Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

156-836 Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Questions 4

What is the Correction Layer mechanism?

Options:

A.

Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.

B.

The load-balancing mechanism used by the MHO.

C.

The MHO's distribution algorithm which determines the handling SGM for a given connection.

D.

Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.

Buy Now
Questions 5

When a VPN tunnel is formed with a Maestro SGM,

Options:

A.

The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

B.

SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner.

C.

The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.

D.

The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.

Buy Now
Questions 6

What type of cluster can a Security Group can be compared to?

Options:

A.

Load Sharing Active / Active

B.

VSLS

C.

Active / Backup

D.

Active / Standby

Buy Now
Questions 7

Which command is used to set the number of sites in a Maestro environment?

Options:

A.

set maestro orchestrator-site-amount

B.

set maestro configuration orchestrator-site-amount

C.

set maestro configuration orchestrator-site-number

D.

set maestro configuration orchestrator-site-id

Buy Now
Questions 8

What happens if you apply a hotfix using gClish?

Options:

A.

If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time.

B.

If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so.

C.

Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A."

D.

If you apply a hotfix using gclish, the operation will fail because an outage would occur.

Buy Now
Questions 9

What is an uplink interface used for?

Options:

A.

To connect in between appliances

B.

To connect appliances to customer's infrastructure

C.

To connect Orchestrators to customer’s infrastructure

D.

To connect in between Orchestrators

Buy Now
Questions 10

In case of Correction, where is information about Owner stored?

Options:

A.

In Correction table of Target Appliance

B.

In Connection tables of all Appliances participating in Correction Layer flow

C.

In Correction tables of all Appliances participating in Correction Layer flow

D.

In Connection table of Target Appliances

Buy Now
Questions 11

What is HealthCheck Point?

Options:

A.

Is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.

B.

Performs a system health check and is meant to replace both a CPInfo and the health check script.

C.

Can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.

D.

Is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.

Buy Now
Questions 12

Which is a key driver for Scalable Platform?

Options:

A.

On-demand flexibility in reconfiguration.

B.

HyperSync provides scalability by reducing overhead.

C.

Resiliency is achieved through the use of redundant hardware.

D.

Cloud-level security by maximizing capabilities of existing hardware.

Buy Now
Questions 13

What is the default Distribution mode?

Options:

A.

Auto-topology

B.

User

C.

Manual-General

D.

Network

Buy Now
Questions 14

What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?

Options:

A.

Two Out-of-band interfaces for access to Orchestrator itself

B.

1Gbps connectivity for Security Groups

C.

Out-of-band interface for access to Orchestrator itself and Serial Console connector

D.

Reserved for internal purposes. Not in use

Buy Now
Questions 15

What is the Correction Layer?

Options:

A.

Correction Layer is a daemon which corrects errors on Backplane interfaces

B.

Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT

C.

Correction Layer is a mechanism which activated in case of asymmetric routing

D.

Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute

Buy Now
Questions 16

What cannot be learned from the output of lldpctl?

Options:

A.

Serial number of Appliance

B.

Appliance model

C.

Distribution mode

D.

Orchestrator's IP

Buy Now
Questions 17

During an upgrade, Is Multi-Version Clustering (MVC) supported?

Options:

A.

No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.

B.

No, Maestro does not support MVC.

C.

Maestro supports MVC or full connectivity upgrade as of R80.40.

D.

Yes, MVC is supported as of R81 for Maestro.

Buy Now
Questions 18

To display processes that are consuming excessive system resources, users should use the_____ command.

Options:

A.

asg perf -v

B.

asg stat -v

C.

top

D.

asg_perf_hogs

Buy Now
Questions 19

Which command should be used to restart Orchestrator service only?

Options:

A.

orchd restart

B.

reboot

C.

service orchestrator restart

D.

cpstop; cpstart

Buy Now
Questions 20

Common Layer 1 issues include

Options:

A.

Routing

B.

Distribution

C.

MAC addresses

D.

Loose or bad cables

Buy Now
Questions 21

In a Maestro Dual Site environment, what is the definition of the term Active Site.

Options:

A.

The Active Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover.

B.

The Active Site is the site where the SMO Master exists.

C.

There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.

D.

The Active Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.

Buy Now
Questions 22

Multiple SGs can exist in a Dual Site environment. Each SG can be configured in one of three ways. Which is not one of those ways?

Options:

A.

Two MHOs connected to two MHOs via load balancers.

B.

Two MHOs at same site connected to remote site MHOs via two different switches.

C.

Two MHOs at same site connected to remote site MHOs via single switch.

D.

Direct connectivity between Remote Site MHOs.2

Buy Now
Questions 23

The drop_monitor command is useful for

Options:

A.

Monitoring Check Point code drops

B.

Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR

C.

Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.

D.

Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.

Buy Now
Questions 24

For the MHO-175, which ports are Management ports?

Options:

A.

Ports 49 - 55 are Management ports.

B.

Ports 1 - 4 are Management ports.

C.

Ports 27 - 47 are Management ports.

D.

Ports 5 - 26 are Management ports.

Buy Now
Questions 25

The ______________ command will allow users to update the specified file on all SGMs.

Options:

A.

g_update_conf_file

B.

g_all"

C.

sed

D.

g_cat

Buy Now
Questions 26

Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?

Options:

A.

When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.

B.

When dynamic routing protocols, such as BGP or OSPF are used.

C.

When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.

D.

When the SG is NATing a very high percentage of traffic passing through it.

Buy Now
Exam Code: 156-836
Exam Name: Check Point Certified Maestro Expert (CCME) R81.X
Last Update: Jun 15, 2025
Questions: 88
156-836 pdf

156-836 PDF

$29.75  $84.99
156-836 Engine

156-836 Testing Engine

$35  $99.99
156-836 PDF + Engine

156-836 PDF + Testing Engine

$47.25  $134.99