
[2024年08月] 合格させるCheckPoint 156-836テストエンジンPDFで完全版無料問題集
Check Point Certified Maestro Expert - R81 (CCME)練習テスト2024年最新の156-836ストレスなしで合格!
質問 # 32
What is the default Distribution mode?
- A. Auto-topology
- B. User
- C. Network
- D. Manual-General
正解:A
解説:
Explanation
Auto-topology is the default distribution mode for Maestro Security Groups. In this mode, the Orchestrator assigns packets to a Security Group Member based on the topology of the port defined in the gateway object.
Each port is either in user mode or network mode depending on the topology. User mode means that the port is connected to the internal network and network mode means that the port is connected to the external network.
The Orchestrator uses a hash function to map each source IP or destination IP to a specific SGM, depending on the mode of the port. This mode ensures that all packets with the same source IP or destination IP are processed by the same SGM, regardless of the port or protocol.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-18
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-7
*Lari Luoma | Lead Consultant | Maestro SME | Check Point Evangelist1, slide 16
質問 # 33
During an upgrade, Is Multi-Version Clustering (MVC) supported?
- A. No, Maestro does not support MVC.
- B. Maestro supports MVC or full connectivity upgrade as of R80.40.
- C. No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.
- D. Yes, MVC is supported as of R81 for Maestro.
正解:D
解説:
Explanation
Multi-Version Clustering (MVC) is a feature that allows different versions of Security Gateways to operate in the same cluster and provide seamless failover and load balancing. MVC is supported for Maestro environments as of R81, which means that it is possible to upgrade the Security Groups in a Maestro environment as a Multi-Version Cluster with zero downtime. This requires that the Maestro Orchestrators are upgraded to R81.20 first, and then the Security Groups can be upgraded one by one to R81.20 while maintaining full connectivity and synchronization.
References =
*Check Point R81.20 for Scalable Platforms - Check Point Software
*Maestro Dual Site configuration with a direct connection through L2 switches
*CHECK POINT MAESTRO EXPERT
質問 # 34
Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?
- A. When the SG is NATing a very high percentage of traffic passing through it.
- B. When dynamic routing protocols, such as BGP or OSPF are used.
- C. When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.
- D. When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.
正解:B
解説:
Explanation
This is the correct answer because Layer 4 distribution is not recommended when dynamic routing protocols are used in Maestro. Layer 4 distribution is a feature that adds the source and/or destination ports to the distribution equation, which can improve the load balancing among the SGMs. However, it can also cause issues with the correction layer, which is a mechanism that ensures the packets are processed by the correct SGM. Dynamic routing protocols, such as BGP or OSPF, use specific ports to exchange routing information and establish neighbor relationships. If Layer 4 distribution is enabled, it can interfere with the routing protocol packets and cause routing instability or failures.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-20
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-8
*Layer 4 Distribution - Yes or No? - Check Point CheckMates
*Support, Support Requests, Training ... - Check Point Software
質問 # 35
Is it possible to define distribution mode per interface?
- A. Yes, only for uplink interfaces
- B. No, only for the Security Group
- C. Yes, only for downlink interfaces
- D. Yes, for both uplink and downlink interfaces
正解:D
解説:
Explanation
Maestro allows you to define the distribution mode per interface, which determines how traffic is distributed among the Security Group Modules (SGMs) in a Security Group. You can configure the distribution mode for each interface individually, or use the default mode for all interfaces. The distribution mode can be set for both uplink and downlink interfaces.
References =
*Check Point Maestro R81.X Administration Guide, page 62, section "Distribution Mode" 1
*Check Point Maestro R81.X Getting Started Guide, page 25, section "Distribution Mode" 2
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
質問 # 36
What type of license is required for an MHO?
- A. The MHO requires a VSX license.
- B. The MHO does not require a license.
- C. The MHO requires a NGTP license.
- D. A license is needed for each attached SGM.
正解:B
解説:
Explanation
The MHO (Maestro Hyperscale Orchestrator) does not require a license by itself, but each SGM (Security Group Module) that is attached to the MHO needs a license. The license type depends on the features and blades that are enabled on the SGM. For example, if the SGM is running VSX, it needs a VSX license.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 71
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
質問 # 37
Complete the sentence: Dual Orchestrators work as.______
- A. Load Sharing cluster
- B. Active - Standby cluster
- C. Hot-Swap RAID
- D. Active-Active cluster
正解:D
解説:
Explanation
Dual Orchestrators work as an Active-Active cluster, which means that both Orchestrators are active and share the load of the traffic that is sent to and from the Security Group Members (SGMs). Active-Active cluster provides better performance and scalability than Active-Standby cluster, which only uses one Orchestrator at a time and keeps the other as a backup. Active-Active cluster also allows for faster failover and recovery in case of an Orchestrator failure, as the surviving Orchestrator can take over the traffic without interruption.
References
*Maestro Expert (CCME) Course - Check Point Software, page 25
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 2
質問 # 38
What is the Correction Layer?
- A. Correction Layer is a daemon which corrects errors on Backplane interfaces
- B. Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute
- C. Correction Layer is a mechanism which activated in case of asymmetric routing
- D. Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT
正解:D
解説:
Explanation
The Correction Layer is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT is involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.
References:
*NAT and the Correction Layer on a Security Gateway - Check Point Software1
*Solved: Maestro queries - Check Point CheckMates
質問 # 39
What happens if the SMO Master fails?
- A. The next SGM with the current lowest SGM ID assumes the role of the SMO Master.
- B. A failover will occur on the MHO and traffic will continue to pass.
- C. The Backup SMO Master will take over in the event of a failure with the SMO Master.
- D. The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.
正解:A
解説:
Explanation
This aligns with the principle of redundancy in network systems, where the next available device with the lowest ID typically takes over management roles in case of a failure.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 91
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
質問 # 40
The _______ command will allow users to update the specified file on all SGMs.
- A. sed
- B. g_cat
- C. g_update_conf_file
- D. g_all"
正解:C
解説:
Explanation
The g_update_conf_file command is a global command that allows users to update the specified file on all Security Group Members of the current Security Group. The command takes the file name and the parameter-value pair as arguments and updates the file accordingly. For example, g_update_conf_file fwkern.conf fwha_enable_arp=1 will add or modify the fwha_enable_arp parameter in the fwkern.conf file on all SGMs.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-12
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-10
*Maestro Commands for Security Groups - Check Point CheckMates
質問 # 41
The core four manual diagnostic tools include:
asg diag verify, asg perf -v, orch_stat -all, and
- A. asg stat -v
- B. asg diag verify
- C. cpinfo
- D. hcp -r all
正解:A
解説:
Explanation
"Asg stat -v" could be a part of the core diagnostic tools, providing valuable statistics and information for manual diagnostics.
References =
*Maestro Expert (CCME) Course - Check Point Software 3
*Check Point Maestro R81.X Administration Guide 1
*Check Point Maestro R81.X Getting Started Guide 2
3: https://www.checkpoint.com/downloads/training/ccme-maestro-expert-r81.10-course.pdf 1:
https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
質問 # 42
What kinds of transceivers are supported on Orchestrator MHO-170?
- A. QSFP, QSFP28
- B. SFP, SFP+, SFP28
- C. SFP, QSFP, QSFP28
- D. SFP+, SFP28, QSFP
正解:A
解説:
Explanation
The Orchestrator MHO-170 supports QSFP and QSFP28 transceivers on its 32x 100 GbE ports. QSFP stands for Quad Small Form-factor Pluggable and QSFP28 is an enhanced version of QSFP that supports up to 28 Gbps per lane. These transceivers can provide high-speed and high-density connectivity for the Maestro environment.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Maestro Transceiver & DAC Inventory - Check Point CheckMates
質問 # 43
What Maestro component is automatically designated the SMO Master?
- A. The SGM with the lowest member ID (the first one added to the security group.)
- B. The first MHO configured is considered the SMO Master.
- C. The SGM with the highest member ID (the last one added to the security group.)
- D. The MDS that pushes policy to the SMO is considered the SMO Master.
正解:A
解説:
Explanation
The SMO Master is the SGM that is responsible for synchronizing the configuration and policy with the other SGMs in the security group. The SMO Master is automatically designated as the SGM with the lowest member ID, which is usually the first one added to the security group. The SMO Master can be changed manually if needed.
References:
*Maestro Frequently Asked Questions (FAQ), under "What is a Single Management Object (SMO)?"
*Check Point Jump Start Course: Maestro, under "Maestro Security Groups"
質問 # 44
While looking at your system's correction statistics, you notice you have a correction rate approaching 100 percent. Is this a problem?
- A. In some scenarios, a correction rate approaching 100 percent of all connections is not unusual. This is not usually a cause for concern as the correction mechanism is fast and efficient.
- B. If correction rates are higher than 80 percent, latency is expected.
- C. A correction rate above 90 percent indicates a need to disable Layer 4 Distribution.
- D. A correction rate approaching 100 percent of all connections is unusual. This is a cause for concern because the SGMs may fail to process traffic.
正解:D
解説:
Explanation
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23 3
*Check Point Maestro Frequently Asked Questions (FAQ), question 9 4
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
3:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
4:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
質問 # 45
At a minimum, how many management and Uplink ports does a SG require?
- A. Neither are required.
- B. Two of each.
- C. One each.
- D. Only one of the two interfaces is needed for the Security Group.
正解:C
解説:
Explanation
A Security Group (SG) requires at least one management port and one uplink port to function properly. The management port is used to connect the SG to the Maestro Hyperscale Orchestrator (MHO) and the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. The uplink port is used to connect the SG to the customer's network infrastructure, such as switches, routers, or firewalls. The uplink port is also used to send and receive traffic from the customer's network to the SG.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
質問 # 46
Multiple SGs can exist in a Dual Site environment. Each SG can be configured in one of three ways. Which is not one of those ways?
- A. Two MHOs at same site connected to remote site MHOs via two different switches.
- B. Direct connectivity between Remote Site MHOs.
- C. Two MHOs connected to two MHOs via load balancers.
- D. Two MHOs at same site connected to remote site MHOs via single switch.
正解:C
解説:
Explanation
This is not one of the ways to configure a Security Group in a Dual Site environment, because load balancers are not required or supported for the inter-site communication between the Maestro Orchestrators (MHOs).
The MHOs use the Site-Sync port and VLANs to synchronize the resources and connections across the sites.
The three valid scenarios for Dual Site configuration are:
*Direct connectivity between remote site Orchestrators: This scenario requires two orchestrators, one for each site, and a direct connection between them using the site-sync port.
*Two orchestrators on the same site are connected to the remote site orchestrators through two different switches: This scenario requires four orchestrators, two for each site, and a connection between them using the site-sync port and two external switches that support QinQ and MTU increment.
*Two orchestrators on the same site are connected to the remote site orchestrators through one switch: This scenario also requires four orchestrators, two for each site, and a connection between them using the site-sync port and one external switch that support QinQ and MTU increment.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*[Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)]
*[Maestro Frequently Asked Questions (FAQ)]
質問 # 47
Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL.
- A. rate limiting
- B. Fast Accelerator
- C. hypersync
- D. SecureXL
正解:D
解説:
Explanation
SecureXL is typically used to accelerate trusted traffic, including non-F2F (face-to-face) traffic, through a secure, fast path.
References =
*SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above 1
*SecureXL Fast Accelerator - Need to clarify packet flow 2
1:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
2:
https://community.checkpoint.com/t5/Security-Gateways/SecureXL-Fast-Accelerator-Need-to-clarify-packet-flo
質問 # 48
......
時間限定!今すぐ無料アクセス156-836練習試験用問題:https://drive.google.com/open?id=12njS1nPMfkHDFMr6TRyXYl6PbjxysDKc
オンライン試験練習テストと詳細な解説付き!:https://www.passtest.jp/CheckPoint/156-836-shiken.html