When troubleshooting a complex routing issue on an R82 Security Gateway, Check Point Support requests a comprehensive system data collection. Which of the following tools is the BEST choice to gather the required OS, configuration, and routing information into a single compressed file?
Answer and explanation
Correct answer: C
The 'cpinfo' utility is a Check Point auto-diagnostic tool that collects comprehensive system data, including OS configuration, routing tables, and Check Point registry data, into a single compressed file. It is the standard tool requested by TAC for initial troubleshooting. 'cpview' provides performance statistics, and 'cpstat' only provides real-time status for specific components.
Question 2
Multiple answers
As a Troubleshooting Administrator, you are investigating a gateway performance issue that occurred over the weekend. Which TWO of the following tools can provide historical data for post-incident analysis? (Select TWO)
Answer and explanation
Correct answers: A, C
CPView History Mode stores gateway statistics (CPU, memory, network, blades) for 30 days and is opened with 'cpview -t' ('cpview --history') per sk101878. SmartConsole Logs & Monitor keeps historical logs and views for the period. 'cpstat' and 'top' show only the current state.
Question 3
A financial institution recently upgraded their primary Security Gateways to R82. Following the upgrade, the monitoring system reports intermittent high CPU utilization.
The troubleshooting administrator connects via SSH and runs the 'top' command, noticing that several 'fwk' processes are consuming 90% of the CPU. The administrator needs to isolate whether the issue is caused by high connection rates, complex NAT rules, or deep packet inspection.
Which of the following workflows represents the BEST methodology to isolate the cause of the high CPU utilization in this USFW (User Space Firewall) environment?
Answer and explanation
Correct answer: B
When 'top' shows the fwk (CoreXL Firewall instance) processes consuming CPU, the least disruptive way to isolate the cause is to use CPView. Its CPU views show per-core and per-instance utilization, and 'CPU > Top-Connections' lists the heaviest connections per CoreXL Firewall instance (sk101878). Once you know the heavy connections and the loaded instance, you can tell high connection rates apart from specific heavy flows or inspection load. Restarting processes, running unfiltered captures on a loaded gateway, or only checking memory does not isolate the cause.
Question 4
When applying the OSI model for cause isolation during troubleshooting, which of the following Check Point tools is MOST appropriate for diagnosing an issue at Layer 3 (Network Layer)?
Answer and explanation
Correct answer: C
At Layer 3 (Network Layer), troubleshooting involves IP addressing and routing. The 'ip route show' (or 'netstat -rn') command is the appropriate tool for verifying routing tables. 'fw ctl arp' operates at Layer 2, while 'cpstat appi' operates at Layer 7.
Question 5
True or False: When investigating traffic flow issues, the SmartConsole Logs & Monitor view will always display drops caused by the implied rule 'Drop out of state TCP packets'.
Answer and explanation
Correct answer: B
False. In SmartConsole > Global Properties > Stateful Inspection, 'Drop out of state TCP packets' and its 'Log on drop' option are enabled by default, so these drops normally do appear in Logs & Monitor. However, logging is configurable (Log on drop can be cleared, and exceptions can be defined), so the view will not always show them. 'fw ctl zdebug drop' on the gateway shows kernel drops in real time whether or not they are logged.
Question 6
During a troubleshooting session, an administrator observes that traffic from a web server is failing. The SmartConsole log shows the traffic matching an accept rule, but the connection still fails. Which of the following is the MOST likely cause that should be investigated next?
Answer and explanation
Correct answer: B
If an initial connection is accepted by the security policy but the connection still fails, a common cause is a routing issue or a misconfigured NAT rule. The gateway may accept the outbound packet, but if NAT is incorrectly applied, the return packet may not reach the original source or may be dropped due to state mismatch.