CheckPoint Check Point Certified Troubleshooting Administrator - R81.20 156-582 CCTA Exam Questions

Page: 1 / 14
Total 75 questions
Question 1

You tested the connection from source to destination and you are not able to find logs in your Security Management. What is the best possible reason?



Answer : C

If logs are not appearing in the Security Management despite successful traffic flow, the most likely reason is that the logging blade is not enabled on the Security Gateway. Without enabling the logging functionality, the gateway will not send logs to the Security Management Server, even though the traffic itself is passing through successfully.


Question 2

After deploying a new Static NAT configuration, traffic is not getting through. What command would you use to verify that the proxy ARP configuration has been loaded?



Answer : B

To verify the Proxy ARP configuration after deploying a new Static NAT setup, the fw ctl arp command is used. This command displays the current ARP table entries, allowing administrators to confirm that the proxy ARP entries corresponding to the Static NAT mappings have been correctly loaded and are active.


Question 3

What does the FWD daemon instruct the gateway to do when communication issues between the gateway and SMS/Log Server occur?



Answer : C

When there are communication issues between the Security Gateway and the Security Management Server (SMS)/Log Server, the FWD daemon directs the gateway to store logs locally. This ensures that logging continues without interruption, and the logs are queued until communication with the SMS/Log Server is re-established, preventing any loss of log data.


Question 4

For Threat Prevention, which process is enabled when the Policy Conversion process has debug turned on using the INTERNAL_POLICY_LOADING=1 command?



Answer : A

When the Policy Conversion process has debugging enabled using the INTERNAL_POLICY_LOADING=1 command, the fwm (Firewall Manager) process is also enabled for detailed debugging. This allows administrators to monitor and troubleshoot the policy loading and conversion process more effectively, ensuring that policies are correctly applied and enforced.


Question 5

What is the name of the Software Blade Package containing CDR (Content Disarm & Reconstruction) and Zero Day protection?



Answer : C

The NGTX (Next Generation Threat Prevention and Extraction) Software Blade Package includes advanced security features like CDR (Content Disarm & Reconstruction) and Zero Day Protection. This package enhances the security posture by disarming potentially malicious content and protecting against newly discovered threats that exploit unknown vulnerabilities.


Question 6

When opening a new Service Request, what feature is in place to help guide you through the process?



Answer : C

When opening a new Service Request (SR) in Check Point's User Center portal, an SR wizard guides users through the process. This wizard assists in collecting necessary information, categorizing the request appropriately, and ensuring that all required details are provided to expedite the resolution process. The SR wizard simplifies the SR creation process, making it more user-friendly and efficient.


Question 7

How many captures does the command "fw monitor -p all" take?



Answer : A

The command fw monitor -p all initiates packet capturing across all 15 inbound and outbound modules within the Check Point inspection chain. This comprehensive capture allows for thorough analysis of packet flow and behavior at every stage of processing, facilitating detailed troubleshooting and performance evaluation.


Page:    1 / 14   
Total 75 questions