New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Checkpoint 156-582 Check Point Certified Troubleshooting Administrator - R81.20 (CCTA) Exam Practice Test

Page: 1 / 8
Total 75 questions

Check Point Certified Troubleshooting Administrator - R81.20 (CCTA) Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

What is a primary advantage of using the fw monitor tool?

Options:

A.

It is menu-driven, making it easy to configure

B.

It can capture packets in various positions as they move through the firewall

C.

It has no negative impact on firewall performance

D.

It always captures all packets hitting the physical layer

Question 2

What is the default protection profile for Autonomous Threat Prevention?

Options:

A.

Perimeter

B.

Guest

C.

Internal

D.

Bypass

Question 3

Check Point's self-service knowledge base of technical documents and tools covers everything from articles describing how to fix specific issues, understand error messages and to how to plan and perform product installation and upgrades. This knowledge base is called:

Options:

A.

SupportCenterBase

B.

SecureDocs

C.

SupportDocs

D.

SecureKnowledge

Question 4

In the Security Management Architecture, what port and process SmartConsole uses to communicate with the management server?

Options:

A.

CPM 19009 and 18191

B.

CPM and 18190

C.

CPM and 19009

D.

FWM and 19009

Question 5

Which of the following files is commonly associated with troubleshooting crashes on a system such as SmartConsole?

Options:

A.

CPMILdump

B.

fw monitor

C.

crash dump

D.

tcpdump

Question 6

After deploying a Hide NAT for a new network, users are unable to access the Internet. What command would you use to check the internal NAT behavior?

Options:

A.

cp ctl kdebug + xlate xltrc nat

B.

fw ctl zdebug + xlate xltrc nat

C.

cp ctl zdebug + xlate xltrc nat

D.

fw ctl kdebug + xlate xltrc nat

Question 7

Which of the following is NOT a way to insert fw monitor into the chain when troubleshooting packets throughout the chain?

Options:

A.

Relative position using id

B.

Absolute position

C.

Relative position using location

D.

Relative position using alias

Question 8

Which is the correct "fw monitor" syntax for creating a capture file for loading it into Wireshark?

Options:

A.

fw monitor -e "accept Output.cap

B.

This cannot be accomplished as it is not supported with R80.10

C.

fw monitor -e "accept

D.

fw monitor -e "accept

Question 9

What are some measures you can take to prevent IPS false positives?

Options:

A.

Capture packets, Update the IPS database, and Back up custom IPS files

B.

Use Recommended IPS profile

C.

Use IPS only in Detect mode

D.

Exclude problematic services from being protected by IPS (sip, H.323, etc.)

Question 10

The URL filtering cache limit exceeded. What issues can this cause?

Options:

A.

When URL filtering cache exceeds the limit, it will be disabled temporarily to overcome instability of the system

B.

RAD process will spawn multiple times to help populate the cache

C.

Resource Advisor (RAD) process on the Security Gateway consumes close to 100 percent of the CPU

D.

Nothing, the Security Gateway dynamically raises the cache when needed

Question 11

Which of the following would be the most appropriate command in debugging a HideNAT issue?

Options:

A.

fw ctl zdebug + fwn allnat

B.

fw ctl zdebug + dynamic natips natports

C.

fw ctl zdebug + xlate xltrc nat

D.

fw ctl zdebug + fwxalloc hidenat

Question 12

Running tcpdump causes a significant increase in CPU usage, what other option should you use?

Options:

A.

o

B.

O

C.

I

D.

i

Question 13

When running the cplic command, what argument is used to show the Signature key?

Options:

A.

-x

B.

-rn

C.

-s

D.

-yall

Question 14

You want to collect diagnostics data to include with an SR (Service Request). What command or utility best meets your needs?

Options:

A.

cpconfig

B.

cpinfo

C.

cpplic

D.

contracts_mgmt

Question 15

How do you verify that Proxy ARP entries are loaded into the kernel?

Options:

A.

fw ctl arp

B.

show arp dynamic all

C.

This information can be viewed in the logs, under NAT section of log, field: Proxy ARP entry

D.

fw ctl get arp list all

Question 16

Where would you look to find the error log file to investigate a logging issue on the Security Management Server?

Options:

A.

SFWDIR/log/fwd.elg

B.

SCPDIR/log/cpd.elg

C.

SMDS_FWDIR/log/cpm.elg

D.

SFWDIR/log/fwm.elg

Question 17

What is the correct process for GUI connectivity issues with SmartConsole troubleshooting?

Options:

A.

Processes (FWM and CPM), Connectivity, GUI clients, Certificate, Authentication

B.

First troubleshoot Authentication and then the rest

C.

Reinstall the SmartConsole and check if it's running properly

D.

Connectivity, Processes (FWM and CPM), GUI clients, Certificate, Authentication

Question 18

How many captures does the command "fw monitor -p all" take?

Options:

A.

All 15 of the inbound and outbound modules

B.

The -p option takes the same number of captures, but gathers all of the data packet

C.

1 from every inbound and outbound module of the chain

D.

All 4 points of the fw VM modules

Question 19

Where can a Check Point customer find information about product licenses they own, download product manuals, and get information about product support expiration?

Options:

A.

Smart Console

B.

PartnerMAP portal

C.

UserCenter portal

D.

In security management server via CLI and executing command cplic print

Question 20

After deploying a new Static NAT configuration, traffic is not getting through. What command would you use to verify that the proxy ARP configuration has been loaded?

Options:

A.

fw ctl conn

B.

fw ctl arp

C.

fw arp ctl

D.

cp ctl arp

Question 21

After deploying a new Static NAT configuration, traffic is not getting through. What command would you use to troubleshoot internal problems with the NAT traffic?

Options:

A.

fw ctl kdebug + xlate xltrc nat

B.

cp ctl zdebug + xlate xltrc nat

C.

fw ctl zdebug + xlate xltrc nat

D.

cp ctl kdebug + xlate xltrc nat

Page: 1 / 8
Total 75 questions