exam questions

Exam 156-315.80 All Questions

View all questions & answers for the 156-315.80 exam

Exam 156-315.80 topic 1 question 103 discussion

Actual exam question from Checkpoint's 156-315.80
Question #: 103
Topic #: 1
[All 156-315.80 Questions]

How would you deploy TE250X Check Point appliance just for email traffic and in-line mode without a Check Point Security Gateway?

  • A. Install appliance TE250X on SpanPort on LAN switch in MTA mode.
  • B. Install appliance TE250X in standalone mode and setup MTA.
  • C. You can utilize only Check Point Cloud Services for this scenario.
  • D. It is not possible, always Check Point SGW is needed to forward emails to SandBlast appliance.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ToadRobertson2
Highly Voted 2 years, 3 months ago
The TE250X is a Sandblast appliance itself so it can't be C. According to the datasheet there are 2 deployment options; Private Cloud i.e. connected to a GW or Inline as Degenhardt said, this means it cant be D. A SPAN port would mean copies of packets are sent to the TE250X, but the appliance just listens and it cannot prevent the clients from receiving the packets, so it can't be A. It has to be B.
upvoted 11 times
...
caz21
Highly Voted 2 years, 2 months ago
C is correct, you would need a gateway to do the redirecting of the mail to a dedicated MTA. It says 'without a gateway'
upvoted 5 times
...
Vasko777
Most Recent 4 months, 3 weeks ago
Correct is B. Page 2 - https://www.checkpoint.com/downloads/products/sandblast-appliances-datasheet.pdf
upvoted 1 times
...
lromeroq
10 months, 2 weeks ago
La B es la respuesta correcta
upvoted 1 times
...
lordlich
12 months ago
C is correct
upvoted 1 times
...
Al789789
1 year, 5 months ago
Threat Emulation Deployments: You can use inline or monitor deployments for file emulation. Inline - Use Prevent and Ask actions to block traffic before it goes to the internal computer. You can configure how Threat Emulation handles connections while it finishes the emulation of a file: Background - The traffic is allowed to enter the internal network Hold - The traffic is blocked and does not enter the internal network until after emulation is finished Monitor - Use a SPAN or TAP configuration to duplicate network traffic. The files are then sent directly to Threat Emulation and the computer in the internal network. If Threat Emulation discovers that a file contains malware, the applicable log action is done. Monitor deployments support only the Detect action. https://sc1.checkpoint.com/documents/R77/CP_R77_ThreatPrevention_WebAdmin/101646.htm
upvoted 1 times
...
NLT
1 year, 8 months ago
B is correct answer.
upvoted 2 times
...
NLT
1 year, 8 months ago
DEPLOYMENT OPTIONS Emulate threats in one of two deployment options: 1. Private cloud: Check Point security gateways send files to a SandBlast appliance for emulation 2. Inline: This is a stand-alone option that deploys a SandBlast Appliance inline as MTA or as an ICAP server or on a SPAN port, utilizing all NGTX Software Blades including IPS, Antivirus, Anti-Bot, Threat Emulation, Threat Extraction, URL Filtering and Application Control.
upvoted 1 times
...
jm31
1 year, 11 months ago
I'll choose D! Base on ATRG Documentation there is three (3) deployment mode Inline, SPAN and Remote only. Option C you still need Security Gateway to forward files. <-- Not a possible answer, though you can use the cloud service while inspecting all the traffic not only email traffic. Option B is not the possible answer based on the 3 deployment modes. Option A Span can't prevent. It can do detect only. <-- Not possible answer So D is the best option for me. Let me know your thoughts. You need a Checkpoint account to access the support center. Reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114806#Deployment%20options%20-%20Inline
upvoted 1 times
...
Gabsf
2 years, 1 month ago
You can't deploy the TE in standalone, always need SMS
upvoted 1 times
seralvarCR
1 year, 5 months ago
This is not true, it is not mentioned in the deployment options, but Sales Engineers promoted these appliances as "completely independant" solutions, not needing any existing Check Point products in place by installing as "standalone"
upvoted 1 times
...
...
Karrol
2 years, 2 months ago
B is correct. SandBlast appliances can be deployed in two modes: 1. Inline or Prevent - As a Mail Transfer Agent (MTA) and as part of the web traffic flow. 2. Detect Only - A SPAN port to receive a copy of traffic. From CCSE R80.10 Handbook, Page 628.
upvoted 2 times
...
mar_san
2 years, 6 months ago
It's B. I think the keyword is standalone and MTA, the others are not relevant.
upvoted 3 times
...
Degenhardt
3 years, 3 months ago
No. It's A: "Inline: This is a stand-alone option that deploys a SandBlast Appliance inline as MTA or as an ICAP server or on a SPAN port, utilizing all NGTX Software Blades including IPS, Antivirus, Anti-Bot, Threat Emulation, Threat Extraction, URL Filtering and Application Control" https://www.checkpoint.com/downloads/products/sandblast-appliances-datasheet.pdf
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago