Summer Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Checkpoint 156-836 Check Point Certified Maestro Expert (CCME) R81.X Exam Practice Test

Page: 1 / 9
Total 88 questions

Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Question 1

Is it possible to define distribution mode per interface?

Options:

A.

Yes, only for downlink interfaces

B.

No, only for the Security Group

C.

Yes, only for uplink interfaces

D.

Yes, for both uplink and downlink interfaces

Question 2

Each morning at 1:00 am, a series of automatic diagnostics on all the SGMs runs by automatic execution of which command?

Options:

A.

hcp -r all

B.

asg diag list

C.

asg diag verify

D.

asg perf -v

Question 3

Logs without a dedicated log file can be found in

Options:

A.

/var/log/junk.log.dbg

B.

/var/log/messages

C.

$RTDIR/log/junk.log

D.

$FWDIR/log/fw.log

Question 4

What cannot be a reason for "Failed to get remote orchestrator interfaces" error message, when clicking on "Orchestrator" in WebUI

Options:

A.

Remote orchestrator has no empty interfaces

B.

Single orchestrator environment, but configured Orchestrator amount is 2

C.

One orchestrator only, but Orchestrator amount is 2 or no Sync in between orchestrators

D.

No Sync between orchestrators

Question 5

What happens if the SMO Master fails?

Options:

A.

The next SGM with the current lowest SGM ID assumes the role of the SMO Master.

B.

The Backup SMO Master will take over in the event of a failure with the SMO Master.

C.

A failover will occur on the MHO and traffic will continue to pass.

D.

The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.

Question 6

What is the max amount of Orchestrators in Dual-site setup?

Options:

A.

2 per Security Group

B.

4 per Security Group

C.

2

D.

4

Question 7

What is the default Distribution mode?

Options:

A.

Auto-topology

B.

User

C.

Manual-General

D.

Network

Question 8

Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

Options:

A.

IPS configuration files

B.

fwkern.conf files.

C.

VPN configuration files

D.

Mobile Access configuration files.

Question 9

How many orchestrators may Dual-Site include?

Options:

A.

2 or 4

B.

2

C.

1

D.

Only 4

Question 10

Which command can be used during an upgrade to verify that the upgraded SGMs have returned to UP status before upgrading other SGMs?

Options:

A.

asg monitor

B.

cpview

C.

asg perf -v

D.

asg stat -v

Question 11

There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?

Options:

A.

Between 2 and 4

B.

All 10

C.

2

D.

3

Question 12

There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators?

Options:

A.

Any pair of available ports

B.

Port 1 in Slot 1 and Port 1 in Slot 2

C.

Port 1 in Slot 1 and Port 2 in Slot 1

D.

Port 1 in Slot 2 and Port 2 in Slot 1

Question 13

When working with Maestro, what is the difference between using Clish and gClish?

Options:

A.

Clish commands are for testing purposes only and cannot be saved, gClish commands apply to all SG members, by default.

B.

Clish commands apply to all UP SG members, by default. gClish commands apply to all SG members, by default.

C.

Clish commands are run on the SG members. gClish commands are run on the MHO and applied to all connected SG members in a specified group.

D.

Clish commands apply only to a specific SG member. gClish commands apply to all UP SG members, by default.

Question 14

What cannot be learned from the output of lldpctl?

Options:

A.

Serial number of Appliance

B.

Appliance model

C.

Distribution mode

D.

Orchestrator's IP

Question 15

To display processes that are consuming excessive system resources, users should use the_____ command.

Options:

A.

asg perf -v

B.

asg stat -v

C.

top

D.

asg_perf_hogs

Question 16

What is the maximum number of Appliances within the same Security Group?

Options:

A.

31

B.

8

C.

52

D.

16

Question 17

What is the Correction Layer?

Options:

A.

Correction Layer is a daemon which corrects errors on Backplane interfaces

B.

Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT

C.

Correction Layer is a mechanism which activated in case of asymmetric routing

D.

Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute

Question 18

In case of Correction, where is information about Owner stored?

Options:

A.

In Correction table of Target Appliance

B.

In Connection tables of all Appliances participating in Correction Layer flow

C.

In Correction tables of all Appliances participating in Correction Layer flow

D.

In Connection table of Target Appliances

Question 19

What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?

Options:

A.

Two Out-of-band interfaces for access to Orchestrator itself

B.

1Gbps connectivity for Security Groups

C.

Out-of-band interface for access to Orchestrator itself and Serial Console connector

D.

Reserved for internal purposes. Not in use

Question 20

There are two 10Gbps dual-port NICs and one 40Gbps NIC installed on a 23800 Appliance in slots 1, 2 and 3 accordingly. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-

orchestrator redundancy when using two Orchestrators?

Options:

A.

Port 1 in Slot 2 and Port 2 in Slot 1

B.

This configuration is not supported

C.

Any pair of available ports

D.

Port 1 in Slot 1 and Port 2 in Slot 1

Question 21

What command will be used for updating fwkern.conf file on all Appliances within Security Group?

Options:

A.

vi

B.

g_all update_conf_file

C.

g_update_kernel

D.

g_update_conf_file

Question 22

How does HyperSync work in a Dual Site environment?

Options:

A.

Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.)

B.

Each active connection has a backup connection on the second site (remote site.)

C.

Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.)

D.

Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs.

Question 23

What is a security group?

Options:

A.

A solution for Security Gateway redundancy and Load Sharing.

B.

A set of appliances of the same model that are collectively managed by the MHO.

C.

A set of network interfaces and individual SGMs assigned to a logical group.

D.

A set of objects in SmartConsole that are responsible for enforcing an access policy.

Question 24

In what mode do MHOs process traffic?

Options:

A.

MHOs process traffic in load sharing mode

B.

MHOs process traffic in Active-Standby mode

C.

MHOs process traffic in Active-Active mode

D.

MHOs process traffic in VSLS mode

Question 25

There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?

Options:

A.

100%/0%

B.

33%/66%

C.

50%/50%

D.

66%/33%

Question 26

Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?

Options:

A.

When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.

B.

When dynamic routing protocols, such as BGP or OSPF are used.

C.

When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.

D.

When the SG is NATing a very high percentage of traffic passing through it.

Page: 1 / 9
Total 88 questions