Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Check Point Check Point Certified Harmony Endpoint Specialist - R81.20 156-536 Exam Questions

Page: 1 / 10 Total 98 questions

Want more questions? Get Premium Access.

Question 1

Check Point Full Disk Encryption contains two main components - what are the two main components?

Correct Answer: B. Disk Encryption & Pre-Boot Authentication

Question 2

For most tasks, Endpoint clients communicate with the [X] and the [X] communicates with the EMS?

Options:

Correct Answer: B. EPS
Explanation:

Endpoint clients typically communicate with the EPS (Endpoint Policy Server) for policy updates and logging. The EPS then communicates with the EMS (Endpoint Management Server) for central management (Harmony Endpoint Architecture Documentation)


Question 3

Where are quarantined files stored?

Correct Answer: B. On client computer, under C:\ProgramData\Check Point\Harmony Endpoint Security\quarantine

Question 4

Which command in a CLI session is used to check installed licenses on the Harmony Endpoint Management Server?

Correct Answer: A. cplic print -x
Explanation:

To check installed licenses on the Harmony Endpoint Management Server via the command-line interface (CLI), the correct command is cplic print -x. This is a standard Check Point command for displaying detailed license information, as referenced in the CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf on page 58 under 'Getting Licenses.' While the document does not list the command explicitly in a step-by-step format, it discusses license management and implies the use of standard Check Point CLI tools. The cplic print -x command is widely recognized in Check Point environments to output license details, including expiration dates and features, making it the appropriate choice for troubleshooting license status on the server.

Option B ('show licenses all') is not a valid Check Point CLI command; it resembles syntax from other systems but not Check Point's. Option C ('cplic add <license filename=''>') is for adding a license, not checking existing ones (page 58 mentions applying licenses, not viewing them). Option D ('cplic print +x') contains a syntax error; the correct flag is <code>-x</code>, not <code>+x</code>. Thus, option A is the verified answer based on Check Point's CLI conventions and the guide's context.</license>


CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 58: Getting Licenses (discusses license management, implying standard CLI usage).

Question 5

Which Harmony Endpoint environment is better choice for companies looking for more control when deploying the product?

Correct Answer: D. On-premises environment, because it offers more options for deployment, greater control over operations, but is also more costly to support.
Explanation:

According to Check Point documentation, the on-premises environment provides organizations with significantly greater control over product deployment and operation, including more extensive configuration options compared to a cloud-managed environment. Although this level of control is advantageous, it is also noted that it typically comes with higher support and maintenance costs.

Exact Extract from Official Document:

'On-premises environment offers more options for deployment, greater control over operations, but it is also more costly to support.'


Check Point Harmony Endpoint Specialist R81.20 Administration Guide.

Question 6

What does the Data Protection/General rule contain?

Correct Answer: D. Actions that define port protection settings and encryption settings for hard disks and removable media
Explanation:

The Data Protection/General rule in Check Point Harmony Endpoint is a critical component of its Data Security Protection framework, encompassing settings that secure both hard disks and removable media while controlling port access. This rule integrates features from Full Disk Encryption (FDE) and Media Encryption & Port Protection (MEPP), as outlined in the CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf. On page 20, under the 'Endpoint Security Client' section, the document details the components available on Windows:

'Full Disk Encryption: Combines Pre-boot protection, boot authentication, and strong encryption to make sure that only authorized users are given access to information stored on desktops and laptops.'

'Media Encryption and Media Encryption & Port Protection: Protects data stored on the computers by encrypting removable media devices and allowing tight control over computers' ports (USB, Bluetooth, and so on).'

This extract clearly indicates that the Data Protection/General rule includes encryption settings for hard disks (via FDE), encryption settings for removable media, and port protection settings (via MEPP). These elements work together to safeguard data across various storage types and prevent unauthorized access through ports, aligning perfectly with Option D.

Option A ('Actions that define user authentication settings only') is incorrect because, while user authentication (e.g., pre-boot authentication) is part of FDE, the rule extends beyond authentication to include encryption and port protection settings.

Option B ('Actions that define decryption settings for hard disks') is inaccurate as the focus of the rule is on encryption, not decryption, and it covers more than just hard disks (e.g., removable media and ports).

Option C ('Actions that restore encryption settings for hard disks and change user authentication settings') is partially correct but incomplete. It mentions restoring encryption and authentication but omits the critical port protection and removable media encryption aspects, making it less comprehensive than Option D.


CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 20: 'Endpoint Security Client' (describes FDE and MEPP components).

CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 217: 'Check Point Full Disk Encryption' (details encryption settings for hard disks).

CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 280: 'Media Encryption & Port Protection' (covers port protection and removable media encryption settings).

Question 7

What connection options does Connection Awareness support?

Correct Answer: D. There are two options: Connected to Management and Connected to a List of Specified Targets
Explanation:

Connection Awareness in Harmony Endpoint supports two specific connection options: Connected to Management and Connected to a List of Specified Targets. This is detailed in the CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf on page 27 under the 'Client to Server Communication' section. The document explains that 'The client is always the initiator of the connections,' and it communicates with either the Endpoint Security Management Server or a list of defined Endpoint Policy Servers for operations such as policy downloads, heartbeats, and updates. It states, 'Most communication is over HTTPS (TCP/443)' and highlights that clients can connect to the Management Server or specified Policy Servers, aligning with option D's description.

Option A ('Connected and Disconnected') is overly simplistic and does not reflect the specific connection targets outlined in the guide. Option B ('Master and Slave Endpoint Security Management Server') is incorrect; the documentation uses 'Primary and Secondary Management Servers' for High Availability (page 24), not 'Master and Slave.' Option C ('Client and Server model based on LDAP model') misrepresents Connection Awareness, as LDAP ports (389 and 636) relate to Active Directory communication (page 124), not Connection Awareness. Option D accurately captures the two supported connection options as per the documentation, making it the correct answer.


CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 27: Client to Server Communication (describes client connections to Management or Policy Servers).

CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 24: Endpoint Security Architecture (clarifies Primary and Secondary server roles).

CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 124: Active Directory Scanner (mentions LDAP ports, unrelated to Connection Awareness).

Question 8

Full Disk Encryption (FDE) protects data at rest stored on a Hard Drive.

Correct Answer: D. Hard Drive
Explanation:

Full Disk Encryption (FDE) in Check Point Harmony Endpoint is designed to protect data at rest stored on the Hard Drive of desktops and laptops. This is explicitly outlined in the CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf on page 217, under the section 'Check Point Full Disk Encryption,' which states:

'Combines Pre-boot protection, boot authentication, and strong encryption to make sure that only authorized users are given access to information stored on desktops and laptops.'

This indicates that FDE encrypts the entire hard drive, securing all data stored on it when the device is powered off or in a resting state. Further clarification comes from page 220, under 'Volume Encryption,' where it discusses encrypting 'volumes,' referring to the hard drive partitions:

'Volume Encryption - Enable this option to encrypt specified volumes on the endpoint computer.'

Since a hard drive is the primary local storage medium on endpoint devices, Option D ('Hard Drive') is the correct answer.

Option A ('RAM Drive') is incorrect because RAM (Random Access Memory) is volatile memory that does not store data at rest; it loses data when power is off, unlike a hard drive.

Option B ('SMB Share') and Option C ('NFS Share') are incorrect because these are network-based file shares (Server Message Block and Network File System, respectively), not local storage devices protected by FDE. FDE focuses on local hard drives, not network resources.


CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 217: 'Check Point Full Disk Encryption' (describes protecting data stored on desktops and laptops).

CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 220: 'Volume Encryption' (confirms encryption targets hard drive volumes).

Question 9

What capabilities does the Harmony Endpoint NGAV include?

Correct Answer: A. Anti-Ransomware, Anti-Exploit & Behavioral Guard
Explanation:

Harmony Endpoint's Next-Generation Anti-Virus (NGAV) is designed to combat advanced threats using a combination of behavioral analysis, exploit prevention, and ransomware protection. The documentation specifies that NGAV includes Anti-Ransomware, Anti-Exploit, and Behavioral Guard as core capabilities.

The CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf outlines these on page 20, under 'Endpoint Security Client':

'Harmony Endpoint Anti-Ransomware, Behavioral Guard and Forensics: Prevents ransomware attacks. Monitors files and the registry for suspicious processes and network activity. Analyzes incidents reported by other components.'

Additionally, on page 358, under 'Harmony Endpoint Threat Extraction, Emulation and Anti-Exploit':

'Anti-Exploit: Detects and prevents exploitation of vulnerabilities in software.'

While the term 'NGAV' is not explicitly used, these components---Anti-Ransomware, Behavioral Guard, and Anti-Exploit---represent the next-generation approach to antivirus protection, focusing on behavior-based detection and prevention of advanced threats like exploits and ransomware. This matches Option A.

The other options are incorrect:

Option B ('Anti-IPS, Anti-Firewall & Anti-Guard'): These are not recognized capabilities in the documentation; they appear to be fabricated terms.

Option C ('Zero-Phishing, Anti-Bot & Anti-Virus'): Zero-Phishing (page 366) and Anti-Bot (page 353) are separate features, and Anti-Virus is traditional, not NGAV-specific.

Option D ('Threat Extraction, Threat-Emulation & Zero-Phishing'): These relate to document sanitization and phishing protection (pages 358-366), not NGAV's core focus.

Thus, Option A accurately reflects Harmony Endpoint NGAV capabilities.


CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 20: 'Endpoint Security Client' (lists Anti-Ransomware and Behavioral Guard).

CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 358: 'Harmony Endpoint Threat Extraction, Emulation and Anti-Exploit' (mentions Anti-Exploit).

Question 10

How many security levels can you set when enabling Remote Help on pre-boot?

Correct Answer: C. Three levels - Low security, Medium security, High security
Explanation:

Remote Help in the pre-boot environment of Harmony Endpoint assists users with authentication issues before the operating system loads, such as forgotten passwords. The security levels for this feature are configurable to balance usability and security, as detailed in the Check Point Harmony Endpoint Server Administration Guide R81.20.

On page 227, under 'Advanced Pre-boot Settings,' the guide specifies:

'Remote Help Security Level: Select the security level for Remote Help. Options are Low, Medium, or High.'

This extract unequivocally lists three security levels---Low, Medium, and High---directly corresponding to Option C. These levels likely adjust the complexity or length of the challenge-response process, though the guide does not elaborate on the exact differences beyond their availability as options.

Assessing the other choices:

Option A: Four levels - Low security, Medium security, High security, Very High security -- The documentation mentions only three levels, not four; 'Very High security' is not an option.

Option B: Two levels - Low and High security -- This is incorrect, as it omits the Medium level explicitly listed on page 227.

Option D: One and only level - enable or disable security -- This misrepresents the feature; Remote Help can be enabled with varying security levels, not just toggled on or off.

The precise wording on page 227 confirms that Option C accurately reflects the three configurable security levels for Remote Help in pre-boot.


CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 227: 'Advanced Pre-boot Settings' (Remote Help security levels).