Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Checkpoint 156-836 Check Point Certified Maestro Expert (CCME) R81.X Exam Practice Test

Page: 1 / 9
Total 88 questions

Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

What is the Correction Layer mechanism?

Options:

A.

Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.

B.

The load-balancing mechanism used by the MHO.

C.

The MHO's distribution algorithm which determines the handling SGM for a given connection.

D.

Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.

Question 2

What is a security group?

Options:

A.

A solution for Security Gateway redundancy and Load Sharing.

B.

A set of appliances of the same model that are collectively managed by the MHO.

C.

A set of network interfaces and individual SGMs assigned to a logical group.

D.

A set of objects in SmartConsole that are responsible for enforcing an access policy.

Question 3

Splitter cannot be used _______

Options:

A.

To connect single port on orchestrator to the same Appliance

B.

To connect single port on orchestrator to multiple port on external switch

C.

To connect single port on Appliance to multiple ports on the orchestrator

D.

To connect single port on orchestrator to multiple Appliances

Question 4

Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL.

Options:

A.

Fast Accelerator

B.

hypersync

C.

rate limiting

D.

SecureXL

Question 5

What is one benefit of a Dual MHO environment?

Options:

A.

Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.

B.

Dual MHOs allow better synchronization to occur between SGMs.

C.

Dual MHOs allow additional SGMs to be added to the SG.

D.

Dual MHOs can be used to achieve increased scalability and redundancy..

Question 6

When a VPN tunnel is formed with a Maestro SGM,

Options:

A.

The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

B.

SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner.

C.

The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.

D.

The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.

Question 7

What is the maximum number of Appliances within Security group in Dual-Site configuration?

Options:

A.

28

B.

31

C.

15

D.

16

Question 8

How many orchestrators may Dual-Site include?

Options:

A.

2 or 4

B.

2

C.

1

D.

Only 4

Question 9

Where should sx_api_ports_dump.py command be ran?

Options:

A.

Management server

B.

Security Group

C.

Orchestrator

D.

SMO Appliance

Question 10

During an upgrade, Is Multi-Version Clustering (MVC) supported?

Options:

A.

No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.

B.

No, Maestro does not support MVC.

C.

Maestro supports MVC or full connectivity upgrade as of R80.40.

D.

Yes, MVC is supported as of R81 for Maestro.

Question 11

Is it possible to define distribution mode per interface?

Options:

A.

Yes, only for downlink interfaces

B.

No, only for the Security Group

C.

Yes, only for uplink interfaces

D.

Yes, for both uplink and downlink interfaces

Question 12

Each morning at 1:00 am, a series of automatic diagnostics on all the SGMs runs by automatic execution of which command?

Options:

A.

hcp -r all

B.

asg diag list

C.

asg diag verify

D.

asg perf -v

Question 13

For the MHO-175, which ports are Management ports?

Options:

A.

Ports 49 - 55 are Management ports.

B.

Ports 1 - 4 are Management ports.

C.

Ports 27 - 47 are Management ports.

D.

Ports 5 - 26 are Management ports.

Question 14

What will happen in case of NAT of the traffic passing through Management network?

Options:

A.

This traffic will not pass correction, since it will be dropped

B.

Orchestrator will disable NAT and traffic will pass with no issue

C.

Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances

D.

This traffic will pass with no inspection

Question 15

How does HyperSync work in a Dual Site environment?

Options:

A.

Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.)

B.

Each active connection has a backup connection on the second site (remote site.)

C.

Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.)

D.

Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs.

Question 16

What command should be used for collecting diagnostic information about the orchestrator?

Options:

A.

cpinfo

B.

asg perf -v

C.

cpview

D.

orch_info

Question 17

In case of Correction, where is information about Owner stored?

Options:

A.

In Correction table of Target Appliance

B.

In Connection tables of all Appliances participating in Correction Layer flow

C.

In Correction tables of all Appliances participating in Correction Layer flow

D.

In Connection table of Target Appliances

Question 18

What happens if the SMO Master fails?

Options:

A.

The next SGM with the current lowest SGM ID assumes the role of the SMO Master.

B.

The Backup SMO Master will take over in the event of a failure with the SMO Master.

C.

A failover will occur on the MHO and traffic will continue to pass.

D.

The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.

Question 19

In what mode do MHOs process traffic?

Options:

A.

MHOs process traffic in load sharing mode

B.

MHOs process traffic in Active-Standby mode

C.

MHOs process traffic in Active-Active mode

D.

MHOs process traffic in VSLS mode

Question 20

The drop_monitor command is useful for

Options:

A.

Monitoring Check Point code drops

B.

Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR

C.

Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.

D.

Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.

Question 21

What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?

Options:

A.

1Gbps connectivity for Security Groups

B.

Reserved for internal purposes. Not in use.

C.

Out-of-band interfaces for access to Orchestrator itself

D.

Additional ports used as uplinks

Question 22

Maestro allows running commands globally in Expert mode by using global prefixes, such as:

Options:

A.

asg all

B.

g_all

C.

all

D.

global

Question 23

What does asg monitor command do?

Options:

A.

This command does not exist

B.

Monitor health status of entire system

C.

Monitor traffic on Appliances in Security Group

D.

Show real-time cluster status of Appliances in Security Group

Question 24

What is the difference between Dual-Site and Dual-Room?

Options:

A.

Dual-Room is a kind of Dual-Site deployment within the same building

B.

Dual-Room is Active / Standby and Dual-Site is Active / Active

C.

Dual-Room is a Single-Site deployment where all Appliances are connected to both orchestrators

D.

They are the same

Question 25

When security policy is installed

Options:

A.

All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.

B.

The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.

C.

All SGMs receive the security policy and simultaneous policy installation occurs.

D.

The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.

Question 26

Where should the sx_api_ports_dump.py command be run?

Options:

A.

Management server

B.

Security Group

C.

Orchestrator

D.

SMO Appliance

Page: 1 / 9
Total 88 questions