
Get 156-836 Actual Free Exam Q&As to Prepare for Your CheckPoint Certification
CheckPoint Actual Free Exam Questions And Answers
The CheckPoint 156-836 exam consists of 90 multiple-choice questions and is delivered through Pearson VUE, a leading provider of computer-based testing. Candidates are given 90 minutes to complete the exam and must score at least 70% to pass. 156-836 exam covers topics such as Maestro management and configuration, troubleshooting, and deployment best practices.
CheckPoint 156-836 (Check Point Certified Maestro Expert - R81 (CCME)) exam is a certification exam that validates the skills and knowledge of professionals in the field of network security. 156-836 exam is designed for individuals who have significant experience in managing, deploying, and troubleshooting Check Point Maestro solutions. 156-836 exam measures the candidate's ability to operate and maintain complex enterprise networks using Check Point Maestro technology.
NEW QUESTION # 53
What is the purpose of g_tcpdump command?
- A. The same as tcpdump, just on Scalable Platform
- B. Collects traffic dump from CIN network
- C. Collects traffic dump from Sync network
- D. Collects traffic dump from all Active Appliances within Security Group
Answer: D
Explanation:
_tcpdump" probably collects traffic dumps from all active appliances within a security group, aligning with the naming convention and function of similar commands in scalable platforms.
References
*Maestro Expert (CCME) Course - Check Point Software, page 331
*What is 'IN' and 'OUT' of g_tcpdump? - Check Point CheckMates2
*CHECK POINT MAESTRO EXPERT, page 23
NEW QUESTION # 54
Possibilities for a failure in a single SGM of a Security Group include.
- A. There are too many active SGMs in the SG.
- B. An administrator imported a hotfix into the CPUSE repository of a single SGM.
- C. A change was made with clish instead of gClish, causing the SGM to handle traffic differently than the other SGMs.
- D. SecureXL is not enabled on the SGM.
Answer: B
Explanation:
Explanation
One of the possible causes of a failure in a single SGM of a Security Group is that an administrator imported a hotfix into the CPUSE repository of a single SGM, instead of using the orchestrator to distribute the hotfix to all the SGMs in the Security Group. This can create a mismatch in the software versions and configurations of the SGMs, and lead to unexpected behavior and errors.
References
*Maestro Expert (CCME) Course - Check Point Software, page 251
*sk172923: The /var/log/messages file does not save Maestro Gaia Clish commands2
*sk180418: Security Gateway Member (SGM) is stuck after it is added to a Security Group with image auto cloning enabled on the Single Management Object (SMO)
NEW QUESTION # 55
How does HyperSync work in a Dual Site environment?
- A. Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs.
- B. Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.)
- C. Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.)
- D. Each active connection has a backup connection on the second site (remote site.)
Answer: B
Explanation:
Explanation
HyperSync is a feature of Maestro that enables stateful synchronization of connections and resources across different sites in a Dual Site environment. HyperSync works by creating two backup connections for each active connection: one on the same site as the active connection, and another on the remote site. This ensures that the connection can be seamlessly resumed in case of a failover event, either within the same site or across the sites. HyperSync uses the Site-Sync port and VLANs to transmit the synchronization packets between the Security Group Members and the Maestro Orchestrators.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*Maestro Frequently Asked Questions (FAQ)
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 56
What is the purpose of g_tcpdump command?
- A. The same as tcpdump, just on Scalable Platform
- B. Collects traffic dump from CIN network
- C. Collects traffic dump from Sync network
- D. Collects traffic dump from all Active Appliances within Security Group
Answer: D
Explanation:
Explanation
_tcpdump" probably collects traffic dumps from all active appliances within a security group, aligning with the naming convention and function of similar commands in scalable platforms.
References
*Maestro Expert (CCME) Course - Check Point Software, page 331
*What is 'IN' and 'OUT' of g_tcpdump? - Check Point CheckMates2
*CHECK POINT MAESTRO EXPERT, page 23
NEW QUESTION # 57
When a VPN tunnel is formed with a Maestro SGM,
- A. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connectionand tunnel owner.
- B. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.
- C. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.
- D. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.
Answer: C
Explanation:
Explanation
In scalable security environments, initial IKE (Internet Key Exchange) handling by a central orchestrator before distributing traffic for encryption is a common approach to maintain efficiency and security.
NEW QUESTION # 58
What happens if the SMO Master fails?
- A. A failover will occur on the MHO and traffic will continue to pass.
- B. The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.
- C. The next SGM with the current lowest SGM ID assumes the role of the SMO Master.
- D. The Backup SMO Master will take over in the event of a failure with the SMO Master.
Answer: C
Explanation:
Explanation
This aligns with the principle of redundancy in network systems, where the next available device with the lowest ID typically takes over management roles in case of a failure.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 91
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 59
When working with Maestro, what is the difference between using Clish and gClish?
- A. Clish commands apply to all UP SG members, by default. gClish commands apply to all SG members, by default.
- B. Clish commands apply only to a specific SG member. gClish commands apply to all UP SG members, by default.
- C. Clish commands are run on the SG members. gClish commands are run on the MHO and applied to all connected SG members in a specified group.
- D. Clish commands are for testing purposes only and cannot be saved, gClish commands apply to all SG members, by default.
Answer: C
NEW QUESTION # 60
What is the command 'asg diag' used for?
- A. Asg diag is used for system diagnostics
- B. Asg diag is used for system backup
- C. Asg diag used for system diagnostics on Chassis only. It does not exist on Maestro
- D. Asg diag is used for creating traffic flow diagrams
Answer: A
Explanation:
The asg diag command is used for system diagnostics on both Maestro and Chassis systems. The asg diag command can perform various tests and checks on the system components, such as hardware, software, network, clock, ARP, and more. The asg diag command can help identify and troubleshoot any issues or errors that may affect the system functionality or performance.
References =
*Check Point Maestro R81.X Administration Guide, page 66, section "asg diag" 1
*Check Point Maestro R81.X Getting Started Guide, page 28, section "asg diag" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 25
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.
checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm
2: https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%
20Maestro%20under%20the%20hood%202022.pptx
NEW QUESTION # 61
What type of cluster can a Security Group be compared to?
- A. Active / Backup
- B. Active / Standby
- C. VSLS
- D. Load Sharing Active / Active
Answer: D
Explanation:
A Security Group (SG) in Check Point Maestro is comparable to a Load Sharing Active/Active cluster. This is because a Security Group consists of multiple Security Group Members (SGMs) that actively share the traffic load, provide high availability, and ensure scalability. Each SGM processes traffic according to the Security Group policy and synchronizes its state with other members, similar to how a Load Sharing Active/Active cluster distributes traffic across multiple nodes.
Exact Extract:
"A Security Group can be compared to a Load Sharing Active/Active cluster because it consists of multiple Security Group Members that share the traffic load and provide high availability and scalability. Each Security Group Member is an active firewall that processes traffic according to the Security Group policy and synchronizes its state with other members. The Maestro Orchestrator acts as a load balancer that distributes the traffic among the Security Group Members based on their capacity and availability."
-Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4
-Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3 Explanation of Options:
* A. Load Sharing Active / Active: Correct, as the Security Group operates like a Load Sharing Active
/Active cluster, with all SGMs actively processing traffic and sharing the load, as described in the documentation.
* B. VSLS: Incorrect, as Virtual System Load Sharing (VSLS) is a specific Check Point clustering mode for Virtual Systems, not directly comparable to a Security Group's architecture.
* C. Active / Backup: Incorrect, as this implies only one node is active while others are passive, which does not align with the active load-sharing nature of Security Groups.
* D. Active / Standby: Incorrect, as this also implies a single active node with standby nodes, whereas all SGMs in a Security Group are active.
References:
Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4 Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3
NEW QUESTION # 62
Which is a key driver for Scalable Platform?
- A. Cloud-level security by maximizing capabilities of existing hardware.
- B. HyperSync provides scalability by reducing overhead.
- C. On-demand flexibility in reconfiguration.
- D. Resiliency is achieved through the use of redundant hardware.
Answer: C
Explanation:
The Scalable Platform software allows you to easily add or remove security gateways from a security group without affecting the existing configuration. You can also use the command line interface or the web UI to reconfigure the security group on demand.
References = Check Point R81.10 for Scalable Platforms - Check Point Software, Scalable Platforms (Maestro and Chassis) comparison between versions - Check Point Software, [Check Point R81.10 AI & ML Driven Threat Prevention and Security Management - Check Point Blog]
NEW QUESTION # 63
The drop_monitor command is useful for
- A. Monitoring Check Point code drops
- B. Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.
- C. Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR
- D. Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.
Answer: B
Explanation:
The drop_monitor command is a tool that monitors and displays the packets that are dropped by the Check Point code or the Gaia OS on the orchestrator and the appliances. It can help troubleshoot network issues and optimize performance. The command shows the drop reason, source, destination, protocol, and port of the dropped packets, as well as the interface and the module that dropped them.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates1
*Support, Support Requests, Training ... - Check Point Software2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge
NEW QUESTION # 64
What is an uplink interface used for?
- A. To connect Orchestrators to customer's infrastructure
- B. To connect in between Orchestrators
- C. To connect in between appliances
- D. To connect appliances to customer's infrastructure
Answer: A
Explanation:
Explanation
Uplink interfaces are used to connect Maestro Hyperscale Orchestrators (MHOs) to the customer's network infrastructure, such as switches, routers, or firewalls. They are also used to send and receive management and control traffic from the customer's network to the MHOs.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 65
Which distribution mode assigns packets to an SGM based solely on the packet destination IP?
- A. User mode
- B. Auto-topology mode
- C. Network mode
- D. Manual mode
Answer: C
Explanation:
Explanation
Network mode is the distribution mode that assigns packets to an SGM based solely on the packet destination IP. In this mode, the Orchestrator uses a hash function to map each destination IP to a specific SGM. This mode ensures that all packets with the same destination IP are processed by the same SGM, regardless of the source IP or port. This mode is suitable for scenarios where the destination IP is the main factor for load balancing, such as NAT or VPN.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-19
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-7
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
NEW QUESTION # 66
What can be learned from the output of sx_api_ports_dump.py command?
- A. Information about backplane bonds
- B. Information about downlink ports only
- C. Information about Security Groups
- D. Orchestrator port status
Answer: A
Explanation:
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3
NEW QUESTION # 67
What does the lldpctl command do?
- A. Show all devices discovered by LLDP protocol on uplink ports
- B. Show all devices discovered by LLDP protocol on all ports
- C. Discover orchestrators
- D. Show all devices discovered by LLDP protocol on downlink ports
Answer: B
Explanation:
The lldpctl command is a tool to display information about the devices discovered by the Link Layer Discovery Protocol (LLDP) on all ports of the Maestro Orchestrator and the Security Group Members. LLDP is a protocol that enables devices to exchange information about their identity, capabilities, and configuration.
LLDP can help to discover the topology and connectivity of the Maestro environment.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.2: LLDP, page 4-9
*Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section:
LLDP, page 3-9
NEW QUESTION # 68
What is the throughput penalty of Security Group?
- A. 5% per member
- B. 10% per Security Group with no relation to the number of members
- C. Depends on the type of Appliance
- D. 1% per member
Answer: D
Explanation:
Explanation
Check Point reduced throughput degradation to 1% per added SGMs. For example, the overall throughput degradation is 10% for 10 SGMs in a Security Group. Check Point aims to reduce this even further in the future.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
NEW QUESTION # 69
What type of license is required for an MHO?
- A. The MHO does not require a license.
- B. The MHO requires a NGTP license.
- C. A license is needed for each attached SGM.
- D. The MHO requires a VSX license.
Answer: A
Explanation:
The MHO (Maestro Hyperscale Orchestrator) does not require a license by itself, but each SGM (Security Group Module) that is attached to the MHO needs a license. The license type depends on the features and blades that are enabled on the SGM. For example, if the SGM is running VSX, it needs a VSX license.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 71
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 70
......
The CCME certification exam consists of 90 questions and is available in multiple languages. 156-836 exam covers a range of topics, including Check Point Maestro deployment and configuration, advanced networking concepts, and troubleshooting and optimization techniques. Those who pass the exam are recognized as experts in the use of Check Point's Maestro technology and are well-equipped to manage and optimize large-scale networks. The CCME certification is an excellent way to demonstrate expertise in the field of IT security and gain a competitive edge in the job market.
156-836 Questions Truly Valid For Your CheckPoint Exam: https://www.exam4free.com/156-836-valid-dumps.html
156-836 Actual Questions - Instant Download Tests Free Updated Today!: https://drive.google.com/open?id=1scmhqwkVzn1pBZe4g3SLtgVppSMhSnUN
