If traffic is passing through the QoS Module matches both rules, which of the following statements is TRUE?

You configure a Check Point QoS Rule Base with two rules: an H.323 rule with a weight of 10, and the Default Rule with a weight of 10. The H.323 rule includes a per-connection guarantee of 384 Kbps. and a per-connection limit of 512 Kbps. The per-connection guarantee is for four connections, and no additional connections are allowed in the Action properties.

If traffic is passing through the QoS Module matches both rules, which of the following statements is TRUE?
A . Each
B . 323 connection will receive at least 512 Kbps of bandwidth.
C . The
D . 323 rule will consume no more than 2048 Kbps of available bandwidth.
E . 50% of available bandwidth will be allocated to the Default Rule.
F . Neither rule will be allocated more than 10% of available bandwidth.

Answer: B

What is a "sticky" connection?

What is a "sticky" connection?
A . A Sticky Connection is one in which a reply packet returns through the same gateway as the original packet.
B . A Sticky Connection is a VPN connection that remains up until you manually bring it down.
C . A Sticky Connection is a connection that remains the same.
D . A Sticky Connection is a connection that always chooses the same gateway to set up the initial connection.

Answer: A

Review the ARP table from the internal Windows host 10.4.8.108. According to the output, which member is the standby machine?

In New Mode HA, the internal cluster IP VIP address is 10.4.8.3. The internal interfaces on two members are 10.4.8.1 and 10.4.8.2. Internal host 10.4.8.108 Pings 10.4.8.3, and receives replies.

Review the ARP table from the internal Windows host 10.4.8.108. According to the output, which member is the standby machine?
A . 10.4.8.3
B . The standby machine cannot be determined by this test.
C . 10.4.8.1
D . 10.4.8.2

Answer: C

How can you completely tear down a specific VPN tunnel in an intranet IKE VPN deployment?

How can you completely tear down a specific VPN tunnel in an intranet IKE VPN deployment?
A . Run the command vpn tu on the Security Gateway, and choose the option "Delete all IPSec+IKE SAs for ALL peers and users".
B . Run the command vpn tu on the Smart Center Server, and choose the option "Delete all IPSec+IKE SAs for ALL peers and users".
C . Run the command vpn tu on the Security Gateway, and choose the option "Delete all IPSec+IKE SAs for a given peer (GW)".
D . Run the command vpn tu on the Security Gateway, and choose the option "Delete all IPSec SAs for a given user (Client)".
E . Run the command vpn tu on the Security Gateway, and choose the option "Delete all IPSec SAs for ALL peers and users".

Answer: C