
Free CheckPoint 156-587 Exam Questions and Answer from Training Expert Lead2Passed
Top CheckPoint 156-587 Courses Online
CheckPoint 156-587 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 55
What file contains the RAD proxy settings?
- A. rad_settings.C
- B. rad_control.C
- C. rad_scheme.C
- D. rad_services.C
Answer: A
NEW QUESTION # 56
What is the most efficient way to read an IKEv2 Debug?
- A. vi on the cti
- B. notepad++
- C. any xml editor
- D. IKEview
Answer: D
Explanation:
IKE view is the most efficient way to read an IKEv2 debug. IKE view is a graphical user interface tool that enables you to analyze the IKEv2 debugs generated by the Security Gateway1. It can parse the debug files and display the information in a structured and readable format. It can also filter the debug messages based on various criteria, such as IP address, encryption domain, or IKEv2 state1. IKE view can help you to troubleshoot the IKEv2 issues and identify the root cause of the problems1. Reference: IKEView: VPN Debugging Tool - Check Point Software
NEW QUESTION # 57
The two procedures available for debugging in the firewall kernel are
i. fw ctl zdebug
ii. fw ctl debug/kdebug
Choose the correct statement explaining the differences in the two
- A. (i) is used to debug the access control policy only, however (ii) can be used to debug a unified policy
- B. (i) is used for general debugging, has a small buffer and is a quick way to set kernel debug flags to getan output via command line whereas (ii) is useful when there is a need for detailed debugging and requires additional steps to set the buffer and get an output via command line
- C. (i) is used on a Security Gateway, whereas (ii) is used on a Security Management Server
- D. (i) is used to debug only issues related to dropping of traffic, however (ii) can be used for any firewall issue including NATing, clustering etc.
Answer: B
Explanation:
The correct statement explaining the differences between the two procedures for debugging in the firewall kernel is D. (i) is used for general debugging, has a small buffer and is a quick way to set kernel debug flags to get an output via command line whereas (ii) is useful when there is a need for detailed debugging and requires additional steps to set the buffer and get an output via command line.
The command fw ctl zdebug is a shortcut command that sets the kernel debug flags to a predefined value and prints the debug output to the standard output. It is useful for general debugging of common issues, such as traffic drops, NAT, VPN, or clustering. It has a small buffer size and does not require additional steps to start or stop the debugging. However, it has some limitations, such as it cannot be used with SecureXL, it cannot filter the output by chain modules, and it cannot save the output to a file12.
The command fw ctl debug is a command that allows the administrator to set the kernel debug flags to a custom value and specify the chain modules to debug. It is useful for detailed debugging of specific issues, such as policy installation, CoreXL, or Identity Awareness. It has a larger buffer size and can save the output to a file. However, it requires additional steps to start and stop the debugging, such as setting the buffer size, clearing the buffer, dumping the buffer, and resetting the debug flags12.
The command fw ctl kdebug is a command that is used in conjunction with fw ctl debug to dump the kernel debug buffer to the standard output or to a file. It is part of the procedure (ii) for detailed debugging in the firewall kernel12.
The other statements are not correct or relevant for explaining the differences between the two procedures for debugging in the firewall kernel. The command fw ctl zdebug can be used to debug more than just the access control policy, and the command fw ctl debug/kdebug can be used to debug more than just the unified policy. Both commands can be used on both the Security Gateway and the Security Management Server, depending on the issue to be debugged12.
References: Check Point Processes and Daemons3, (CCTE) - Check Point Software2
1: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.
10_AdvancedTechnicalReferenceGuide/html_frameset.htm 2: https://www.checkpoint.com/downloads
/training/DOC-Training-Data-Sheet-CCTE-R81.10-V1.0.pdf 3: https://supportcenter.checkpoint.com
/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk97638
NEW QUESTION # 58
If SmartLog is not active or failed to parse results from server, what commands can be run to re-enable the service?
- A. smartloginit and smartlogstop
- B. smartlogstart and smartlogstop
- C. smartlogstart and smartlogsetup
- D. smartlogrestart and smartlogstart
Answer: D
Explanation:
The correct answer is A. smartlogrestart and smartlogstart. These commands are used to restart the SmartLog service and start the SmartLog indexing process. They can be run on the Security Management Server or the Log Server to resolve issues with SmartLog not being active or failing to parse results from the server. The other commands are not valid or relevant for this purpose. References: Check Point Troubleshooting Expert (CCTE) R81.10 Course Data Sheet1, Check Point Troubleshooting Expert (CCTE) R81.10 Course Outline2, Check Point Troubleshooting Expert (CCTE) R81.10 Lab Manual3, sk175223 - SmartLog is not active or failed to parse results from server
NEW QUESTION # 59
User defined URLS and HTTPS inspection User defined URLs on the Security Gateway are stored in which database file?
- A. urtf_https.bin
- B. urlf db.bin
- C. https_db.bin
- D. https_urif.bin
Answer: B
NEW QUESTION # 60
For Identity Awareness, what is the PDP process?
- A. Log Sifter
- B. Identity server
- C. Captive Portal Service
- D. UserAuth Database
Answer: B
NEW QUESTION # 61
The Check Point Watch Daemon (CPWD) monitors critical Check Point processes, terminating them or restarting them as needed to maintain consistent, stable operating conditions. When checking the status/output of CPWD you are able to see some columns like APP, PID, STAT, START, etc. What is the column "STAT" used for?
- A. Shows the Watch Dog name of the monitored process
- B. Shows what monitoring method Watch Dog is using to track the process
- C. Shows the status of the monitored process
- D. Shows how many times the Watch Dog started the monitored process
Answer: C
Explanation:
The STAT column in the output of the cpwd_admin list command shows the status of the monitored process. The possible values are E for established, meaning that the process is running, or T for terminated, meaning that the process is not running. The STAT column is useful for quickly checking if any critical process has crashed or failed to start. If the value is T, the process should be restarted and the reason for the termination should be investigated. The STAT column does not show the Watch Dog name, the number of times the process was started, or the monitoring method of the Watch Dog.
NEW QUESTION # 62
Check Point Threat Prevention policies can contain multiple policy layers and each layer consists of its own Rule Base.
Which Threat Prevention daemon is used for Anti-virus?
- A. in.emaild.mta
- B. in.emaild
- C. ctasd
- D. in.msd
Answer: C
Explanation:
ctasd: This daemon is responsible for Threat Emulation, Anti-Bot, Application Control, and various other security features, including Anti-virus. From Check Point R80.10 onwards, Anti-virus functionality is integrated within ctasd.
NEW QUESTION # 63
Which process is responsible for the generation of certificates?
- A. cpca
- B. dbsync
- C. cpm
- D. fwm
Answer: A
NEW QUESTION # 64
What command is used to find out which port Multi-Portal has assigned to the Mobile Access Portal?
- A. mpclient getdata mobi
- B. mpcient getdata sslvpn
- C. netstat getdata sslvpn
- D. netstat -nap | grep mobile
Answer: B
NEW QUESTION # 65
The Check Point Watch Daemon (CPWD) monitors critical Check Point processes, terminating them or restarting them as needed to maintain consistent, stable operating conditions. When checking the status/output of CPWD you are able to see some columns like APP, PID, STAT, START, etc. What is the column "STAT" used for?
- A. Shows the Watch Dog name of the monitored process
- B. Shows what monitoring method Watch Dog is using to track the process
- C. Shows the status of the monitored process
- D. Shows how many times the Watch Dog started the monitored process
Answer: C
NEW QUESTION # 66
Troubleshooting issues with Mobile Access requires the following:
- A. Debug logs of FWD captured with the command - 'fw debug fwd on
TDERROR_MOBILE_ACCESS=5' - B. 'ma_vpnd' process on Security Gateway
- C. Standard VPN debugs, packet captures and debugs of cvpnd1 process on Security Gateway
- D. Standard VPN debugs and packet captures on Security Gateway, debugs of 'cvpnd' process on Security Management
Answer: C
NEW QUESTION # 67
When debugging is enabled on firewall kernel module using the fw ctl debug' command with required options, many debug messages are provided by the kernel that help the administrator to identify Issues. Which of the following is true about these debug messages generated by the kernel module?
- A. Messages are written to /etc/dmesg file
- B. Messages are written to SFWDIR
- C. Messages are written to a buffer and collected using 'fw ctl kdebug
- D. Messages are written to console and also /var/log/messages file
Answer: C
NEW QUESTION # 68
You need to monitor traffic pre-inbound and before the VPN module in a Security Gateway. How would you achieve this using fw monitor?
- A. fw monitor -pi -vpn
- B. fw monitor -pi +vpn
- C. fw monitor -pi +vpn
- D. fw monitor -p all
Answer: A
Explanation:
The fw monitor command is a powerful troubleshooting tool in Check Point Gateways that captures packets at various points in the processing chain. The question asks how to capture traffic pre-inbound (before inbound processing, i.e., at the "i" inspection point) and before the VPN module (before VPN decryption or processing).
The fw monitor syntax allows specifying inspection points using options like -pi (pre-inbound) and module names (e.g., -vpn for the VPN module). The correct syntax to capture traffic before a specific module is -pi -<module>, where the module name is prefixed with a minus sign to indicate "before" the module.
Option A: Incorrect. fw monitor -p all captures packets at all inspection points in the chain, which includes pre-inbound, post-inbound, pre-outbound, and post-outbound points, as well as points around all modules. This is too broad and does not specifically target pre-inbound and before the VPN module.
Option B: Correct. fw monitor -pi -vpn captures packets at the pre-inbound inspection point ("i") and before the VPN module (-vpn). The -pi specifies the pre-inbound point, and -vpn ensures the capture occurs before VPN processing (e.g., decryption).
Option C: Incorrect. fw monitor -pi +vpn would capture packets at the pre-inbound point but after the VPN module (+vpn indicates after the module), which contradicts the requirement to capture before the VPN module.
Option D: Incorrect. This option is a duplicate of Option C in the provided question, likely a typographical error. Even if corrected, +vpn is incorrect for the same reason as Option C.
Reference:
The Check Point R81.20 Gaia Administration Guide explains the fw monitor command and its options, including how to specify inspection points and module positions. The CCTE R81.20 course includes hands-on labs for using fw monitor to troubleshoot packet flow, emphasizing precise inspection point selection.
For precise details, refer to:
Check Point R81.20 Gaia Administration Guide, section on "fw monitor" (available via Check Point Support Center).
CCTE R81.20 Courseware, which covers advanced packet capture techniques with fw monitor (available through authorized training partners).
NEW QUESTION # 69
What components make up the Context Management Infrastructure?
- A. CPMI and FW Loader
- B. CPX and FWM
- C. CMI Loader and Pattern Matcher
- D. CPM and SOLR
Answer: C
NEW QUESTION # 70
What are the three main component of Identity Awareness?
- A. Identity Awareness Blade on Security Gateway, User Database on Security Management Server and Active Directory
- B. User, Active Directory and Access Role
- C. Identity Source Identity Server (POP) and Identity Enforcement (PEP)
- D. Client, SMS and Secure Gateway
Answer: C
NEW QUESTION # 71
In Mobile Access VPN. clientless access is done using a web browser. The primary communication path for these browser based connections is a process that allows numerous processes to utilize port
443 and redirects traffic to a designated port of the respective process Which daemon handles this?
- A. HTTPS Inspection Daemon (HID)
- B. Connectra VPN Daemon (cvpnd)
- C. Multi-portal Daemon (MPD)
- D. Mobile Access Daemon (MAD)
Answer: C
Explanation:
The Multi-portal Daemon (mpdaemon) is responsible for handling the clientless access connections in Mobile Access VPN. It listens on port 443 and redirects the traffic to the appropriate port of the process that handles the specific connection type, such as cvpnd for SSL Network Extender, MAD for Mobile Access Portal, or HID for HTTPS Inspection. The mpdaemon also performs authentication and authorization for the clientless access connections. References: Check Point Processes and Daemons1, Mobile Access Blade Administration Guide
1: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk97638 : https://sc1.checkpoint.com/documents/R81.10
/WebAdminGuides/EN/CP_R81.10_Mobile_Access_AdminGuide/html_frameset.htm
NEW QUESTION # 72
What are the main components of Check Point's Security Management architecture?
- A. Management server, Log server. Gateway server. Security server
- B. Management server, management database, log server, automation server
- C. Management server. Log Server, LDAP Server, Web Server
- D. Management server. Security Gateway. Multi-Domain Server. SmartEvent Server
Answer: B
NEW QUESTION # 73
You are using the Identity Collector with Identity Awareness in large environment. Users report that they cannot access resources on Internet. You identify that the traffic is matching the cleanup rule instead of the proper rule with Access Roles using the IDC. How can you check if IDC is working?
- A. ad query | debug on
- B. pdp connections idc
- C. pdp debug set IDP all all
- D. pep debug idc on
Answer: B
NEW QUESTION # 74
The FileApp parser in the Content Awareness engine does not extract text from which of the following file types?
- A. PDFs
- B. Microsoft Office Excel files
- C. Microsoft Office PowerPoint files
- D. Microsoft Office.docx files
Answer: A
NEW QUESTION # 75
The FileApp parser in the Content Awareness engine does not extract text from which of the following file types?
- A. Microsoft Office Excel files
- B. Microsoft Office .docx files
- C. Microsoft Office Powerpoint files
- D. PDF
Answer: D
NEW QUESTION # 76
......
New (2026) CheckPoint 156-587 Exam Dumps: https://www.lead2passed.com/CheckPoint/156-587-practice-exam-dumps.html
156-587 Practice Dumps - Verified By Lead2Passed Updated 111 Questions: https://drive.google.com/open?id=1I4q-gRBtaKDigNcwV7uPHYyBlfZBzLbd