Troubleshooting Expert - R81.20 (CCTE) Free Sample Questions

20 free sample questions266 in the full practice test Other version: 156-585(284)

Try simulator

156-587 Sample Questions

  1. Question 1

    A financial services company is experiencing intermittent failures with their Management High Availability (MHA) synchronization. The primary Security Management Server (SMS) reports 'synchronization is running', but the secondary SMS shows a 'collision' state and fails to become active. A network trace reveals no packet loss between the management servers. Which initial command should a troubleshooting expert run on the primary SMS to diagnose the cause of the collision state?

    Answer and explanation

    Correct answer: D

    The ha_diagnostic.sh script is the designated tool for in-depth analysis of MHA issues. It specifically checks for database schema differences, object inconsistencies, and other factors that lead to a 'collision' state, which is often caused by out-of-band changes on one of the servers. While cpstat ha provides status, it doesn't diagnose the root cause of a collision. Restarting event processes (evstop/evstart) is unlikely to resolve a database-level conflict. mds_backup is for backups, not MHA diagnostics.

  2. Question 2

    During a performance audit of a Check Point R81.20 cluster, an administrator observes that traffic for a high-volume, trusted internal application is being handled by the Firewall Worker (fwk) processes instead of being accelerated by SecureXL. The rule for this traffic is placed at the top of the policy, and logs confirm it is being matched. Which of the following is the MOST likely reason for this behavior?

    Answer and explanation

    Correct answer: C

    SecureXL cannot accelerate connections that require advanced logging. Setting the track option to 'Detailed Log' or 'Extended Log' forces the connection to be passed to the Firewall Worker (fwk) process for deeper inspection and logging, bypassing acceleration. This is a common reason for expected traffic not being offloaded. The cluster mode, dynamic NAT, and CoreXL instance count affect performance in other ways but do not inherently prevent SecureXL from accelerating a connection that is otherwise eligible.

  3. Question 3

    A hospital's security team is troubleshooting an Identity Awareness issue where physicians using shared workstations cannot be uniquely identified, causing incorrect policy application. The current setup uses AD Query. The goal is to force each user to authenticate when they access a specific set of clinical research portals, regardless of any existing session from a previous user on the same machine. Which configuration change would BEST achieve this requirement?

    Answer and explanation

    Correct answer: C

    Browser-Based Authentication (Captive Portal) is the ideal solution for this scenario. By setting it as a required action in the access control rule governing access to the clinical portals, the gateway will intercept the HTTP/S request and force the user to authenticate via a web page. This overrides any existing identity session for that workstation and ensures the current user is correctly identified for that specific destination. Terminal Server agent is for multi-user servers, not shared workstations. An Access Role is used for policy but doesn't force re-authentication. Decreasing session timeouts is a blunt instrument and doesn't guarantee immediate re-authentication.

  4. Question 4

    Multiple answers

    A user is unable to connect to the corporate network using the Check Point Mobile Access VPN client. The connection fails during the key negotiation phase. The administrator runs vpn debug trunc on the Security Gateway and captures the IKE debug logs. The output contains the message: NO_PROPOSAL_CHOSEN. What are the two MOST likely causes of this error? (Select TWO).

    Answer and explanation

    Correct answers: B, D

  5. Question 5

    Multiple answers

    An administrator is troubleshooting a slow policy installation process to a remote Security Gateway. Which two processes on the Security Management Server are primarily responsible for compiling the policy and transferring it to the gateway? (Select TWO).

    Answer and explanation

    Correct answers: A, B

  6. Question 6

    A kernel debug using fw ctl zdebug is being performed on a production gateway to diagnose a connectivity issue. The administrator is concerned about the performance impact and wants to ensure the debug buffer does not overwrite important initial data too quickly. What is the correct command to increase the kernel debug buffer size to 2048 KB?

    Answer and explanation

    Correct answer: B

    The correct command to set the kernel debug buffer size is fw ctl debug -buf . The fw ctl zdebug command is used to clear the buffer and view its contents, not to configure its size. The other options use incorrect syntax or commands.

  7. Question 7

    True or False: When troubleshooting Identity Awareness, the pdp process runs on the Security Gateway (PEP) and is responsible for enforcing the identity-based policy.

    Answer and explanation

    Correct answer: B

    This statement is false. The Policy Decision Point (pdp) process is responsible for acquiring identities and making policy decisions, and it runs on the Security Management Server or a dedicated Identity Collector. The Policy Enforcement Point (pep) daemon runs on the Security Gateway and is responsible for enforcing the decisions made by the PDP.

  8. Question 8

    A retail company has deployed Check Point firewalls at its headquarters (HQ) and multiple branch offices. They are experiencing issues where the Site-to-Site VPN tunnels between HQ and the branches flap intermittently. The administrator suspects a Dead Peer Detection (DPD) issue. Which command should be used on the Security Gateway to view the current DPD timers and status for active tunnels?

    Answer and explanation

    Correct answer: C

    The vpn shell utility provides an interactive mode for advanced VPN troubleshooting. Within this shell, the tunnels all command provides detailed information about all active tunnels, including their DPD status, timers, and sequence numbers. This is the most direct and comprehensive way to investigate DPD behavior. vpn tu is a TUI tool for basic tunnel management, fw ctl vpn iflist lists VPN-related kernel interfaces, and cpstat vpn -f all gives general status but not detailed DPD timers.

  9. Question 9

    An administrator notices that the /var/log/ partition on a Security Gateway is filling up rapidly with fw.log files. The gateway is configured to send logs to a dedicated Log Server, and connectivity between the two is stable. What is the MOST likely cause for the local logging?

    Answer and explanation

    Correct answer: D

    In the gateway object's properties under 'Logs', there is a setting to 'Forward logs to Log Server'. Advanced options for this setting allow the gateway to start logging locally if the connection to the log server is lost or if the logging rate exceeds the connection's capacity. Even with stable connectivity, a very high log rate can trigger this local logging behavior, causing fw.log to be created and grow. This is the most common reason for unexpected local logging when a remote Log Server is configured.

  10. Question 10

    A consultant is tasked with troubleshooting a complex application performance issue through a Check Point cluster. The traffic is encrypted (HTTPS) and uses multiple, short-lived TCP sessions. The consultant needs to see the full, unencrypted payload and correlate it with kernel-level decisions like NAT and routing for specific packets. Which combination of tools would be the MOST effective for this task?

    Answer and explanation

    Correct answer: C

    fw monitor is the only standard tool that can show both kernel debug information and the packet data itself, across all inspection points (i, I, o, O). To see the unencrypted payload of HTTPS traffic, HTTPS Inspection must be enabled for that traffic flow. The -p all flag ensures fw monitor shows the packet data at every stage. This combination allows the consultant to see the decrypted application data and correlate it directly with kernel debug messages for NAT, routing, and policy decisions, providing a complete picture of the traffic flow.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 550 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon