Free Check Point Check Point Certified Troubleshooting Administrator - R81.20 156-582 Exam Questions
Page: 1 / 8Total 75 questions
Want more questions? Get Premium Access.
Question 1
You want to print the status of WatchDog-monitored processes. What command best meets your needs?
Correct Answer:A. cpwd_admin list
Explanation:
The cpwd_admin list command is used to display the status of processes monitored by the WatchDog service in Check Point. WatchDog ensures that critical processes are running and restarts them if they fail, maintaining the stability and security of the gateway.
Question 2
What is the name of the Software Blade Package containing CDR (Content Disarm & Reconstruction) and Zero Day protection?
Correct Answer:C. NGTX - Next Generation Threat Prevention and Extraction
Explanation:
The NGTX (Next Generation Threat Prevention and Extraction) Software Blade Package includes advanced security features like CDR (Content Disarm & Reconstruction) and Zero Day Protection. This package enhances the security posture by disarming potentially malicious content and protecting against newly discovered threats that exploit unknown vulnerabilities.
Question 3
You were asked to set up logging for a rule to log a full list of URLs when the rule hits in the Rule Base. How do you accomplish that?
Correct Answer:A. Set Extended logging under rule log type
Explanation:
To log a full list of URLs when a specific rule is triggered in the Rule Base, you should set Extended logging under the rule's log type. This configuration ensures that detailed information, including the URLs accessed, is captured in the logs whenever the rule is matched. This level of logging provides comprehensive visibility into user activities and helps in detailed auditing and analysis.
Question 4
What Check Point process controls logging?
Correct Answer:B. FWD
Explanation:
The FWD (Firewall Daemon) process is responsible for controlling logging in Check Point environments. It manages the creation, storage, and transmission of logs from Security Gateways to the Security Management Server, ensuring that all relevant security events are recorded and available for analysis.
Question 5
Running tcpdump causes a significant increase on CPU usage, what other option should you use?
Correct Answer:C. cppcap
Explanation:
When tcpdump causes high CPU usage, an alternative is to use cppcap, which is optimized for capturing packets with lower CPU overhead in Check Point environments. cppcap is designed to work efficiently with Check Point's infrastructure, reducing the performance impact compared to generic tools like tcpdump.
Question 6
Is it possible to analyze ICMP packets with tcpdump?
Correct Answer:A. Yes, tcpdump is not limited to TCP specific issues
Explanation:
Yes, it is possible to analyze ICMP packets with tcpdump. While tcpdump is often associated with capturing TCP packets, it is not limited to them and can capture and analyze any protocol that traverses the network, including ICMP, which operates at Layer 3 (Network Layer) of the OSI model. ICMP packets do not use ports, but tcpdump can filter and display these packets based on other criteria such as type and code fields.
Question 7
The Check Point FW Monitor tool captures and analyzes incoming packets at multiple points in the traffic inspections. Which of the following is the correct inspection flow for traffic?
(i) - pre-inbound: Before the packet enters the inbound processing path.
(I) - post-inbound: After the inbound processing.
(o) - pre-outbound: Before the packet enters the outbound processing path.
(O) - post-outbound: After the outbound processing.
This sequence ensures that packets are captured and analyzed at all critical points during their traversal through the firewall.
Question 8
When accessing License Status In Smart Console, what information is available?
Correct Answer:C. Blade Name, Expiration Date, Attached to, Status
Explanation:
In SmartConsole, when accessing the License Status, the following information is available:
Blade Name: Identifies the specific security blade the license pertains to.
Expiration Date: Indicates when the license will expire.
Attached to: Shows which device or component the license is attached to.
Status: Reflects the current state of the license (e.g., active, expired).
This information helps administrators monitor and manage their licenses effectively, ensuring that all security features remain operational.
Question 9
For Threat Prevention, which process is enabled when the Policy Conversion process has debug turned on using the INTERNAL_POLICY_LOADING=1 command?
Correct Answer:A. fwm
Explanation:
When the Policy Conversion process has debugging enabled using the INTERNAL_POLICY_LOADING=1 command, the fwm (Firewall Manager) process is also enabled for detailed debugging. This allows administrators to monitor and troubleshoot the policy loading and conversion process more effectively, ensuring that policies are correctly applied and enforced.
Question 10
After manipulating the rulebase and objects with SmartConsole the application crashes and closes immediately. To troubleshoot, you will need to review the crash report. In which directory on the host PC will you find this report?
Crash reports for SmartConsole are typically located in the <SmartConsole Directory>\data\crash_report\ directory on the host PC. Reviewing these reports provides insights into why the application crashed, including error messages and stack traces, which are essential for diagnosing and resolving the underlying issues.