Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Checkpoint 156-836 Dumps

Page: 1 / 8
Total 75 questions

Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Question 1

What is the default Distribution mode?

Options:

A.

Auto-topology

B.

User

C.

Manual-General

D.

Network

Question 2

In what mode do MHOs process traffic?

Options:

A.

MHOs process traffic in load sharing mode

B.

MHOs process traffic in Active-Standby mode

C.

MHOs process traffic in Active-Active mode

D.

MHOs process traffic in VSLS mode

Question 3

When security policy is installed

Options:

A.

All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.

B.

The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other membersretrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.

C.

All SGMs receive the security policy and simultaneous policy installation occurs.

D.

The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.

Question 4

What is a downlink interface used for?

Options:

A.

To connect appliances to Orchestrators

B.

To connect appliances to customer's infrastructure

C.

To connect in between Orchestrators

D.

To connect Orchestrators to customer's infrastructure

Question 5

What is the command 'asg diag' used for?

Options:

A.

Asg diag used for system diagnostics on Chassis only. It does not exist on Maestro

B.

Asg diag is used for system backup

C.

Asg diag is used for system diagnostics

D.

Asg diag is used for creating traffic flow diagrams

Question 6

What Maestro component acts as a load balancer and network switch?

Options:

A.

Security Switching Module (SSM)

B.

Maestro Hyperscale Orchestrator (MHO)

C.

Security Group (SG)

D.

Security Gateway Module (SGM)

Question 7

What is the maximum number of Appliances within Security group in Dual-Site configuration?

Options:

A.

28

B.

31

C.

15

D.

16

Question 8

In a Maestro Dual Site environment, what is the definition of the term Active Site.

Options:

A.

The Active Site is the site that is not handling any traffic for the specific SG, but itsconnections are synced to its SGMs from the MHOs to be ready in the event of a failover.

B.

The Active Site is the site where the SMO Master exists.

C.

There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.

D.

The Active Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.

Question 9

When a VPN tunnel is formed with a Maestro SGM,

Options:

A.

The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

B.

SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connectionand tunnel owner.

C.

The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.

D.

The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.

Question 10

At a minimum, how many management and Uplink ports does a SG require?

Options:

A.

Only one of the two interfaces is needed for the Security Group.

B.

Neither are required.

C.

Two of each.

D.

One each.

Question 11

What kinds of transceivers are supported on Orchestrator MHO-170?

Options:

A.

SFP, QSFP, QSFP28

B.

SFP+, SFP28, QSFP

C.

SFP, SFP+, SFP28

D.

QSFP, QSFP28

Question 12

What is a security group?

Options:

A.

A solution for Security Gateway redundancy and Load Sharing.

B.

A set of appliances of the same model that are collectively managed by the MHO.

C.

A set of network interfaces and individual SGMs assigned to a logical group.

D.

A set of objects in SmartConsole that are responsible for enforcing an access policy.

Question 13

Which distribution mode assigns packets to an SGM based solely on the packet destination IP?

Options:

A.

User mode

B.

Manual mode

C.

Network mode

D.

Auto-topology mode

Question 14

What is the maximum number of Appliances within Security group in Dual-Site configuration?

Options:

A.

28

B.

31

C.

15

D.

16

Question 15

Which licenses should be issued for the Orchestrator?

Options:

A.

No licenses are required for Orchestrator

B.

Depends on Software Blades enabled on connected appliances

C.

The Orchestrator is considered a Management server, hence it's licensed the same way

D.

The Orchestrator requires NGTX license

Question 16

There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators?

Options:

A.

Any pair of available ports

B.

Port 1 in Slot 1 and Port 1 in Slot 2

C.

Port 1 in Slot 1 and Port 2 in Slot 1

D.

Port 1 in Slot 2 and Port 2 in Slot 1

Question 17

What does the lldpctl command do?

Options:

A.

Show all devices discovered by LLDP protocol on downlink ports

B.

Show all devices discovered by LLDP protocol on all ports

C.

Discover orchestrators

D.

Show all devices discovered by LLDP protocol on uplink ports

Question 18

Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

Options:

A.

IPS configuration files

B.

fwkern.conf files.

C.

VPN configuration files

D.

Mobile Access configuration files.

Question 19

HealthCheck Point _____

Options:

A.

is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.

B.

performs a system health check and is meant to replace both a CPInfo and the health check script.

C.

can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.

D.

is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.

Question 20

How many orchestrators may Dual-Site include?

Options:

A.

2 or 4

B.

2

C.

1

D.

Only 4

Question 21

What is the Correction Layer mechanism?

Options:

A.

Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.

B.

The load-balancing mechanism used by the MHO.

C.

The MHO's distribution algorithm which determines the handling SGM for a given connection.

D.

Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.

Question 22

What kinds of transceivers are supported on Orchestrator MHO-140?

Options:

A.

SFP, QSFP, QSFP28

B.

SFP+, SFP28, QSFP

C.

SFP, SFP+, SFP28

D.

SFP, SFP+, QSFP, QSFP28

Page: 1 / 8
Total 75 questions