Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Checkpoint 156-836 Dumps

Page: 1 / 9
Total 88 questions

Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Question 1

In case of Correction, where is information about Owner stored?

Options:

A.

In Correction table of Target Appliance

B.

In Connection tables of all Appliances participating in Correction Layer flow

C.

In Correction tables of all Appliances participating in Correction Layer flow

D.

In Connection table of Target Appliances

Question 2

What is one benefit of a Dual MHO environment?

Options:

A.

Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.

B.

Dual MHOs allow better synchronization to occur between SGMs.

C.

Dual MHOs allow additional SGMs to be added to the SG.

D.

Dual MHOs can be used to achieve increased scalability and redundancy..

Question 3

What is the difference between Dual-Site and Dual-Room?

Options:

A.

Dual-Room is a kind of Dual-Site deployment within the same building

B.

Dual-Room is Active / Standby and Dual-Site is Active / Active

C.

Dual-Room is a Single-Site deployment where all Appliances are connected to both orchestrators

D.

They are the same

Question 4

What kinds of transceivers are supported on Orchestrator MHO-140?

Options:

A.

SFP, QSFP, QSFP28

B.

SFP+, SFP28, QSFP

C.

SFP, SFP+, SFP28

D.

SFP, SFP+, QSFP, QSFP28

Question 5

Which distribution mode assigns packets to an SGM based solely on the packet destination IP?

Options:

A.

User mode

B.

Manual mode

C.

Network mode

D.

Auto-topology mode

Question 6

Which command do you use to find bottlenecks in the system that are affecting performance, even functionality in some cases?

Options:

A.

asg stat -v

B.

asg diag verify

C.

asg perf -v

D.

asg monitor

Question 7

What happens if the SMO Master fails?

Options:

A.

The next SGM with the current lowest SGM ID assumes the role of the SMO Master.

B.

The Backup SMO Master will take over in the event of a failure with the SMO Master.

C.

A failover will occur on the MHO and traffic will continue to pass.

D.

The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.

Question 8

What is the purpose of interface bonding?

Options:

A.

A bond interface can be configured for high availability redundancy.

B.

A bond interface is used for passing synchronization traffic between the SGMs.

C.

For load sharing which increases connection throughput above that which is possible using one physical interface.

D.

A bond interface can be configured for high availability redundancy or for load sharing which increases connection throughput above that which is possible using one physical interface.

Question 9

What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?

Options:

A.

1Gbps connectivity for Security Groups

B.

Reserved for internal purposes. Not in use.

C.

Out-of-band interfaces for access to Orchestrator itself

D.

Additional ports used as uplinks

Question 10

HealthCheck Point _____

Options:

A.

is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.

B.

performs a system health check and is meant to replace both a CPInfo and the health check script.

C.

can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.

D.

is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.

Question 11

The ______________ command will allow users to update the specified file on all SGMs.

Options:

A.

g_update_conf_file

B.

g_all"

C.

sed

D.

g_cat

Question 12

What type of cluster can a Security Group can be compared to?

Options:

A.

Load Sharing Active / Active

B.

VSLS

C.

Active / Backup

D.

Active / Standby

Question 13

In a Maestro Dual Site environment, what is the definition of the term Active Site.

Options:

A.

The Active Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover.

B.

The Active Site is the site where the SMO Master exists.

C.

There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.

D.

The Active Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.

Question 14

Which command should be used to restart Orchestrator service only?

Options:

A.

orchd restart

B.

reboot

C.

service orchestrator restart

D.

cpstop; cpstart

Question 15

When security policy is installed

Options:

A.

All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.

B.

The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.

C.

All SGMs receive the security policy and simultaneous policy installation occurs.

D.

The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.

Question 16

Which licenses should be issued for the Orchestrator?

Options:

A.

No licenses are required for Orchestrator

B.

Depends on Software Blades enabled on connected appliances

C.

The Orchestrator is considered a Management server, hence it's licensed the same way

D.

The Orchestrator requires NGTX license

Question 17

The core four manual diagnostic tools include:

asg diag verify, asg perf -v, orch_stat -all, and

Options:

A.

asg diag verify

B.

cpinfo

C.

hcp -r all

D.

asg stat -v

Question 18

Splitter cannot be used _______

Options:

A.

To connect single port on orchestrator to the same Appliance

B.

To connect single port on orchestrator to multiple port on external switch

C.

To connect single port on Appliance to multiple ports on the orchestrator

D.

To connect single port on orchestrator to multiple Appliances

Question 19

Logs without a dedicated log file can be found in

Options:

A.

/var/log/junk.log.dbg

B.

/var/log/messages

C.

$RTDIR/log/junk.log

D.

$FWDIR/log/fw.log

Question 20

What cannot be a reason for "Failed to get remote orchestrator interfaces" error message, when clicking on "Orchestrator" in WebUI

Options:

A.

Remote orchestrator has no empty interfaces

B.

Single orchestrator environment, but configured Orchestrator amount is 2

C.

One orchestrator only, but Orchestrator amount is 2 or no Sync in between orchestrators

D.

No Sync between orchestrators

Question 21

Common Layer 1 issues include

Options:

A.

Routing

B.

Distribution

C.

MAC addresses

D.

Loose or bad cables

Question 22

What does the lldpctl command do?

Options:

A.

Show all devices discovered by LLDP protocol on downlink ports

B.

Show all devices discovered by LLDP protocol on all ports

C.

Discover orchestrators

D.

Show all devices discovered by LLDP protocol on uplink ports

Question 23

What will happen in case of NAT of the traffic passing through Management network?

Options:

A.

This traffic will not pass correction, since it will be dropped

B.

Orchestrator will disable NAT and traffic will pass with no issue

C.

Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances

D.

This traffic will pass with no inspection

Question 24

The __________

command can be used during an upgrade to verify that the upgraded SGMs have returned to UP status before upgrading other SGMs.

Options:

A.

asg monitor

B.

cpview

C.

asg perf -v

D.

watch asg stat -v

Question 25

What happens when you make changes from Clish on the SMO Master?

Options:

A.

The changes are synchronized to the SMS/MDS as a backup.

B.

The changes are synchronized to the MHO as a backup.

C.

Changes are only applied on the SMO Master.

D.

Changes are applied to all members in the SG.

Question 26

What can be learned from the output of sx_api_ports_dump.py command?

Options:

A.

Information about backplane bonds

B.

Information about Security Groups

C.

Orchestrator port status

D.

Information about downlink ports only

Page: 1 / 9
Total 88 questions