
CheckPoint 156-836 Real Exam Questions and Answers FREE
Exam Dumps 156-836 Practice Free Latest CheckPoint Practice Tests
CheckPoint 156-836 certification exam is an essential certification for IT professionals who work with Check Point Maestro. Check Point Certified Maestro Expert - R81 (CCME) certification provides IT professionals with the knowledge and skills necessary to design, deploy, and manage Maestro networks effectively. Check Point Certified Maestro Expert - R81 (CCME) certification also demonstrates that an individual possesses the expertise required to manage complex network environments and troubleshoot issues that may arise. Obtaining this certification can lead to better job opportunities and increased earning potential in the field of network security.
The Check Point Maestro has emerged as a highly sought-after solution in the networking industry, as it enables organizations to scale their security infrastructure in line with their business needs. The CCME certification exam is designed to equip IT professionals with the skills and knowledge they need to effectively deploy and manage Check Point Maestro in their organizations. Check Point Certified Maestro Expert - R81 (CCME) certification is recognized globally and is highly valued by organizations that rely on Check Point solutions for their security needs.
NEW QUESTION # 26
What command can be run to show which SGM is selected to receive traffic?
- A. asg calc
- B. asg monitor
- C. g_tcpdump
- D. dxl calc
Answer: A
Explanation:
Explanation
The asg calc command is a tool to show which SGM is selected to receive traffic based on the distribution mode and the packet parameters. It takes the port number, the source IP, the destination IP, and optionally the source port and the destination port as arguments and returns the SGM ID and the hash value. For example, asg calc 1 10.0.0.1 20.0.0.2 1234 80 will show which SGM will receive the traffic from 10.0.0.1:1234 to
20.0.0.2:80 on port 1.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using theCommand Line Interface and WebUI, Lesson 4.1: asg calc, page 4-5
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: asg calc, page 4-5
*asg calc - Check Point Software
NEW QUESTION # 27
The drop_monitor command is useful for
- A. Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.
- B. Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.
- C. Monitoring Check Point code drops
- D. Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR
Answer: B
Explanation:
Explanation
The drop_monitor command is a tool that monitors and displays the packets that are dropped by the Check Point code or the Gaia OS on the orchestrator and the appliances. It can help troubleshoot network issues and optimize performance. The command shows the drop reason, source, destination, protocol, and port of the dropped packets, as well as the interface and the module that dropped them.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates1
*Support, Support Requests, Training ... - Check Point Software2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge
NEW QUESTION # 28
Is it possible to define distribution mode per interface?
- A. Yes, only for downlink interfaces
- B. Yes, for both uplink and downlink interfaces
- C. No, only for the Security Group
- D. Yes, only for uplink interfaces
Answer: B
Explanation:
Explanation
Maestro allows you to define the distribution mode per interface, which determines how traffic is distributed among the Security Group Modules (SGMs) in a Security Group. You can configure the distribution mode for each interface individually, or use the default mode for all interfaces. The distribution mode can be set for both uplink and downlink interfaces.
References =
*Check Point Maestro R81.X Administration Guide, page 62, section "Distribution Mode" 1
*Check Point Maestro R81.X Getting Started Guide, page 25, section "Distribution Mode" 2
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
NEW QUESTION # 29
What cannot be a reason for "Failed to get remote orchestrator interfaces" error message, when clicking on
"Orchestrator" in WebUI
- A. Remote orchestrator has no empty interfaces
- B. One orchestrator only, but Orchestrator amount is 2 or no Sync in between orchestrators
- C. Single orchestrator environment, but configured Orchestrator amount is 2
- D. No Sync between orchestrators
Answer: A
Explanation:
Explanation
One of the possible reasons for the "Failed to get remote orchestrator interfaces" error message, when clicking on "Orchestrator" in WebUI, is that the remote orchestrator has no empty interfaces that can be assigned to a security group. This can happen if all the interfaces on the remote orchestrator are already part of configured security groups, or if the remote orchestrator has no physical interfaces at all. In this case, the WebUI cannot display the unassigned interfaces of the remote orchestrator, and shows the error message.
References
*Not able to see unassigned interfaces on checkpoint Orchestrator
*Maestro 140 not detecting Interfaces
*Maestro Expert (CCME) Course - Check Point Software, page
NEW QUESTION # 30
What cannot be learned from the output of lldpctl?
- A. Distribution mode
- B. Appliance model
- C. Orchestrator's IP
- D. Serial number of Appliance
Answer: A
Explanation:
Explanation
The lldpctl command is a tool to display information about the devices discovered by the Link Layer Discovery Protocol (LLDP) on all ports of the Maestro Orchestrator and the Security Group Members. LLDP is a protocol that enables devices to exchange information about their identity, capabilities, and configuration.
LLDP can help to discover the topology and connectivity of the Maestro environment. The output of lldpctl can show the serial number, appliance model, and orchestrator's IP of the connected devices, but it cannot show the distribution mode of the Security Group. The distribution mode is the algorithm that determines how the Maestro Orchestrator distributes the traffic among the Security Group Members. To view the distribution mode, other commands such as asg monitor or asg stat can be used.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.2: LLDP, page 4-9
*Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section:
LLDP, page 3-9
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-7
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Log and Configuration Files - Check Point Software
NEW QUESTION # 31
What will happen in case of NAT of the traffic passing through Management network?
- A. This traffic will not pass correction, since it will be dropped
- B. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances
- C. This traffic will pass with no inspection
- D. Orchestrator will disable NAT and traffic will pass with no issue
Answer: D
Explanation:
Explanation
According to the Check Point MAESTRO R80.20SP Administration Manual1, NAT is not supported on the management network. If you configure NAT on the management network, the Orchestrator will disable NAT and allow the traffic to pass without translation. This is to ensure that the management traffic can reach the Security Group members and the SmartConsole without any issues.
References
*Check Point MAESTRO R80.20SP Administration Manual, page 291
NEW QUESTION # 32
Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?
- A. When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.
- B. When the SG is NATing a very high percentage of traffic passing through it.
- C. When dynamic routing protocols, such as BGP or OSPF are used.
- D. When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.
Answer: C
Explanation:
Explanation
This is the correct answer because Layer 4 distribution is not recommended when dynamic routing protocols are used in Maestro. Layer 4 distribution is a feature that adds the source and/or destination ports to the distribution equation, which can improve the load balancing among the SGMs. However, it can also cause issues with the correction layer, which is a mechanism that ensures the packets are processed by the correct SGM. Dynamic routing protocols, such as BGP or OSPF, use specific ports to exchange routing information and establish neighbor relationships. If Layer 4 distribution is enabled, it can interfere with the routing protocol packets and cause routing instability or failures.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-20
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-8
*Layer 4 Distribution - Yes or No? - Check Point CheckMates
*Support, Support Requests, Training ... - Check Point Software
NEW QUESTION # 33
The core four manual diagnostic tools include:
asg diag verify, asg perf -v, orch_stat -all, and
- A. asg stat -v
- B. hcp -r all
- C. asg diag verify
- D. cpinfo
Answer: A
Explanation:
Explanation
"Asg stat -v" could be a part of the core diagnostic tools, providing valuable statistics and information for manual diagnostics.
References =
*Maestro Expert (CCME) Course - Check Point Software 3
*Check Point Maestro R81.X Administration Guide 1
*Check Point Maestro R81.X Getting Started Guide 2
3: https://www.checkpoint.com/downloads/training/ccme-maestro-expert-r81.10-course.pdf 1:
https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
NEW QUESTION # 34
What is the command 'asg diag' used for?
- A. Asg diag is used for system diagnostics
- B. Asg diag is used for system backup
- C. Asg diag is used for creating traffic flow diagrams
- D. Asg diag used for system diagnostics on Chassis only. It does not exist on Maestro
Answer: A
Explanation:
Explanation
The asg diag command is used for system diagnostics on both Maestro and Chassis systems. The asg diag command can perform various tests and checks on the system components, such as hardware, software, network, clock, ARP, and more. The asg diag command can help identify and troubleshoot any issues or errors that may affect the system functionality or performance.
References =
*Check Point Maestro R81.X Administration Guide, page 66, section "asg diag" 1
*Check Point Maestro R81.X Getting Started Guide, page 28, section "asg diag" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 25
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
NEW QUESTION # 35
What is the max amount of Orchestrators in Dual-site setup?
- A. 4 per Security Group
- B. 0
- C. 1
- D. 2 per Security Group
Answer: A
Explanation:
Explanation
A Dual Site setup can have either two or four orchestrators, depending on the scenario. However, the maximum number of orchestrators per Security Group is four, regardless of the number of sites. This is because each Security Group can have up to two orchestrators on each site, and each site can have up to two orchestrators. Therefore, the maximum number of orchestrators in a Dual Site setup is four per Security Group.
References =
*Maestro Frequently Asked Questions (FAQ)
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
NEW QUESTION # 36
What does the lldpctl command do?
- A. Discover orchestrators
- B. Show all devices discovered by LLDP protocol on uplink ports
- C. Show all devices discovered by LLDP protocol on downlink ports
- D. Show all devices discovered by LLDP protocol on all ports
Answer: D
Explanation:
Explanation
The lldpctl command is a tool to display information about the devices discovered by the Link Layer Discovery Protocol (LLDP) on all ports of the Maestro Orchestrator and the Security Group Members. LLDP is a protocol that enables devices to exchange information about their identity, capabilities, and configuration.
LLDP can help to discover the topology and connectivity of the Maestro environment.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.2: LLDP, page 4-9
*Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section:
LLDP, page 3-9
NEW QUESTION # 37
Logs without a dedicated log file can be found in
- A. /var/log/messages
- B. $RTDIR/log/junk.log
- C. $FWDIR/log/fw.log
- D. /var/log/junk.log.dbg
Answer: A
Explanation:
Explanation
The /var/log/messages file is a general system log file that contains information about various system events, such as booting, shutdown, cron jobs, kernel messages, and other system services. Logs without a dedicated log file can be found in this file, as well as some Maestro Gaia Clishcommands that are not saved in the
/var/log/command_logger.log file.
References
*Maestro Audit Logs - Where are they? - Check Point CheckMates1
*sk172923: The /var/log/messages file does not save Maestro Gaia Clish commands2
*Maestro Expert (CCME) Course - Check Point Software, page 33
NEW QUESTION # 38
In a Maestro Dual Site environment, what is the definition of the term Active Site.
- A. There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.
- B. The Active Site is the site that is not handling any traffic for the specific SG, but itsconnections are synced to its SGMs from the MHOs to be ready in the event of a failover.
- C. The Active Site is the site where the SMO Master exists.
- D. The Active Site is the site currently handling the enforcement on traffic passing for a specific SG.Connections are synced within the SGMs in the Active Site.
Answer: D
Explanation:
Explanation
In a Maestro Dual Site environment, there are two sites that can host Security Group Members (SGMs) for each Security Group (SG). The Active Site is the one that is currently processing the traffic for a specific SG, while the Standby Site is the one that is ready to take over in case of a failover. The Active Site and the Standby Site can be different for different SGs, depending on the load balancing and failover policies. The Active Site and the Standby Site are synchronized by the Maestro Orchestrators (MHOs) using the Site-Sync port and VLANs.
References =
*Solved: Maestro dual site failover - Check Point CheckMates
*Maestro Dual Site configuration with a direct connection through L2 switches
NEW QUESTION # 39
Which command is used to set the number of sites in a Maestro environment?
- A. set maestro configuration orchestrator-site-number
- B. set maestro orchestrator-site-amount
- C. set maestro configuration orchestrator-site-amount
- D. set maestro configuration orchestrator-site-id
Answer: C
Explanation:
Explanation
This command is used to set the number of sites in a Maestro environment, which can be either one or two.
The number of sites determines the site-sync configuration and the failover policies for the Security Groups and the Security Group Members. The default value is one, and it can be changed only before the first Security Group is created.
References =
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 40
What is the Orchestrator?
- A. Manager of compute and network resources, load balancer and network switch
- B. Network Switch
- C. Load balancer
- D. None of above
Answer: A
Explanation:
Explanation
The Orchestrator is a Maestro component that manages the compute and network resources of the Security Group Modules (SGMs) in a Security Group. It also acts as a load balancer and a network switch, distributing traffic among the SGMs and connecting them to the customer's network infrastructure.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 41
Multiple SGs can exist in a Dual Site environment. Each SG can be configured in one of three ways. Which is not one of those ways?
- A. Two MHOs at same site connected to remote site MHOs via single switch.
- B. Direct connectivity between Remote Site MHOs.
- C. Two MHOs connected to two MHOs via load balancers.
- D. Two MHOs at same site connected to remote site MHOs via two different switches.
Answer: C
Explanation:
Explanation
This is not one of the ways to configure a Security Group in a Dual Site environment, because load balancers are not required or supported for the inter-site communication between the Maestro Orchestrators (MHOs).
The MHOs use the Site-Sync port and VLANs to synchronize the resources and connections across the sites.
The three valid scenarios for Dual Site configuration are:
*Direct connectivity between remote site Orchestrators: This scenario requires two orchestrators, one for each site, and a direct connection between them using the site-sync port.
*Two orchestrators on the same site are connected to the remote site orchestrators through two different switches: This scenario requires four orchestrators, two for each site, and a connection between them using the site-sync port and two external switches that support QinQ and MTU increment.
*Two orchestrators on the same site are connected to the remote site orchestrators through one switch: This scenario also requires four orchestrators, two for each site, and a connection between them using the site-sync port and one external switch that support QinQ and MTU increment.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*[Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)]
*[Maestro Frequently Asked Questions (FAQ)]
NEW QUESTION # 42
Where should sx_api_ports_dump.py command be ran?
- A. SMO Appliance
- B. Management server
- C. Orchestrator
- D. Security Group
Answer: C
Explanation:
Explanation
The sx_api_ports_dump.py command should be run on the Orchestrator, which is the device that manages the communication and the configuration of the Security Groups and the SGMs. The command shows the port mapping and the traffic distribution for each Security Group, as well as the backplane bonds and the Orchestrator ports. The command does not work on the Management server, the Security Group, or the SMO Appliance, as they do not have the same role and functionality as the Orchestrator.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 31
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 3
NEW QUESTION # 43
What is the maximum number of Appliances within the same Security Group?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Explanation
The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 51
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 44
Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL.
- A. SecureXL
- B. Fast Accelerator
- C. hypersync
- D. rate limiting
Answer: A
Explanation:
Explanation
SecureXL is typically used to accelerate trusted traffic, including non-F2F (face-to-face) traffic, through a secure, fast path.
References =
*SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above 1
*SecureXL Fast Accelerator - Need to clarify packet flow 2
1:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
2:
https://community.checkpoint.com/t5/Security-Gateways/SecureXL-Fast-Accelerator-Need-to-clarify-packet-flo
NEW QUESTION # 45
What kinds of transceivers are supported on Orchestrator MHO-170?
- A. SFP+, SFP28, QSFP
- B. SFP, QSFP, QSFP28
- C. SFP, SFP+, SFP28
- D. QSFP, QSFP28
Answer: D
Explanation:
Explanation
The Orchestrator MHO-170 supports QSFP and QSFP28 transceivers on its 32x 100 GbE ports. QSFP stands for Quad Small Form-factor Pluggable and QSFP28 is an enhanced version of QSFP that supports up to 28 Gbps per lane. These transceivers can provide high-speed and high-density connectivity for the Maestro environment.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Maestro Transceiver & DAC Inventory - Check Point CheckMates
NEW QUESTION # 46
For the MHO-175, which ports are Management ports?
- A. Ports 1 - 4 are Management ports.
- B. Ports 27 - 47 are Management ports.
- C. Ports 5 - 26 are Management ports.
- D. Ports 49 - 55 are Management ports.
Answer: A
Explanation:
Explanation
According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 -
47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751
NEW QUESTION # 47
What Maestro component acts as a load balancer and network switch?
- A. Security Switching Module (SSM)
- B. Maestro Hyperscale Orchestrator (MHO)
- C. Security Group (SG)
- D. Security Gateway Module (SGM)
Answer: B
Explanation:
Explanation
*The Quantum Maestro Orchestrator uses the Distribution Mode to assign incoming traffic to Security Group Members.
*Reference: Working with the Distribution Mode
NEW QUESTION # 48
......
Verified 156-836 Exam Dumps Q&As - Provide 156-836 with Correct Answers: https://www.vce4dumps.com/156-836-valid-torrent.html
156-836 Exam Questions | Real 156-836 Practice Dumps: https://drive.google.com/open?id=1UjgXuXXzoefi0d9wXLy0fcR2iV7DQ2lK