Certification Path
The Check Point Certified Security Administrator certification path includes only one 156-215.77 certification exam.
Check Point 156-215.77 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Lab 4: Building a Security Policy | - Create Security Gateway Object- Create GUI Client Object - Create Rules for Corporate Gateway - Save the Policy - Install the Policy - Test the Corporate Policy - Create the Remote Security Gateway Object - Create a New Policy for the Branch Office - Combine and Organize Security Policies |
| Remote Access VPNs | - Multiple Remote Access VPN Connectivity Modes- Establishing a Connection Between a Remote User and a Gateway |
| Security Policy Basics | - The Rule Base- Managing Objects in SmartDashboard - SmartDashboard and Objects - Object-Tree Pane - Objects-List Pane - Object Types - Rule Base Pane |
| VPN Deployments | - Site-to-Site VPNs- Remote-Access VPNs |
| VPN Topologies | - Meshed VPN Community- Star VPN Community - Choosing a Topology - Combination VPNs - Topology and Encryption Issues |
| Introduction to Check Point Technology | Objectives:
|
| Security Gateway Inspection Architecture | -INSPECT Engine Packet Flow |
| Introduction to Identity Awareness | - AD Query- Browser-Based Authentication - Identity Agents - Deployment |
| Check Point DeploymentPlatforms | - Security Appliances- Security Software Blades - Remote Access Solutions |
| Introduction to NAT | - IP Addressing- Hid NAT - Choosing the Hide Address in Hide NAT - Static NAT - Original Packet - Reply Packet - NAT Global Properties - Object Configuration - Hid NAT - Hide NAT Using Another Interface - Static NAT |
| SmartView Tracker | - Log Types- SmartView Tracker Tabs - Action Icons - Log-File Management - Administrator Auditing - Global Logging and Alerting - Time Setting - Blocking Connections |
| Access Control and VPN Communities | - Accepting All Encrypted Traffic- Excluded Services - Special Considerations for Planning a VPN Topology |
| Lab 9: Identity Awareness | - Configuring the Security Gateway- Defining the User Access Role - Applying User Access Roles to the Rule Base - Testing Identity Based Awareness - Prepare Rule Base for Next Lab |
| SmartUpdate and Managing Licenses | - SmartUpdate Architecture- SmartUpdate Introduction - Overview of Managing Licenses - License Terminology - Upgrading Licenses - Retrieving License Data from Security Gateways - Adding New Licenses to the License & Contract Repository - Importing License Files - Adding License Details Manually - Attaching Licenses - Detaching Licenses - Deleting Licenses From License & Contract Repository - Installation Process |
| Creating the Rule Base | - Basic Rule Base Concepts- Delete Rule - Basic Rules - Implicit/Explicit Rules - Control Connections - Detecting IP Spoofing - Configuring Anti-Spoofing |
| Securing Channels of Communication | - Secure Internal Communication- Testing the SIC Status - Resetting the Trust State |
| Using SmartUpdate | Objectives:
|
| Client Authentication | - Client Authentication and Sign-On Overview- Sign-On Methods - Wait Mode - Configuring Authentication Tracking |
| Managing Objects | - Classic View of the Objects Tree- Group View of the Objects Tree |
| Lab 3: CLI Tools | - Working in Expert Mode- Applying Useful Commands in CLISH - Add and Delete Administrators via the CLI - Perform Backup and Restore |
| Policy Management andRevision Control | -Policy Package Management - Database Revision Control- Multicasting |
| Check Point SmartConsole Clients | - SmartDashboard- Smartview Tracker - SmartLog - SmartEvent - SmartView Monitor - SmartReporter - SmartUpdate - SmartProvisioning - SmartEndpoint |
| Introduction to the Security Policy | Objectives:
|
| Lab 8: Configuring User Directory | - Connect User Directory to Security- Management Server |
| Monitoring Suspicious Activity Rules | -Monitoring Alerts |
| Network Address Translation | Objectives:
|
| Lab 7: Configure NAT | - Configure Static NAT on the DMZ Server- Test the Static NAT Address - Configure Hide NAT on the Corporate Network - Test the Hide NAT Address - Observe Hide NAT Traffic Using fw monitor - Configure Wireshark - Observe Traffic - Observe Static NAT Traffic Using fw monitor |
| Monitoring Traffic and Connections | Objectives:
|
| Gateway Status | - Overall Status- Software Blade Status - Displaying Gateway Information |
| Integrating VPNs into a Rule Base | - Simplified vs. Traditional Mode VPNs- VPN Tunnel Management - Permanent Tunnels - Tunnel Testing for Permanent Tunnels - VPN Tunnel Sharing |
| Security Gateway Authentication | - Types of Legacy Authentication p. 142- Authentication Schemes p. 143 - Remote User Authentication p. 145 - Authentication Methods p. 146 |
| Session Authentication | -Configuring Session Authentication |
| Lab 6: Monitoring with SmartView Tracker | - Launch SmartView Tracker- Track by Source and Destination - Modify the Gateway to Active - SmartView Monitor |
| Lab 5: Configure the DMZ | - Create DMZ Objects in SmartDashboard- Create DMZ Access Rules - Test the Policy |
| Lab 10: Site-to-site VPN Between Corporate and Branch Office | - Define the VPN Domain- Create the VPN Community - Create the VPN Rule and Modifying the Rule Base - Test VPN Connection - VPN Troubleshooting |
| LDAP User Management with UserDirectory | - LDAP Features- Distinguished Name - Multiple LDAP Servers - Using an Existing LDAP Server - Configuring Entities to Work with the Gateway - Defining an Account Unit - Managing Users - UserDirectory Groups |
| Service Contracts p. | -Managing Contracts Updating Contracts |
| The Check Point VPN | |
| Security ManagementServer | - Managing Users in SmartDashboard- Users Database |
| Deployment Platforms | Objectives:
|
| SmartView Tracker vs.SmartView Monitor | |
| The Check Point Firewall | - OSI Model- Mechanism for controlling - Network traffic. - Packet Filtering - Stateful Inspection - Application Intelligence |
| Special VPN Gateway Conditions | - Authentication Between Community Members- Domain and Route-Based VPNs - Domain-Based VPNs - Route-Based VPN |
| Lab 2: Branch Office Security Gateway Installation | - Install SecurePlatform on Branch Gateway- Configuring Branch Office Security - Gateway with the First time Configuration Wizard - Configure Branch Gateway - WebUI |
| Lab 1: Distributed Installation | - Install Security Management Server- Configure Security Management Server - WebUI - Configuring the Management Server - Install Corporate Security Gateway - Configure Corporate Security Gateway - WebUI - Configuring the Corporate Security Gateway - Installing SmartConsole |
| Manual NAT | - Configuring Manual NAT- Special Considerations - ARP |
| Identity Awareness | Objectives:
|
| User Authentication | - User Authentication Rule Base Considerations |
| VPN Implementation | - VPN Setup- Understanding VPN Deployment - VPN Communities - Remote Access Community |
| Rule Base Management | - Understanding Rule Base Order- Completing the Rule Base |
| User Management and Authentication | Objectives:
|
| Viewing License Properties | -Checking for Expired Licenses To Export a License to a File |
| Check Point SecurityManagement Architecture(SMART) | - SmartConsole- Security Management Server - Security Gateway |
| DeploymentConsiderations | - Standalone Deployment- Distributed Deployment - Standalone Full HA - Bridge Mode |
| Creating Users and Groups | -User Types |
| SmartView Monitor | - Customized Views- Gateway Status View - Traffic View - Tunnels View - Remote Users View - Cooperative Enforcement View |
| Check Point Gaia | - History - Power of Two Gaia- Benefits of Gaia - Gaia Architecture - Gaia System Information |
| Introduction to Check Point VPNs | Objectives:
|
CheckPoint 156-215.77 Exam Overview:
| Certification Vendor: | Check Point Software Technologies |
| Exam Name: | Check Point Certified Security Administrator R77 (CCSA) |
| Exam Number: | 156-215.77 |
| Certificate Validity Period: | 24 months |
| Passing Score: | 70% |
| Related Certifications: | Check Point Certified Security Expert (CCSE R77) Check Point Certified Security Master (CCSM) |
| Exam Price: | $250 USD |
| Exam Duration: | 90 minutes |
| Real Exam Qty: | 90 |
| Exam Format: | Multiple-choice, Scenario-based |
| Available Languages: | English |
| Recommended Training: | Check Point Official CCSA R77 Training |
| Exam Registration: | Pearson VUE Registration |
| Sample Questions: | CheckPoint 156-215.77 Sample Questions |
| Exam Way: | Onsite at Pearson VUE test centers or online proctored via OnVUE |
| Pre Condition: | No mandatory prerequisites; recommended basic networking and TCP/IP knowledge |
| Official Syllabus URL: | https://www.checkpoint.com/training/certification/ccsa/ |

We're so confident of our products that we provide no hassle product exchange.


By Harold


