Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Checkpoint > CCME > 156-836

156-836 Check Point Certified Maestro Expert (CCME) R81.X Question and Answers

Question # 4

In case of Correction, where is information about Owner stored?

A.

In Correction table of Target Appliance

B.

In Connection tables of all Appliances participating in Correction Layer flow

C.

In Correction tables of all Appliances participating in Correction Layer flow

D.

In Connection table of Target Appliances

Full Access
Question # 5

What will happen in case of NAT of the traffic passing through Management network?

A.

This traffic will not pass correction, since it will be dropped

B.

Orchestrator will disable NAT and traffic will pass with no issue

C.

Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances

D.

This traffic will pass with no inspection

Full Access
Question # 6

What is the purpose of g_tcpdump command?

A.

Collects traffic dump from all Active Appliances within Security Group

B.

Collects traffic dump from CIN network

C.

Collects traffic dump from Sync network

D.

The same as tcpdump, just on Scalable Platform

Full Access
Question # 7

Which command should be used to restart Orchestrator service only?

A.

orchd restart

B.

reboot

C.

service orchestrator restart

D.

cpstop; cpstart

Full Access
Question # 8

On the MHO, to view connected ports and their functions, use the following command:

A.

asg_ifconfig

B.

show ports

C.

orch_stat -c

D.

orch_stat -p

Full Access
Question # 9

Do all MHOs need to be upgraded before starting the SGM upgrades?

A.

During the upgrade process all SGMs should be upgraded before upgrading all of the MHOs.

B.

A minimum of one of the MHOs should be upgraded before starting the SGM upgrades. However, there is no requirement to upgrade all the SGMs during the same maintenancewindow as the MHO

C.

All MHOs must first be upgraded before starting the SGM upgrades However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHOs.

D.

MHOs do not need to be upgraded at all because Maestro supports the use of different versions between the MHOs and SGMs.

Full Access
Question # 10

Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL.

A.

Fast Accelerator

B.

hypersync

C.

rate limiting

D.

SecureXL

Full Access
Question # 11

Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?

A.

When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.

B.

When dynamic routing protocols, such as BGP or OSPF are used.

C.

When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.

D.

When the SG is NATing a very high percentage of traffic passing through it.

Full Access
Question # 12

What command will be used for updating fwkern.conf file on all Appliances within Security Group?

A.

vi

B.

g_all update_conf_file

C.

g_update_kernel

D.

g_update_conf_file

Full Access
Question # 13

There are two 10Gbps dual-port NICs and one 40Gbps NIC installed on a 23800 Appliance in slots 1, 2 and 3 accordingly. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-

orchestrator redundancy when using two Orchestrators?

A.

Port 1 in Slot 2 and Port 2 in Slot 1

B.

This configuration is not supported

C.

Any pair of available ports

D.

Port 1 in Slot 1 and Port 2 in Slot 1

Full Access
Question # 14

What does the lldpctl command do?

A.

Show all devices discovered by LLDP protocol on downlink ports

B.

Show all devices discovered by LLDP protocol on all ports

C.

Discover orchestrators

D.

Show all devices discovered by LLDP protocol on uplink ports

Full Access
Question # 15

Which is a key driver for Scalable Platform?

A.

On-demand flexibility in reconfiguration.

B.

HyperSync provides scalability by reducing overhead.

C.

Resiliency is achieved through the use of redundant hardware.

D.

Cloud-level security by maximizing capabilities of existing hardware.

Full Access
Question # 16

How does HyperSync work in a Dual Site environment?

A.

Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.)

B.

Each active connection has a backup connection on the second site (remote site.)

C.

Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.)

D.

Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs.

Full Access
Question # 17

Where should the sx_api_ports_dump.py command be run?

A.

Management server

B.

Security Group

C.

Orchestrator

D.

SMO Appliance

Full Access
Question # 18

Maestro allows running commands globally in Expert mode by using global prefixes, such as:

A.

asg all

B.

g_all

C.

all

D.

global

Full Access
Question # 19

What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?

A.

Two Out-of-band interfaces for access to Orchestrator itself

B.

1Gbps connectivity for Security Groups

C.

Out-of-band interface for access to Orchestrator itself and Serial Console connector

D.

Reserved for internal purposes. Not in use

Full Access
Question # 20

Each morning at 1:00 am, a series of automatic diagnostics on all the SGMs runs by automatic execution of which command?

A.

hcp -r all

B.

asg diag list

C.

asg diag verify

D.

asg perf -v

Full Access
Question # 21

What cannot be learned from the output of lldpctl?

A.

Serial number of Appliance

B.

Appliance model

C.

Distribution mode

D.

Orchestrator's IP

Full Access
Question # 22

In a dual MHO environment, MHO1 and MHO2 are connected to the SGM line cards in which way?

A.

MHO1 and MHO2 are connected to the SGMs using the Sync cable.

B.

MHO1 and MHO2 are connected to the line cards in any order administrators see fit.

C.

MHO 1 is connected to the even-numbered ports, while MHO2 is connected to odd-numbered ports.

D.

MHO 1 is connected to the odd-numbered ports, while MHO2 is connected to even-numbered ports.

Full Access
Question # 23

For the MHO-175, which ports are Management ports?

A.

Ports 49 - 55 are Management ports.

B.

Ports 1 - 4 are Management ports.

C.

Ports 27 - 47 are Management ports.

D.

Ports 5 - 26 are Management ports.

Full Access
Question # 24

In what mode do MHOs process traffic?

A.

MHOs process traffic in load sharing mode

B.

MHOs process traffic in Active-Standby mode

C.

MHOs process traffic in Active-Active mode

D.

MHOs process traffic in VSLS mode

Full Access
Question # 25

Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

A.

IPS configuration files

B.

fwkern.conf files.

C.

VPN configuration files

D.

Mobile Access configuration files.

Full Access
Question # 26

Which command do you use to find bottlenecks in the system that are affecting performance, even functionality in some cases?

A.

asg stat -v

B.

asg diag verify

C.

asg perf -v

D.

asg monitor

Full Access