Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Checkpoint 156-836 Dumps Questions Answers

Page: 1 / 7
Total 88 questions

Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Question 1

During an upgrade, Is Multi-Version Clustering (MVC) supported?

Options:

A.

No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.

B.

No, Maestro does not support MVC.

C.

Maestro supports MVC or full connectivity upgrade as of R80.40.

D.

Yes, MVC is supported as of R81 for Maestro.

Buy Now
Question 2

Possibilities for a failure in a single SGM of a Security Group include.

Options:

A.

A change was made with clish instead of gClish, causing the SGM to handle traffic differently than the other SGMs.

B.

SecureXL is not enabled on the SGM.

C.

An administrator imported a hotfix into the CPUSE repository of a single SGM.

D.

There are too many active SGMs in the SG.

Question 3

When a VPN tunnel is formed with a Maestro SGM,

Options:

A.

The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

B.

SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner.

C.

The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.

D.

The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.

Question 4

In what mode do MHOs process traffic?

Options:

A.

MHOs process traffic in load sharing mode

B.

MHOs process traffic in Active-Standby mode

C.

MHOs process traffic in Active-Active mode

D.

MHOs process traffic in VSLS mode

Question 5

What happens if you apply a hotfix using gClish?

Options:

A.

If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time.

B.

If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so.

C.

Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A."

D.

If you apply a hotfix using gclish, the operation will fail because an outage would occur.

Question 6

What is the Orchestrator?

Options:

A.

Network Switch

B.

Manager of compute and network resources, load balancer and network switch

C.

Load balancer

D.

None of above

Question 7

The core four manual diagnostic tools include:

asg diag verify, asg perf -v, orch_stat -all, and

Options:

A.

asg diag verify

B.

cpinfo

C.

hcp -r all

D.

asg stat -v

Question 8

Which command can be used during an upgrade to verify that the upgraded SGMs have returned to UP status before upgrading other SGMs?

Options:

A.

asg monitor

B.

cpview

C.

asg perf -v

D.

asg stat -v

Question 9

What is the difference between Dual-Site and Dual-Room?

Options:

A.

Dual-Room is a kind of Dual-Site deployment within the same building

B.

Dual-Room is Active / Standby and Dual-Site is Active / Active

C.

Dual-Room is a Single-Site deployment where all Appliances are connected to both orchestrators

D.

They are the same

Question 10

How does HyperSync work in a Dual Site environment?

Options:

A.

Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.)

B.

Each active connection has a backup connection on the second site (remote site.)

C.

Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.)

D.

Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs.

Question 11

In a Maestro Dual Site environment, what is the definition of the term Standby Site?

Options:

A.

The Standby Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover.

B.

There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.

C.

The Standby Site is the second site to have been defined in the process of configuring the Dual Site environment.

D.

The Standby Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.

Question 12

What type of license is required for an MHO?

Options:

A.

The MHO requires a NGTP license.

B.

The MHO requires a VSX license.

C.

The MHO does not require a license.

D.

A license is needed for each attached SGM.

Question 13

Which distribution mode assigns packets to an SGM based solely on the packet destination IP?

Options:

A.

User mode

B.

Manual mode

C.

Network mode

D.

Auto-topology mode

Question 14

What will happen in case of NAT of the traffic passing through Management network?

Options:

A.

This traffic will not pass correction, since it will be dropped

B.

Orchestrator will disable NAT and traffic will pass with no issue

C.

Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances

D.

This traffic will pass with no inspection

Question 15

Maestro allows running commands globally in Expert mode by using global prefixes, such as:

Options:

A.

asg all

B.

g_all

C.

all

D.

global

Question 16

The ______________ command will allow users to update the specified file on all SGMs.

Options:

A.

g_update_conf_file

B.

g_all"

C.

sed

D.

g_cat

Question 17

What is the purpose of g_tcpdump command?

Options:

A.

Collects traffic dump from all Active Appliances within Security Group

B.

Collects traffic dump from CIN network

C.

Collects traffic dump from Sync network

D.

The same as tcpdump, just on Scalable Platform

Question 18

When working with Maestro, what is the difference between using Clish and gClish?

Options:

A.

Clish commands are for testing purposes only and cannot be saved, gClish commands apply to all SG members, by default.

B.

Clish commands apply to all UP SG members, by default. gClish commands apply to all SG members, by default.

C.

Clish commands are run on the SG members. gClish commands are run on the MHO and applied to all connected SG members in a specified group.

D.

Clish commands apply only to a specific SG member. gClish commands apply to all UP SG members, by default.

Question 19

To display processes that are consuming excessive system resources, users should use the_____ command.

Options:

A.

asg perf -v

B.

asg stat -v

C.

top

D.

asg_perf_hogs

Question 20

What command should be used for collecting diagnostic information about the orchestrator?

Options:

A.

cpinfo

B.

asg perf -v

C.

cpview

D.

orch_info

Question 21

Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

Options:

A.

IPS configuration files

B.

fwkern.conf files.

C.

VPN configuration files

D.

Mobile Access configuration files.

Question 22

Do all MHOs need to be upgraded before starting the SGM upgrades?

Options:

A.

During the upgrade process all SGMs should be upgraded before upgrading all of the MHOs.

B.

A minimum of one of the MHOs should be upgraded before starting the SGM upgrades. However, there is no requirement to upgrade all the SGMs during the same maintenancewindow as the MHO

C.

All MHOs must first be upgraded before starting the SGM upgrades However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHOs.

D.

MHOs do not need to be upgraded at all because Maestro supports the use of different versions between the MHOs and SGMs.

Question 23

A splitter cannot be used:

Options:

A.

To connect a single port on an Orchestrator to the same Appliance

B.

To connect a single port on an Orchestrator to multiple ports on an external switch

C.

To connect a single port on an Appliance to multiple ports on the Orchestrator

D.

To connect a single port on an Orchestrator to multiple Appliances

Question 24

What does asg monitor command do?

Options:

A.

This command does not exist

B.

Monitor health status of entire system

C.

Monitor traffic on Appliances in Security Group

D.

Show real-time cluster status of Appliances in Security Group

Question 25

What is an uplink interface used for?

Options:

A.

To connect in between appliances

B.

To connect appliances to customer's infrastructure

C.

To connect Orchestrators to customer’s infrastructure

D.

To connect in between Orchestrators

Question 26

What is HealthCheck Point?

Options:

A.

Is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.

B.

Performs a system health check and is meant to replace both a CPInfo and the health check script.

C.

Can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.

D.

Is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.

Page: 1 / 7
Total 88 questions