server is renamed, trust will need to be reestablished as the certificate is reissued"
upvoted 2 times
...
ChinkSantana
3 years ago
Answer is C: CCSA Manual page 79: Once SIC is established, the management server and its components are identified by their SIC names rather than the IP address. If the Security Management Server is renamed, trust will need to be reestablished as the certificate is reissued.
upvoted 2 times
...
Al789789
3 years, 2 months ago
D is correct answer. IP Address of the Internal Certificate Authority (ICA) of Security Management Server / Domain Management Server is automatically added to Check Point Registry file ($CPDIR/registry/HKLM_registry.data) on Security Gateway when SIC is first established (between Security Gateway and Management Server). If the IP Address of Security Management Server / Domain Management Server is changed, and SIC is never manually reset (between Security Gateway and Management Server), then the AutoRenewal of the Certificate will fail. https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103356
upvoted 2 times
...
mrnqaz
3 years, 5 months ago
SIC is dependent on the SMS name... If you look at the CN you will notice the SMS name. Hence, it is specific to name and not IP.
upvoted 1 times
...
DrTee
4 years, 1 month ago
C is partially correct. based on sk40993, Notes, Notes: Since the hostname (name of the Security Management) has not been changed, SIC communication should not be affected, as long as the routing is correct. Make sure that there is connectivity between the Security Management and the managed Security Gateway(s), and that DNS resolution is to the new IP Address. 3. If the DNS does not resolve to the new IP, you will need to reset SIC to confirm the change.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...