CheckPoint 156-587テストエンジン練習テスト問題、試験問題集 [Q16-Q31]

Share

CheckPoint 156-587テストエンジン練習テスト問題、試験問題集

100%無料156-587日常練習試験には111問があります

質問 # 16
Which of the following file is commonly associated with troubleshooting crashes on a system such as the Security Gateway?

  • A. CPMIL dump
  • B. tcpdump
  • C. fw monitor
  • D. core dump

正解:D

解説:
When troubleshooting crashes on a Security Gateway (or any Linux-based system), the file type that is typically generated and used for in-depth analysis is a core dump.
A core dump captures the memory state of a process at the time it crashed and is critical for root-cause analysis.
Other options:
A . tcpdump: A packet capture file, not a crash-related file.
C . fw monitor: A Check Point packet capture tool, but not for crash debugging.
D . CPMIL dump: Not a common or standard crash dump reference in Check Point.


質問 # 17
What Check Point process controls logging?

  • A. FWD
  • B. CPVVD
  • C. CPM
  • D. CPD

正解:D

解説:
The CPD process controls logging on the Security Management Server or the Log Server. It is responsible for receiving logs from the Security Gateways, storing them in the log files, and forwarding them to the SmartLog and SmartEvent servers. It also handles the communication with the SmartConsole clients and the CPM process. The CPD process runs on the Security Management Server or the Log Server as part of the Management High Availability module.
Reference:
1: Check Point Processes and Daemons - CPD
2: Troubleshooting Check Point logging issues when Security Management Server / Log Server is not receiving logs from Security Gateway Troubleshooting Expert R81.1 (CCTE) Course Outline) - Module 9: Logging and Status Troubleshooting.


質問 # 18
You are seeing output from the previous kernel debug. What command should you use to avoid that?

  • A. fw ctl debug = 0
  • B. fw ctl debug 0
  • C. fw ctl clean buffer = 0
  • D. fw ctl zdebug disable

正解:B


質問 # 19
The FileApp parser in the Content Awareness engine does not extract text from which of the following file types?

  • A. Microsoft Office PowerPoint files
  • B. Microsoft Office Excel files
  • C. PDFs
  • D. Microsoft Office.docx files

正解:C


質問 # 20
Check Point Threat Prevention policies can contain multiple policy layers and each layer consists of its own Rule Base.
Which Threat Prevention daemon is used for Anti-virus?

  • A. in.emaild
  • B. ctasd
  • C. in.emaild.mta
  • D. in.msd

正解:B

解説:
ctasd: This daemon is responsible for Threat Emulation, Anti-Bot, Application Control, and various other security features, including Anti-virus. From Check Point R80.10 onwards, Anti-virus functionality is integrated within ctasd.


質問 # 21
The management configuration stored in the Postgres database is partitioned into several relational database domains. What is the purpose of the Global Domain?

  • A. This domain is used as the global database to track the changes made by multiple administrators on the same objects prior to publishing.
  • B. This domain is used as the global database to back up the objects referencing the corresponding object attributes from the System Domain.
  • C. This domain is used as the global database for MDSM and contains global objects and policies.
  • D. Global Domains is used by the IPS software blade to map the IDs to the corresponding countries according to the IpToCountry.csv file.

正解:C

解説:
The Global Domain is one of the relational database domains in the Postgres database that stores the management configuration. The purpose of the Global Domain is to serve as the global database for Multi- Domain Security Management (MDSM) and contain the global objects and policies that are shared across all domains. The Global Domain also stores the global settings, such as the administrator roles, the LDAP servers, the IPS profiles, and the SmartEvent views. The Global Domain can be managed by the Global Domain Administrator or the Super User Administrator using the SmartConsole. The Global Domain can be backed up and restored using the mds_backup and mds_restore commands.
References:
* 1: Architecture and Processes - Check Point Software
* 2: Multi-Domain Security Management R81.10 Administration Guide
* 3: How to backup and restore Multi-Domain Security Management Server


質問 # 22
Check Point Access Control Daemons contains several daemons for Software Blades and features. Which Daemon is used for Application & Control URL Filtering?

  • A. cprac
  • B. pdpd
  • C. pepd
  • D. rad

正解:D

解説:
https://support.checkpoint.com/results/sk/sk97638


質問 # 23
What is correct about the Resource Advisor (RAD) service on the Security Gateways?

  • A. RAD is not a separate module, it is an integrated function of the 'fw' kernel module and does all operations in the kernel space
  • B. RAD has a kernel module that looks up the kernel cache notifies client about hits and misses and forwards a-sync requests to RAD user space module which is responsible for online categorization
  • C. RAD is completely loaded as a kernel module that looks up URL in cache and if not found connects online for categorization There is no user space involvement in this process
  • D. RAD functions completely in user space The Pattern Matter (PM) module of the CMI looks up for URLs in the cache and if not found, contact the RAD process in user space to do online categorization

正解:B

解説:
The Resource Advisor (RAD) service on the Security Gateways is responsible for online categorization of URLs and resources for Application Control and Threat Prevention blades. RAD has two components: a kernel module and a user space module. The kernel module looks up the kernel cache for URLs and resources, notifies the client about hits and misses, and forwards asynchronous requests to the user space module. The user space module handles the communication with the Check Point online web service and updates the kernel cache with the results. RAD can operate in three modes: hold, background, and custom, depending on the configuration of the blades and the policy. References:
* Check Point Processes and Daemons - Section: Security Gateway Software Blades and Features - Subsection: URL Filtering Blade
* Solved: Re: RAD's high utilization - Post by @PhoneBoy
* Check Point Certified Troubleshooting Expert (CCTE) - Exam Topics - Module 5: Advanced Access Control


質問 # 24
An administrator receives reports about issues with log indexing and text searching regarding an existing Management Server. In trying to find a solution she wants to check if the process responsible for this feature is running correctly. What is true about the related process?

  • A. solr is a child process of cpm
  • B. fwm manaqes this database after initialization of the 1CA
  • C. fwssd crashes can affect therefore not show in the list
  • D. cpd needs to be restarted manual to show in the list

正解:A

解説:
The process responsible for log indexing and text searching is solr, which is a child process of cpm. The solr process is responsible for indexing the logs and providing the search engine for SmartLog and SmartConsole. The solr process is started by the cpm process and can be monitored by the command cpwd_admin list. The solr process uses the PostgreSQL database to store the indexed data and the Lucene library to perform the text search. The solr process can be affected by various factors, such as the size and number of log files, the hardware resources, the network connectivity, and the configuration settings. If the solr process is not running correctly, the administrator may experience issues with log indexing and text searching, such as slow performance, missing logs, or incorrect results.


質問 # 25
You are using the Identity Collector with Identity Awareness in large environment. Users report that they cannot access resources on Internet. You identify that the traffic is matching the cleanup rule instead of the proper rule with Access Roles using the IDC. How can you check if IDC is working?

  • A. pdp debug set IDP all all
  • B. ad query | debug on
  • C. pep debug idc on
  • D. pdp connections idc

正解:D


質問 # 26
SmartEvent utilizes the Log Server, Correlation Unit and SmartEvent Server to aggregate logs and identify security events. The three main processes that govern these SmartEvent components are:

  • A. cpcu, cplog, cpse
  • B. fwd, secu, sesrv
  • C. cpsemd, cpsead, and DBSync
  • D. eventiasv, eventiarp,eventiacu

正解:D

解説:
SmartEvent is a unified security event management and analysis solution that collects and analyzes data from multiple sources to identify and respond to security threats. SmartEvent consists of three main components:
Log Server, Correlation Unit, and SmartEvent Server1. The three main processes that govern these SmartEvent components are:
* eventiasv: This process is responsible for indexing the logs received from the Log Server and storing them in the SmartEvent database. It also performs log consolidation and compression to optimize the disk space usage2.
* eventiarp: This process is responsible for running the predefined and custom correlation rules on the indexed logs and generating security events based on the rule criteria. It also sends notifications and triggers automatic responses for the security events3.
* eventiacu: This process is responsible for providing the web-based user interface for SmartEvent, which allows the administrators to view, analyze, and manage the security events. It also provides the SmartEvent API for external integration4. References: Check Point Processes and Daemons5, SmartEvent Administration Guide1
1: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.
10_SmartEvent_AdminGuide/html_frameset.htm 2: https://sc1.checkpoint.com/documents/R81.10
/WebAdminGuides/EN/CP_R81.10_SmartEvent_AdminGuide/Content/Topics-SmartEvent/SmartEvent- Components.htm#_Toc64167467 3: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN
/CP_R81.10_SmartEvent_AdminGuide/Content/Topics-SmartEvent/SmartEvent-Components.
htm#_Toc64167468 4: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.
10_SmartEvent_AdminGuide/Content/Topics-SmartEvent/SmartEvent-Components.htm#_Toc64167469 5:
https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk97638


質問 # 27
What is the correct syntax to turn a VPN debug on and create new empty debug files'?

  • A. vpn debug truncon
  • B. vpn debug trunkon
  • C. vpndebug trunc on
  • D. vpn kdebug on

正解:A


質問 # 28
What command(s) will turn off all vpn debug collection?

  • A. fw ctl debug 0
  • B. vpn debug off and vpn debug ikeoff
  • C. vpn debug -a off
  • D. vpn debug off

正解:B


質問 # 29
What is the proper command for allowing the system to create core files?

  • A. # set core-dump enable
    # save config
  • B. SFWDIR/scripts/core-dump-enable.sh
  • C. set core-dump enable
    >save config
  • D. service core-dump start

正解:C


質問 # 30
The management configuration stored in the Postgres database is partitioned into several relational database domains. What is the purpose of the Global Domain?

  • A. This domain is used as the global database to track the changes made by multiple administrators on the same objects prior to publishing.
  • B. This domain is used as the global database to back up the objects referencing the corresponding object attributes from the System Domain.
  • C. This domain is used as the global database for MDSM and contains global objects and policies.
  • D. Global Domains is used by the IPS software blade to map the IDs to the corresponding countries according to the IpToCountry.csv file.

正解:C


質問 # 31
......

有効な問題最新版を試そう156-587テスト解釈156-587有効な試験ガイド:https://www.passtest.jp/CheckPoint/156-587-shiken.html

156-587試験資料CheckPoint学習ガイド:https://drive.google.com/open?id=1iro0lRKjIaCis3Vl1Vk7bL2bUGV14--v