Labour Day - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

156-836 Check Point Certified Maestro Expert (CCME) R81.X Questions and Answers

Questions 4

There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?

Options:

A.

100%/0%

B.

33%/66%

C.

50%/50%

D.

66%/33%

Buy Now
Questions 5

After you import the R81.10 software package, what do you use to verify that it is possible to upgrade an MHO or SG?

Options:

A.

Run HCP. One of the tests will list upgrade eligibility status for the MHO or SG.

B.

Run the Pre-Upgrade Verifier to make sure it is possible to upgrade

C.

Nothing. CPUSE will run a verification during the upgrade process to ensure the package is compatible.

D.

The package is verified during the import process and a warning or error will be displayed at that time.

Buy Now
Questions 6

There are two 10Gbps dual-port NICs and one 40Gbps NIC installed on a 23800 Appliance in slots 1, 2 and 3 accordingly. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-

orchestrator redundancy when using two Orchestrators?

Options:

A.

Port 1 in Slot 2 and Port 2 in Slot 1

B.

This configuration is not supported

C.

Any pair of available ports

D.

Port 1 in Slot 1 and Port 2 in Slot 1

Buy Now
Questions 7

What is a security group?

Options:

A.

A solution for Security Gateway redundancy and Load Sharing.

B.

A set of appliances of the same model that are collectively managed by the MHO.

C.

A set of network interfaces and individual SGMs assigned to a logical group.

D.

A set of objects in SmartConsole that are responsible for enforcing an access policy.

Buy Now
Questions 8

What is the throughput penalty of Security Group?

Options:

A.

Depends on the type of Appliance

B.

1% per member

C.

10% per Security Group with no relation to the number of members

D.

5% per member

Buy Now
Questions 9

What is a downlink interface used for?

Options:

A.

To connect appliances to Orchestrators

B.

To connect appliances to customer's infrastructure

C.

To connect in between Orchestrators

D.

To connect Orchestrators to customer's infrastructure

Buy Now
Questions 10

When a VPN tunnel is formed with a Maestro SGM,

Options:

A.

The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

B.

SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connectionand tunnel owner.

C.

The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.

D.

The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.

Buy Now
Questions 11

What Maestro component is automatically designated the SMO Master?

Options:

A.

The SGM with the lowest member ID (the first one added to the security group.)

B.

The MDS that pushes policy to the SMO is considered the SMO Master.

C.

The first MHO configured is considered the SMO Master.

D.

The SGM with the highest member ID (the last one added to the security group.)

Buy Now
Questions 12

There are two 10Gbps dual-port NICs and one 40Gbps NIC installed on a 23800 Appliance in slots 1, 2 and 3 accordingly. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-

orchestrator redundancy when using two Orchestrators?

Options:

A.

Port 1 in Slot 2 and Port 2 in Slot 1

B.

This configuration is not supported

C.

Any pair of available ports

D.

Port 1 in Slot 1 and Port 2 in Slot 1

Buy Now
Questions 13

What happens if you apply a hotfix using gClish?

Options:

A.

If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time.

B.

If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so.

C.

Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A."

D.

If you apply a hotfix using gclish, the operation will fail because an outage would occur.

Buy Now
Questions 14

Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?

Options:

A.

When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.

B.

When dynamic routing protocols, such as BGP or OSPF are used.

C.

When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.

D.

When the SG is NATing a very high percentage of traffic passing through it.

Buy Now
Questions 15

Maestro allows running commands globally in Expert mode by using global prefixes, such as:

Options:

A.

asg all

B.

g_all

C.

all

D.

global

Buy Now
Questions 16

Maestro allows running commands globally in Expert mode by using global prefixes, such as:

Options:

A.

asg all

B.

g_all

C.

all

D.

global

Buy Now
Questions 17

In a Maestro Dual Site environment, what is the definition of the term Active Site.

Options:

A.

The Active Site is the site that is not handling any traffic for the specific SG, but itsconnections are synced to its SGMs from the MHOs to be ready in the event of a failover.

B.

The Active Site is the site where the SMO Master exists.

C.

There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.

D.

The Active Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.

Buy Now
Questions 18

What is the maximum number of Appliances within Security group in Dual-Site configuration?

Options:

A.

28

B.

31

C.

15

D.

16

Buy Now
Questions 19

What type of license is required for an MHO?

Options:

A.

The MHO requires a NGTP license.

B.

The MHO requires a VSX license.

C.

The MHO does not require a license.

D.

A license is needed for each attached SGM.

Buy Now
Questions 20

What does the lldpctl command do?

Options:

A.

Show all devices discovered by LLDP protocol on downlink ports

B.

Show all devices discovered by LLDP protocol on all ports

C.

Discover orchestrators

D.

Show all devices discovered by LLDP protocol on uplink ports

Buy Now
Questions 21

Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

Options:

A.

IPS configuration files

B.

fwkern.conf files.

C.

VPN configuration files

D.

Mobile Access configuration files.

Buy Now
Questions 22

What is a security group?

Options:

A.

A solution for Security Gateway redundancy and Load Sharing.

B.

A set of appliances of the same model that are collectively managed by the MHO.

C.

A set of network interfaces and individual SGMs assigned to a logical group.

D.

A set of objects in SmartConsole that are responsible for enforcing an access policy.

Buy Now
Exam Code: 156-836
Exam Name: Check Point Certified Maestro Expert (CCME) R81.X
Last Update: Apr 27, 2024
Questions: 75

PDF + Testing Engine

$56  $159.99

Testing Engine

$42  $119.99
buy now 156-836 testing engine

PDF (Q&A)

$35  $99.99
buy now 156-836 pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 30 Apr 2024