
100% Pass Guaranteed Free 156-836 Exam Dumps Nov 16, 2024
Verified & Latest 156-836 Dump Q&As with Correct Answers
NEW QUESTION # 46
The drop_monitor command is useful for
- A. Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.
- B. Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR
- C. Monitoring Check Point code drops
- D. Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.
Answer: D
Explanation:
Explanation
The drop_monitor command is a tool that monitors and displays the packets that are dropped by the Check Point code or the Gaia OS on the orchestrator and the appliances. It can help troubleshoot network issues and optimize performance. The command shows the drop reason, source, destination, protocol, and port of the dropped packets, as well as the interface and the module that dropped them.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates1
*Support, Support Requests, Training ... - Check Point Software2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge
NEW QUESTION # 47
What is the maximum number of Appliances within Security group in Dual-Site configuration?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 48
What is a security group?
- A. A solution for Security Gateway redundancy and Load Sharing.
- B. A set of appliances of the same model that are collectively managed by the MHO.
- C. A set of network interfaces and individual SGMs assigned to a logical group.
- D. A set of objects in SmartConsole that are responsible for enforcing an access policy.
Answer: A
Explanation:
Explanation
Security groups are used to simplify management and policy enforcement across multiple devices or network segments, often offering redundancy and load balancing features
NEW QUESTION # 49
What is the maximum number of Appliances within the same Security Group?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
Explanation
The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 51
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 50
At a minimum, how many management and Uplink ports does a SG require?
- A. Neither are required.
- B. Only one of the two interfaces is needed for the Security Group.
- C. One each.
- D. Two of each.
Answer: C
Explanation:
Explanation
A Security Group (SG) requires at least one management port and one uplink port to function properly. The management port is used to connect the SG to the Maestro Hyperscale Orchestrator (MHO) and the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. The uplink port is used to connect the SG to the customer's network infrastructure, such as switches, routers, or firewalls. The uplink port is also used to send and receive traffic from the customer's network to the SG.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 51
When a VPN tunnel is formed with a Maestro SGM,
- A. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.
- B. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connectionand tunnel owner.
- C. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.
- D. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.
Answer: C
Explanation:
Explanation
In scalable security environments, initial IKE (Internet Key Exchange) handling by a central orchestrator before distributing traffic for encryption is a common approach to maintain efficiency and security.
NEW QUESTION # 52
What Maestro component acts as a load balancer and network switch?
- A. Security Gateway Module (SGM)
- B. Maestro Hyperscale Orchestrator (MHO)
- C. Security Group (SG)
- D. Security Switching Module (SSM)
Answer: B
Explanation:
Explanation
*The Quantum Maestro Orchestrator uses the Distribution Mode to assign incoming traffic to Security Group Members.
*Reference: Working with the Distribution Mode
NEW QUESTION # 53
How does HyperSync work in a Dual Site environment?
- A. Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.)
- B. Each active connection has a backup connection on the second site (remote site.)
- C. Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs.
- D. Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.)
Answer: D
Explanation:
Explanation
HyperSync is a feature of Maestro that enables stateful synchronization of connections and resources across different sites in a Dual Site environment. HyperSync works by creating two backup connections for each active connection: one on the same site as the active connection, and another on the remote site. This ensures that the connection can be seamlessly resumed in case of a failover event, either within the same site or across the sites. HyperSync uses the Site-Sync port and VLANs to transmit the synchronization packets between the Security Group Members and the Maestro Orchestrators.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*Maestro Frequently Asked Questions (FAQ)
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 54
There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?
- A. 66%/33%
- B. 33%/66%
- C. 50%/50%
- D. 100%/0%
Answer: C
Explanation:
Explanation
The proportion of traffic distribution done by Orchestrator depends on the traffic distribution mode that is configured for the Security Group. There are three modes: Round Robin, Load Sharing, andActive/Standby1.
*Round Robin mode distributes the traffic equally among all the appliances in the Security Group, regardless of the number of downlinks they have. This mode is suitable for scenarios where all the appliances have similar performance and capacity. In this mode, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
*Load Sharing mode distributes the traffic proportionally to the number of downlinks each appliance has. This mode is suitable for scenarios where the appliances have different performance and capacity. In this mode, the proportion of traffic distribution would be 33%/66% for two appliances with one and two downlinks respectively.
*Active/Standby mode distributes the traffic to only one appliance at a time, while the other appliances are in standby mode. This mode is suitable for scenarios where high availability is required. In this mode, the proportion of traffic distribution would be 100%/0% or 0%/100% for two appliances with one and two downlinks respectively, depending on which appliance is active.
Since the question does not specify the traffic distribution mode, the default mode is Round Robin2.
Therefore, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
NEW QUESTION # 55
What is the default Distribution mode?
- A. User
- B. Auto-topology
- C. Manual-General
- D. Network
Answer: B
Explanation:
Explanation
Auto-topology is the default distribution mode for Maestro Security Groups. In this mode, the Orchestrator assigns packets to a Security Group Member based on the topology of the port defined in the gateway object.
Each port is either in user mode or network mode depending on the topology. User mode means that the port is connected to the internal network and network mode means that the port is connected to the external network.
The Orchestrator uses a hash function to map each source IP or destination IP to a specific SGM, depending on the mode of the port. This mode ensures that all packets with the same source IP or destination IP are processed by the same SGM, regardless of the port or protocol.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-18
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-7
*Lari Luoma | Lead Consultant | Maestro SME | Check Point Evangelist1, slide 16
NEW QUESTION # 56
What is the Correction Layer?
- A. Correction Layer is a mechanism which activated in case of asymmetric routing
- B. Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute
- C. Correction Layer is a daemon which corrects errors on Backplane interfaces
- D. Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT
Answer: D
Explanation:
Explanation
The Correction Layer is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT is involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.
References:
*NAT and the Correction Layer on a Security Gateway - Check Point Software1
*Solved: Maestro queries - Check Point CheckMates
NEW QUESTION # 57
What kinds of transceivers are supported on Orchestrator MHO-170?
- A. SFP, QSFP, QSFP28
- B. QSFP, QSFP28
- C. SFP+, SFP28, QSFP
- D. SFP, SFP+, SFP28
Answer: B
Explanation:
Explanation
The Orchestrator MHO-170 supports QSFP and QSFP28 transceivers on its 32x 100 GbE ports. QSFP stands for Quad Small Form-factor Pluggable and QSFP28 is an enhanced version of QSFP that supports up to 28 Gbps per lane. These transceivers can provide high-speed and high-density connectivity for the Maestro environment.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Maestro Transceiver & DAC Inventory - Check Point CheckMates
NEW QUESTION # 58
When security policy is installed
- A. All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.
- B. The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.
- C. All SGMs receive the security policy and simultaneous policy installation occurs.
- D. The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other membersretrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.
Answer: D
Explanation:
Explanation
This is the correct answer because it describes the security policy installation flow for a Maestro Security Group. The SMO Master is the Security Group Member that acts as the leader and the single point of contact for the Management Server. The SMO Master verifies the policy and installs it first, then notifies the other SGMs that a new policy is available. The other SGMs fetch the policy from the SMO Master and install it in parallel.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.3: Security Policy Installation, page 2-15
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Policy Installation, page 2-13
*Policy installation flow - Check Point Software
NEW QUESTION # 59
For the MHO-175, which ports are Management ports?
- A. Ports 5 - 26 are Management ports.
- B. Ports 49 - 55 are Management ports.
- C. Ports 27 - 47 are Management ports.
- D. Ports 1 - 4 are Management ports.
Answer: D
Explanation:
Explanation
According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 -
47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751
NEW QUESTION # 60
The _______ command will allow users to update the specified file on all SGMs.
- A. g_all"
- B. g_cat
- C. sed
- D. g_update_conf_file
Answer: D
Explanation:
Explanation
The g_update_conf_file command is a global command that allows users to update the specified file on all Security Group Members of the current Security Group. The command takes the file name and the parameter-value pair as arguments and updates the file accordingly. For example, g_update_conf_file fwkern.conf fwha_enable_arp=1 will add or modify the fwha_enable_arp parameter in the fwkern.conf file on all SGMs.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-12
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-10
*Maestro Commands for Security Groups - Check Point CheckMates
NEW QUESTION # 61
What Maestro component is automatically designated the SMO Master?
- A. The SGM with the highest member ID (the last one added to the security group.)
- B. The first MHO configured is considered the SMO Master.
- C. The SGM with the lowest member ID (the first one added to the security group.)
- D. The MDS that pushes policy to the SMO is considered the SMO Master.
Answer: C
Explanation:
Explanation
The SMO Master is the SGM that is responsible for synchronizing the configuration and policy with the other SGMs in the security group. The SMO Master is automatically designated as the SGM with the lowest member ID, which is usually the first one added to the security group. The SMO Master can be changed manually if needed.
References:
*Maestro Frequently Asked Questions (FAQ), under "What is a Single Management Object (SMO)?"
*Check Point Jump Start Course: Maestro, under "Maestro Security Groups"
NEW QUESTION # 62
Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?
- A. When dynamic routing protocols, such as BGP or OSPF are used.
- B. When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.
- C. When the SG is NATing a very high percentage of traffic passing through it.
- D. When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.
Answer: A
Explanation:
Explanation
This is the correct answer because Layer 4 distribution is not recommended when dynamic routing protocols are used in Maestro. Layer 4 distribution is a feature that adds the source and/or destination ports to the distribution equation, which can improve the load balancing among the SGMs. However, it can also cause issues with the correction layer, which is a mechanism that ensures the packets are processed by the correct SGM. Dynamic routing protocols, such as BGP or OSPF, use specific ports to exchange routing information and establish neighbor relationships. If Layer 4 distribution is enabled, it can interfere with the routing protocol packets and cause routing instability or failures.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-20
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-8
*Layer 4 Distribution - Yes or No? - Check Point CheckMates
*Support, Support Requests, Training ... - Check Point Software
NEW QUESTION # 63
......
CheckPoint 156-836 exam is a certification program offered by Check Point Software Technologies Ltd. Check Point Certified Maestro Expert - R81 (CCME) certification is designed to validate the skills and knowledge of individuals who are experts in the Maestro technology. 156-836 exam is targeted at professionals who are involved in designing, implementing, and managing complex network security architectures.
CheckPoint 156-836 exam is designed for IT professionals who want to validate their expertise in the Check Point Certified Maestro Expert - R81 (CCME) technology. 156-836 exam is an advanced-level certification designed for those who have extensive knowledge of Check Point security solutions and want to demonstrate their mastery of this technology. Passing 156-836 exam will certify that the candidate has the skills and knowledge required to design, deploy, and manage the Check Point Maestro solution.
Latest 156-836 dumps - Instant Download PDF: https://quiztorrent.testbraindump.com/156-836-exam-prep.html
