[Q43-Q66] 156-836練習CheckPoint高合格率回答あなたを試験は高確率で合格させます![2024]

Share

156-836練習CheckPoint高合格率回答あなたを試験は高確率で合格させます![2024]

最高の方法からパスCCMEの156-836試験合格させます


Check Point Certified Maestro Expert(CCME)認定を取得することは、企業環境でCheck Point Maestroを管理および展開する高度な専門知識と熟練度を証明することを意味し、IT専門家がキャリアを進め、上位のポジションや高い給与の機会を開くことができます。


チェックポイント156-836試験は、チェックポイントソフトウェアテクノロジーが提供するベンダー固有の認定試験です。この試験は、チェックポイント認定のMaestro Expert -R81(CCME)アーキテクチャ、展開、構成、管理などのさまざまな分野で候補者の知識とスキルをテストするように設計されています。この試験は、複数の選択の質問で構成されており、提案された環境で管理されています。

 

質問 # 43
At a minimum, how many management and Uplink ports does a SG require?

  • A. Neither are required.
  • B. Two of each.
  • C. Only one of the two interfaces is needed for the Security Group.
  • D. One each.

正解:D

解説:
Explanation
A Security Group (SG) requires at least one management port and one uplink port to function properly. The management port is used to connect the SG to the Maestro Hyperscale Orchestrator (MHO) and the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. The uplink port is used to connect the SG to the customer's network infrastructure, such as switches, routers, or firewalls. The uplink port is also used to send and receive traffic from the customer's network to the SG.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline


質問 # 44
What is a security group?

  • A. A set of network interfaces and individual SGMs assigned to a logical group.
  • B. A set of objects in SmartConsole that are responsible for enforcing an access policy.
  • C. A solution for Security Gateway redundancy and Load Sharing.
  • D. A set of appliances of the same model that are collectively managed by the MHO.

正解:C

解説:
Explanation
Security groups are used to simplify management and policy enforcement across multiple devices or network segments, often offering redundancy and load balancing features


質問 # 45
How many orchestrators may Dual-Site include?

  • A. 2 or 4
  • B. Only 4
  • C. 0
  • D. 1

正解:A

解説:
Explanation
A Dual Site environment can include either two or four orchestrators, depending on the scenario. There are three primary scenarios for Dual Site configuration:
*Direct connectivity between remote site orchestrators: This scenario requires two orchestrators, one for each site, and a direct connection between them using the site-sync port.
*Two orchestrators on the same site are connected to the remote site orchestrators through two different switches: This scenario requires four orchestrators, two for each site, and a connection between them using the site-sync port and two external switches that support QinQ and MTU increment.
*Two orchestrators on the same site are connected to the remote site orchestrators through one switch: This scenario also requires four orchestrators, two for each site, and a connection between them using the site-sync port and one external switch that supports QinQ and MTU increment.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
*Maestro Frequently Asked Questions (FAQ)


質問 # 46
What is the max amount of Orchestrators in Dual-site setup?

  • A. 0
  • B. 2 per Security Group
  • C. 1
  • D. 4 per Security Group

正解:D

解説:
Explanation
A Dual Site setup can have either two or four orchestrators, depending on the scenario. However, the maximum number of orchestrators per Security Group is four, regardless of the number of sites. This is because each Security Group can have up to two orchestrators on each site, and each site can have up to two orchestrators. Therefore, the maximum number of orchestrators in a Dual Site setup is four per Security Group.
References =
*Maestro Frequently Asked Questions (FAQ)
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)


質問 # 47
What is the maximum number of Appliances within the same Security Group?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:C

解説:
Explanation
The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 51
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline


質問 # 48
HealthCheck Point _____

  • A. is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.
  • B. is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.
  • C. performs a system health check and is meant to replace both a CPInfo and the health check script.
  • D. can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.

正解:A

解説:
Explanation
HealthCheck Point (HCP) is a tool that can perform various tests and checks on the system components of the Security Group Modules (SGMs), such as hardware, software, network, clock,ARP, and more. It can also display the performance statistics of the SGMs, such as throughput, packet rate, CPU utilization, memory usage, and more. Additionally, HCP can provide a graphical representation of the Firewall topology for the Security Group, showing the connections and statuses of the SGMs and the Orchestrators. Furthermore, HCP can generate a report of the critical and informative events that occurred on the system, such as configuration changes, errors, warnings, and alerts. HCP can help identify and troubleshoot any issues or errors that may affect the system functionality or performance.
References =
*HealthCheck Point (HCP) Release Updates - Check Point Software 1
*Professional Services Healthcheck - Check Point Software 2
*HealthCheck Point - Check Point CheckMates 3


質問 # 49
What will happen in case of NAT of the traffic passing through Management network?

  • A. This traffic will pass with no inspection
  • B. This traffic will not pass correction, since it will be dropped
  • C. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances
  • D. Orchestrator will disable NAT and traffic will pass with no issue

正解:D

解説:
Explanation
According to the Check Point MAESTRO R80.20SP Administration Manual1, NAT is not supported on the management network. If you configure NAT on the management network, the Orchestrator will disable NAT and allow the traffic to pass without translation. This is to ensure that the management traffic can reach the Security Group members and the SmartConsole without any issues.
References
*Check Point MAESTRO R80.20SP Administration Manual, page 291


質問 # 50
Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

  • A. VPN configuration files
  • B. IPS configuration files
  • C. Mobile Access configuration files.
  • D. fwkern.conf files.

正解:B

解説:
Explanation
References
*Maestro R80.30SP Jumbo Hotfix Accumulator, Section: Important Notes
*Check Point Maestro R80.30SP with Gaia 3.10, Section: Known Limitations
*Check Point SNMP MIB files, Section: Revision History


質問 # 51
What can be learned from the output of sx_api_ports_dump.py command?

  • A. Information about Security Groups
  • B. Information about backplane bonds
  • C. Information about downlink ports only
  • D. Orchestrator port status

正解:B

解説:
Explanation
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3


質問 # 52
In what mode do MHOs process traffic?

  • A. MHOs process traffic in Active-Standby mode
  • B. MHOs process traffic in VSLS mode
  • C. MHOs process traffic in Active-Active mode
  • D. MHOs process traffic in load sharing mode

正解:C

解説:
Explanation
MHOs process traffic in Active-Active mode, which means that both MHOs are active and share the load of the traffic that is sent to and from the SGMs. Active-Active mode provides better performance and scalability than Active-Standby mode, which only uses one MHO at a time and keeps the other as a backup.
Active-Active mode also allows for faster failover and recovery in case of an MHO failure, as the surviving MHO can take over the traffic without interruption.
References
*Maestro Expert (CCME) Course - Check Point Software, page 25
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 2


質問 # 53
What is the purpose of g_tcpdump command?

  • A. The same as tcpdump, just on Scalable Platform
  • B. Collects traffic dump from CIN network
  • C. Collects traffic dump from Sync network
  • D. Collects traffic dump from all Active Appliances within Security Group

正解:D

解説:
Explanation
_tcpdump" probably collects traffic dumps from all active appliances within a security group, aligning with the naming convention and function of similar commands in scalable platforms.
References
*Maestro Expert (CCME) Course - Check Point Software, page 331
*What is 'IN' and 'OUT' of g_tcpdump? - Check Point CheckMates2
*CHECK POINT MAESTRO EXPERT, page 23


質問 # 54
What is the Correction Layer mechanism?

  • A. The MHO's distribution algorithm which determines the handling SGM for a given connection.
  • B. The load-balancing mechanism used by the MHO.
  • C. Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.
  • D. Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.

正解:D

解説:
Explanation
The Correction Layer mechanism is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT or VPNs are involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.
References:
*NAT and the Correction Layer on a VSX Gateway - Check Point Software1
*Solved: Maestro queries - Check Point CheckMates


質問 # 55
The drop_monitor command is useful for

  • A. Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.
  • B. Monitoring Check Point code drops
  • C. Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.
  • D. Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR

正解:C

解説:
Explanation
The drop_monitor command is a tool that monitors and displays the packets that are dropped by the Check Point code or the Gaia OS on the orchestrator and the appliances. It can help troubleshoot network issues and optimize performance. The command shows the drop reason, source, destination, protocol, and port of the dropped packets, as well as the interface and the module that dropped them.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates1
*Support, Support Requests, Training ... - Check Point Software2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge


質問 # 56
Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL.

  • A. hypersync
  • B. Fast Accelerator
  • C. SecureXL
  • D. rate limiting

正解:C

解説:
Explanation
SecureXL is typically used to accelerate trusted traffic, including non-F2F (face-to-face) traffic, through a secure, fast path.
References =
*SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above 1
*SecureXL Fast Accelerator - Need to clarify packet flow 2
1:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
2:
https://community.checkpoint.com/t5/Security-Gateways/SecureXL-Fast-Accelerator-Need-to-clarify-packet-flo


質問 # 57
What is the Correction Layer?

  • A. Correction Layer is a mechanism which activated in case of asymmetric routing
  • B. Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT
  • C. Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute
  • D. Correction Layer is a daemon which corrects errors on Backplane interfaces

正解:B

解説:
Explanation
The Correction Layer is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT is involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.
References:
*NAT and the Correction Layer on a Security Gateway - Check Point Software1
*Solved: Maestro queries - Check Point CheckMates


質問 # 58
After you import the R81.10 software package, what do you use to verify that it is possible to upgrade an MHO or SG?

  • A. Run HCP. One of the tests will list upgrade eligibility status for the MHO or SG.
  • B. The package is verified during the import process and a warning or error will be displayed at that time.
  • C. Nothing. CPUSE will run a verification during the upgrade process to ensure the package is compatible.
  • D. Run the Pre-Upgrade Verifier to make sure it is possible to upgrade

正解:D

解説:
Explanation
The Pre-Upgrade Verifier is a tool that checks the compatibility and readiness of the Maestro environment for the upgrade process. It verifies the current version, the target version, the hardware requirements, the configuration settings, and the license validity of the Maestro Orchestrators and the Security Groups. It also identifies any potential issues or risks that might affect the upgrade and provides recommendations on how to resolve them. The Pre-Upgrade Verifier should be run before importing the R81.10 software package and before performing the actual upgrade.
References =
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT


質問 # 59
What happens when you make changes from Clish on the SMO Master?

  • A. The changes are synchronized to the MHO as a backup.
  • B. The changes are synchronized to the SMS/MDS as a backup.
  • C. Changes are only applied on the SMO Master.
  • D. Changes are applied to all members in the SG.

正解:C

解説:
Explanation
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.2: Security Group Configuration, page 2-10
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Configuration, page 2-9
*Security Group Configuration - Check Point Software


質問 # 60
Maestro allows running commands globally in Expert mode by using global prefixes, such as:

  • A. global
  • B. g_all
  • C. all
  • D. asg all

正解:B

解説:
Explanation
The g_all prefix is used to run commands globally in Expert mode on all Security Group Members of the current Security Group. For example, g_all cpstop will stop the Check Point services on all SGMs. The other prefixes are not valid for global commands in Expert mode.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-11
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-9
*Global Expert Mode Commands - Check Point CheckMates


質問 # 61
There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators?

  • A. Port 1 in Slot 2 and Port 2 in Slot 1
  • B. Port 1 in Slot 1 and Port 1 in Slot 2
  • C. Any pair of available ports
  • D. Port 1 in Slot 1 and Port 2 in Slot 1

正解:B

解説:
Explanation
The correct interfaces to connect to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators are Port 1 in Slot 1 and Port 1 in Slot 2. This is because each slot represents a different NIC, and each port represents a different physical link. By connecting two ports from different slots, the appliance can have redundant connections to the same orchestrator, and avoid a single point of failure in case of a NIC or link failure.
References
*Check Point 156-835 Certification Flashcards | Quizlet1
*Maestro Expert (CCME) Course - Check Point Software, page 182
*Maestro Technical Training, Module 2: Maestro Security Groups and the Single Management Object, slide
163


質問 # 62
What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?

  • A. 1Gbps connectivity for Security Groups
  • B. Reserved for internal purposes. Not in use.
  • C. Out-of-band interfaces for access to Orchestrator itself
  • D. Additional ports used as uplinks

正解:C

解説:
Explanation
The Management ports located on the Rear Panel of the Orchestrator MHO-140 are out-of-band interfaces that provide access to the Orchestrator itself for configuration and management purposes. They are not used for traffic distribution or connectivity to the Security Groups or the external networks. They are 1Gbps RJ-45 ports that can be connected to a switch or a router.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates2, page 4


質問 # 63
When security policy is installed

  • A. The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other membersretrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.
  • B. All SGMs receive the security policy and simultaneous policy installation occurs.
  • C. All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.
  • D. The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.

正解:A

解説:
Explanation
This is the correct answer because it describes the security policy installation flow for a Maestro Security Group. The SMO Master is the Security Group Member that acts as the leader and the single point of contact for the Management Server. The SMO Master verifies the policy and installs it first, then notifies the other SGMs that a new policy is available. The other SGMs fetch the policy from the SMO Master and install it in parallel.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.3: Security Policy Installation, page 2-15
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Policy Installation, page 2-13
*Policy installation flow - Check Point Software


質問 # 64
To display processes that are consuming excessive system resources, users should use the_____ command.

  • A. asg stat -v
  • B. asg perf -v
  • C. top
  • D. asg_perf_hogs

正解:D

解説:
Explanation
The asg_perf_hogs command is a script that displays the processes that are consuming excessive system resources, such as CPU, memory, disk, and network, on the orchestrator and the appliances. It can help identify performance issues and bottlenecks in the Maestro environment.
References
*Software Provision and Performance hogs failed - Check Point CheckMates1
*CHECK POINT MAESTRO EXPERT, page 33


質問 # 65
Which command is used to set the number of sites in a Maestro environment?

  • A. set maestro configuration orchestrator-site-amount
  • B. set maestro orchestrator-site-amount
  • C. set maestro configuration orchestrator-site-id
  • D. set maestro configuration orchestrator-site-number

正解:A

解説:
Explanation
This command is used to set the number of sites in a Maestro environment, which can be either one or two.
The number of sites determines the site-sync configuration and the failover policies for the Security Groups and the Security Group Members. The default value is one, and it can be changed only before the first Security Group is created.
References =
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT


質問 # 66
......


CCME試験は80の多肢選択問題から構成され、候補者は試験を完了するために180分の時間が与えられます。この試験は、候補者がCheck Point Maestroアーキテクチャ、展開、管理、およびトラブルシューティングに関する知識をテストするために設計されています。試験は、マルチドメイン管理、クラスタリング、および仮想システムなどの高度なトピックもカバーしています。この試験は、製品とその機能に対する深い理解、および製品を実際に操作した経験が必要です。

 

CheckPoint 156-836事前に試験練習テストPassTest: https://www.passtest.jp/CheckPoint/156-836-shiken.html

156-836練習テスト問題回答解釈:https://drive.google.com/open?id=1YJJzq89raHzzJGuY3_lzLlJrtAwAoiF5