Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Checkpoint 156-582 Dumps

Page: 1 / 8
Total 75 questions

Check Point Certified Troubleshooting Administrator - R81.20 (CCTA) Questions and Answers

Question 1

Check Point provides tools & commands to help you identify issues about products and applications. Which Check Point command can help you display status and statistics information for various Check Point products and applications?

Options:

A.

cpstat

B.

CP-stat

C.

CPview

D.

fwstat

Question 2

After deploying a new Static NAT configuration, traffic is not getting through. What command would you use to troubleshoot internal problems with the NAT traffic?

Options:

A.

fw ctl kdebug + xlate xltrc nat

B.

cp ctl zdebug + xlate xltrc nat

C.

fw ctl zdebug + xlate xltrc nat

D.

cp ctl kdebug + xlate xltrc nat

Question 3

Which Layer of the OSI Model is responsible for routing?

Options:

A.

Network

B.

Transport

C.

Session

D.

Data link

Question 4

Which of the following is NOT a way to insert fw monitor into the chain when troubleshooting packets throughout the chain?

Options:

A.

Relative position using id

B.

Absolute position

C.

Relative position using location

D.

Relative position using alias

Question 5

As a security administrator/engineer in your company, you have noticed that your HQ Check Point Security Management Server is not receiving logs from your HQ Check Point Gateway/Cluster. To investigate this issue in the command line, you will need to verify which process is running?

Options:

A.

cpm

B.

cpd

C.

fwd

D.

fwm

Question 6

Application Control and URL Filtering update files are located in which directory?

Options:

A.

SCPDIR/appi/update

B.

SFWDIR/conf/update

C.

SCPDIR/apci/update

D.

SFWDIR/appi/update/

Question 7

Which of the following files is commonly associated with troubleshooting crashes on a system such as SmartConsole?

Options:

A.

CPMILdump

B.

fw monitor

C.

crash dump

D.

tcpdump

Question 8

What is the impact of an expired or missing contract file?

Options:

A.

The existing protection settings will be removed in SmartConsole but protections are still being enforced by the Security Gateway.

B.

The existing protection settings display in SmartConsole remain and during policy install the Security Gateway asks the administrator to put a new contract file during policy install.

C.

The existing protection settings display in SmartConsole remain and the Security Gateway will use a 14-day EVAL free license instead.

D.

The existing protection settings display in SmartConsole remain but are not being enforced by the Security Gateway.

Question 9

Running tcpdump causes a significant increase on CPU usage, what other option should you use?

Options:

A.

fw monitor

B.

Wait for out of business hours to do a packet capture

C.

cppcap

D.

You need to use tcpdump with -e option to decrease the length of packet in captures and it will utilize the less CPU

Question 10

You want to collect diagnostics data to include with an SR (Service Request). What command or utility best meets your needs?

Options:

A.

cpconfig

B.

cpinfo

C.

cpplic

D.

contracts_mgmt

Question 11

What is the name of a protocol for VPN establishment and negotiation?

Options:

A.

NAT-T

B.

IPsec

C.

VPN

D.

IKE

Question 12

After reviewing the Install Policy report and error codes listed in it, you need to check if the policy installation port is open on the Security Gateway. What is the correct port to check?

Options:

A.

19009

B.

18190

C.

18210

D.

18191

Question 13

You need to capture NAT information into packet capture, what tool is the best suitable for this task?

Options:

A.

tcpdump

B.

fw monitor

C.

cppcap

D.

fw ctl zdebug + xlate xltrc nat

Question 14

How many captures does the command "fw monitor -p all" take?

Options:

A.

All 15 of the inbound and outbound modules

B.

The -p option takes the same number of captures, but gathers all of the data packet

C.

1 from every inbound and outbound module of the chain

D.

All 4 points of the fw VM modules

Question 15

What is the correct process for GUI connectivity issues with SmartConsole troubleshooting?

Options:

A.

Processes (FWM and CPM), Connectivity, GUI clients, Certificate, Authentication

B.

First troubleshoot Authentication and then the rest

C.

Reinstall the SmartConsole and check if it's running properly

D.

Connectivity, Processes (FWM and CPM), GUI clients, Certificate, Authentication

Question 16

What is the name of the Software Blade Package containing CDR (Content Disarm & Reconstruction) and Zero Day protection?

Options:

A.

TE - Threat Emulation

B.

SNBT - Sandblast

C.

NGTX - Next Generation Threat Prevention and Extraction

D.

NGTP - Next Generation Threat Prevention

Question 17

You were asked to set up logging for a rule to log a full list of URLs when the rule hits in the Rule Base. How do you accomplish that?

Options:

A.

Set Extended logging under rule log type

B.

Click on the rule, column logging and set "log URL" under application control blade layer

C.

All URLs are logged by default

D.

For URL logging you need to modify blade settings of URL filtering blade under SmartConsole, Manage & Settings, blades, URL filtering

Question 18

To verify that communication is working between the Security Management Server and the Security Gateway, which service port should be checked?

Options:

A.

257

B.

18209

C.

259

D.

19009

Question 19

What is a primary advantage of using the fw monitor tool?

Options:

A.

It is menu-driven, making it easy to configure

B.

It can capture packets in various positions as they move through the firewall

C.

It has no negative impact on firewall performance

D.

It always captures all packets hitting the physical layer

Question 20

How do you verify that Proxy ARP entries are loaded into the kernel?

Options:

A.

fw ctl arp

B.

show arp dynamic all

C.

This information can be viewed in the logs, under NAT section of log, field: Proxy ARP entry

D.

fw ctl get arp list all

Question 21

What is the difference between the “Super User" and “Read Write All" SmartConsole permission profiles?

Options:

A.

“Read Write All" has the extra ability to make changes within the Gaia operating system

B.

“Super User” has the extra ability to administer other administrative accounts

C.

“Super User” has the extra ability to make changes within the Gaia operating system

D.

“Super User" had the extra ability of being able to use the Management API

Question 22

Which is the correct "fw monitor" syntax for creating a capture file for loading it into Wireshark?

Options:

A.

fw monitor -e "accept Output.cap

B.

This cannot be accomplished as it is not supported with R80.10

C.

fw monitor -e "accept

D.

fw monitor -e "accept

Page: 1 / 8
Total 75 questions