Maestro Expert R81.1 (CCME) Free Sample Questions

20 free sample questions229 in the full practice test

Try simulator

156-836 Sample Questions

  1. Question 1

    A financial institution is deploying a Maestro R81.10 Dual Site environment in which the sites are connected through Layer 2 switches over a long-distance link. Which requirement applies to the connection between the Layer 2 switches on the two sites?

    Answer and explanation

    Correct answer: B

    The Quantum Maestro Getting Started Guide (Dual Site with switches) requires: 'Latency between the Layer 2 switches on different sites must be lower than 100ms' and 'Packet lost between the Layer 2 switches on different sites must be lower than 5%.' The sites synchronize both connections and configuration, so the inter-site path matters. Direct connection between sites is the best practice; the switch-based designs carry the Site Sync VLANs (default 3600/3601).

  2. Question 2

    An administrator is investigating a performance issue in a Maestro Security Group. They suspect that a small number of very heavy connections are being concentrated on a single Security Gateway Module (SGM), overwhelming it. Which command would provide the most direct evidence of this traffic distribution imbalance by showing the number of connections per SGM?

    Answer and explanation

    Correct answer: A

    "asg perf -v" adds a "Per SGM Distribution Summary" to the continuously updated asg perf view. The summary shows each Security Group Member's throughput, packet rate, connection rate, concurrent connections, core loads and memory usage, which makes a connection or load imbalance between members visible. "cphaprob stat" is not the Maestro tool for this. "asg stat -i tasks" shows which member runs the SMO and the other tasks. "asg monitor" continuously shows the same member and component status as "asg stat".

  3. Question 3

    A Maestro environment has two Orchestrators on one site. During a planned upgrade, the upgrade of the second Orchestrator fails. The first Orchestrator and all SGMs still run the old version. What is the documented way to recover the failed Orchestrator?

    Answer and explanation

    Correct answer: C

    The R81.10 guide has a procedure titled "Rolling Back a Failed Upgrade of a Maestro Orchestrator". It reverts the Orchestrator to its pre-upgrade configuration: Gaia settings, Security Group topology and physical port configuration. Work on one Orchestrator at a time. In Expert mode, stop the Orchestrator service with "orchd stop". Then, in Gaia Clish, restore the Gaia snapshot created automatically during the upgrade with "set snapshot revert". The Orchestrator reboots and reverts. After that, align date and time with the other Orchestrators and verify connectivity. Both Orchestrators then run the same version again, which is required. Rebooting, continuing the upgrade on the other Orchestrator, or copying files by SCP does not restore a consistent state.

  4. Question 4

    True or False: In a Maestro environment, the Single Management Object (SMO) IP address is a virtual IP that always resides on the designated SMO Master SGM.

    Answer and explanation

    Correct answer: B

    False. The Security Group has one management IP address, but all Security Appliances in the Security Group use this IPv4 address as their Gaia management IP address; it is not a virtual IP that moves to the SMO Master. The SMO Master (the Active Security Group Member with the lowest ID) handles the management tasks, such as policy installation and logging, and updates the other members.

  5. Question 5

    Multiple answers

    Which TWO statements about Layer 4 distribution in a Maestro R81.10 Security Group are correct? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    R81.10 Admin Guide, Working with the Distribution Mode: "The default mode is Auto-Topology (Per-Port) and the Layer 4 distribution is enabled." With Layer 4 distribution enabled, User (Internal) mode assigns packets by Source Port + Destination IP, Network (External) mode by Source IP + Destination Port, and General mode by Source IP, Source Port, Destination IP and Destination Port. You enable or disable it in gClish with set distribution l4-mode {enabled|disabled} and check it with show distribution l4-mode. Maestro has no payload-offset (user-defined) distribution and no asg_user_distribution or g_asg_distribution_gslb_by_ip command.

  6. Question 6

    A new Security Group has been created in a Maestro R81.10 environment. An administrator needs to push a custom script to all SGMs in this new group to gather specific performance metrics. The script should not be sent to any other Security Groups. Which action is the most appropriate for this task?

    Answer and explanation

    Correct answer: C

    There is no asg_file or asg_cp2all command in Quantum Maestro. The documented tool is asg_cp2blades [-b ] [-r] [-s] [ ], run in Gaia gClish or Expert mode on a Security Group Member. It copies a file from the current SGM to the other SGMs; with no -b (or -b all) it targets all SGMs of that Security Group on all Maestro Sites. Each Security Group is a separate gateway, so running it on Security Group the new group copies the file only to that group's SGMs. The command does not run on the Orchestrator, update_conf_file only edits parameters in configuration files such as fwkern.conf, and asg_config save only saves the gClish configuration.

  7. Question 7

    A systems engineer is provisioning a new Maestro MHO-170 Orchestrator running R81.10. After connecting the management interface and assigning an IP address to Mgmt1 in Gaia Clish, the engineer is unable to access the WebUI (Gaia Portal). What is the most likely reason?

    Answer and explanation

    Correct answer: B

    On Maestro Orchestrators R80.20SP - R81.20 there is no Gaia First Time Configuration Wizard, and Orchestrators do not need a license. The Getting Started Guide procedure is: connect to the MGMT port (default 192.168.1.1, admin/admin) or the console, activate the Orchestrator (enter "y"; this enables the Downlink and Uplink ports), then in Gaia Clish run set interface Mgmt1 ipv4-address mask-length , set interface Mgmt1 state on, set static-route default nexthop gateway address on and save config. Only then is Gaia Portal reachable at https:// . If the port is not set to state on (or no route/save), the WebUI is unreachable even though an IP was assigned.

  8. Question 8

    Multiple answers

    Which of the following are key benefits of connecting two Orchestrators on the same site in a Check Point Maestro R81.10 environment? (Select THREE)

    Answer and explanation

    Correct answers: B, C, E

    Two Orchestrators on the same site work together Active/Active: each Security Appliance is cabled to both Orchestrators, and Uplink and Management interfaces are configured as Bond interfaces across both, so the failure of one Orchestrator or one downlink cable does not stop traffic distribution. Orchestrators are upgraded or patched one at a time (a Jumbo Hotfix stops traffic processing only on the Orchestrator being updated). A second Orchestrator does not change SGM licensing (Orchestrators need no license), and Security Group management tasks run on the SMO, not on the Orchestrators.

  9. Question 9

    An administrator sees in the asg stat -v output that SGM 1_3 of a Quantum Maestro R81.10 Security Group is DOWN while all other SGMs are ACTIVE. Before opening a support case, the administrator wants to run the built-in Maestro diagnostic test suite (System Health, Resources, SSD Health, Policy, Licenses, networking tests and more) and see a Passed/Failed summary with the failure reasons. Which Gaia gClish command should be used?

    Answer and explanation

    Correct answer: B

    In Quantum Maestro R81.10, the built-in diagnostic tests are run with the "smo verifiers" commands in Gaia gClish on the Security Group. show smo verifiers report runs all tests (for example System Health = asg stat -v, Resources = asg resource, SSD Health = asg resource --ssd, Policy = asg policy verify -a, Licenses = asg_license_verifier -v, Bond, ARP Consistency, Core Dumps) and shows a Passed/Failed summary with a Reason column and the output file. show smo verifiers print shows the full output, and report name / report id run specific tests. There is no asg diag --chassis/--blades, g_asg_diag or asg test command.

  10. Question 10

    An administrator runs asg monitor -v on a Maestro Security Group. What does the output show?

    Answer and explanation

    Correct answer: C

    "asg monitor" continuously shows the same information as "asg stat", refreshed at an interval. The "-v" parameter shows only the System component status, and "-all" shows both the Security Group Member and System component status. The command does not trace packets, show distribution hashes, or capture traffic. To find which member handles a connection, use "asg search". To capture traffic, use "tcpdump -mcap".

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 229 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon