
Real CheckPoint 156-585 Exam Questions [Updated 2021]
156-585 Exam Dumps Pass with Updated 2021 Check Point Certified Troubleshooting Expert
CheckPoint 156-585 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 27
Where do Protocol parsers register themselves for IPS?
- A. Other handlers register to Protocol parser
- B. Context Management Infrastructure
- C. Passive Streaming Library
- D. Protections database
Answer: C
NEW QUESTION 28
How can you increase the ring buffer size to 1024 descriptors?
- A. fw ctl int rx_ringsize 1024
- B. dbedit>modify properties firewall_properties rx_ringsize 1024
- C. echo rx_ringsize=1024>>/etc/sysconfig/sysctl.conf
- D. set interface eth0 rx-ringsize 1024
Answer: D
NEW QUESTION 29
During firewall kernel debug with fw ctl zdebug you received less information than expected. You noticed that a lot of messages were lost since the time the debug was started. What should you do to resolve this issue?
- A. Increase debug buffer; Use fw ctl debug -buf 32768
- B. Redirect debug output to file; Use fw ctl zdebug -o ./debug.elg
- C. Redirect debug output to file; Use fw ctl debug -o ./debug.elg
- D. Increase debug buffer; Use fw ctl zdebug -buf 32768
Answer: A
NEW QUESTION 30
You need to run a kernel debug over a longer period of time as the problem occurs only once or twice a week. Therefore, you need to add a timestamp to the kernel debug and write the output to a file but you can't afford to fill up all the remaining disk space and you only have 10 GB free for saving the debugs. What is the correct syntax for this?
- A. fw ctl kdebug -T -m 10 -s 1000000 -o debugfilename
- B. fw ctl debug -T -f -m 10 -s 1000000 -o debugfilename
- C. fw ctl kdebug -T -f -m 10 -s 1000000 -o debugfilename
- D. fw ctl kdebug -T -f -m 10 -s 1000000 > debugfilename
Answer: B
NEW QUESTION 31
VPN's allow traffic to pass through the Internet securely byencryptingthe traffic as it enters the VPN tunnel and then decrypting the exists. Which process is responsible for Mobile VPN connections?
- A. vpnk
- B. fwk
- C. vpnd
- D. cvpnd
Answer: A
NEW QUESTION 32
What is the purpose of the Hardware Diagnostics Tool?
- A. Verifying that Security Gateway hardware is functioning correctly
- B. Verifying that Check Point Appliance hardware is actually broken
- C. Verifying that Check Point Appliance hardware is functioning correctly
- D. Verifying the Security Management Server hardware is functioning correctly
Answer: D
NEW QUESTION 33
What is the simplest and most efficient way to check all dropped packets in real time?
- A. fw ctl zdebug * drop in expert mode
- B. cat /dev/fwTlog in expert mode
- C. tail -f SFWDIR/log/fw log |grep drop in expert mode
- D. Smartlog
Answer: C
NEW QUESTION 34
Check Point Access Control Daemons contains several daemons for Software Blades and features Which Daemon is usedfor Application & Control URL Filtering?
- A. pdpd
- B. cprad
- C. rad
- D. pepd
Answer: D
NEW QUESTION 35
What is the correct syntax to set all debug flags for Unified Policy related issues?
- A. fw ctl debug -m UP all
- B. fw ctl debug -m fw all
- C. fw ctl kdebug -m UP all
- D. fw ctl debug -m up all
Answer: A
NEW QUESTION 36
What file extension should be used with fw monitor to allow the output file to be imported and read in Wireshark?
- A. .tgz
- B. .pcap
- C. .exe
- D. .cap
Answer: D
NEW QUESTION 37
Where will the usermode core files be located?
- A. SCPDIR/var/log/dump/usermode
- B. SFWDlR/var'log/dump/usermode
- C. /var/log/dump/usermode
- D. /var/suroot
Answer: C
NEW QUESTION 38
If the cpsemd process of SmartEvent has crashed or is having trouble coming up. then it usually indicates that___________.
- A. Postgres database ts down
- B. Cpd daemon is unable to connect to the log server
- C. The logged in administrator does not have permissions to run SmartEvent
- D. The SmartEvent core on the Solr mdexer has been deleted
Answer: D
NEW QUESTION 39
Joey is configuring a site-to-site VPN with his business partner. On Joey's site he has a Check Point R80.10 Gateway and his partner uses Cisco ASA 5540 as a gateway.
Joey's VPN domain on the Check Point Gateway object is manually configured with a group object that contains two network objects:
VPN_Domain3 = 192.168.14.0/24
VPN_Domain4 = 192.168.15.0/24
Partner's site ACL as viewed from "show run"
access-list JOEY-VPN extended permit ip 172.26.251.0 255.255.255.0 192.168.14.0 255.255.255.0 access-list JOEY-VPN extended permit ip 172.26.251.0 255.255.255.0 192.168.15.0 255.255.255.0 When they try to establish VPN tunnel, it fails. What is the most likely cause of the failure given the information provided?
- A. Tunnel falls on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation due to the algorithm mismatch.
- B. Tunnel falls on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation. Check Point continues to present its own encryption domain as 192.168.14.0/24 and 192.168.15.0/24, but the peer expects the one network 192.168.14.0/23
- C. Tunnel fails on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation. Check Point continues to present its own encryption domain as 192.168.14.0/23, but the peer expects the two distinct networks 192.168.14.0/24 and 192.168.15.0/24.
- D. Tunnel fails on Joey's site, because he misconfigured IP address of VPN peer.
Answer: C
NEW QUESTION 40
In Security Management High Availability, if the primary and secondary managements, running the same version of R80.x, are in a state of 'Collision', how can this be resolved?
- A. Reset the SIC of the secondary management server
- B. The Collision state does not happen in R80.x as the synchronizing automatically on every publish action
- C. Run the command 'fw send synch force' on the primary server and 'fw get sync quiet' on the secondary server
- D. Administrator should manually synchronize the servers using SmartConsole
Answer: D
NEW QUESTION 41
Rules within the Threat Prevention policy use the Malware database and network objects. Which directory is used for the Malware database?
- A. $FWDlR/log/install_manager_tmp/ANTIMALWARBlog?
- B. $FWDlR/conf/install_firewall_imp/ANTIMALWARE/conf/
- C. $FWDIR/conf/install_manager_tmp/ANTIMALWARE/conf/
- D. $CPDIR/conf/install_manager_lmp/ANTIMALWARE/conf/
Answer: A
NEW QUESTION 42
When debugging is enabled on firewall kernel module using the 'fw ctl debug' command with required options, many debug messages are provided by the kernel that help the administrator to identify issues. Which of the following is true about these debug messages generated by the kernel module?
- A. Messages are written to $FWDIR/log/fw.elg
- B. Messages are written to console and also /var/log/messages file
- C. Messages are written to a buffer and collected using 'fw ctl kdebug'
- D. Messages are written to /etc/dmesg file
Answer: B
NEW QUESTION 43
What is the function of the Core Dump Manager utility?
- A. To send crash information to an external analyzer
- B. To determine which process is slowing down the system
- C. To generate a new core dump for analysis
- D. To limit the number of core dump files per process as well as the total amount of disk space used by core files
Answer: D
NEW QUESTION 44
Which command is used to write a kernel debug to a file?
- A. fw ctl kdebug -T -f > debug.txt
- B. fw ctl debug -S -t > debug.txt
- C. fw ctl debug -T -f > debug.txt
- D. fw ctl kdebug -T -l > debug.txt
Answer: A
NEW QUESTION 45
Which Daemon should be debugged for HTTPS Inspection related issues?
- A. VPND
- B. HTTPD
- C. FWD
- D. WSTLSO
Answer: D
NEW QUESTION 46
John has renewed his NGTX License but he gets an error (contract for Anti-Bot expired). He wants to check the subscription status on the CU of the gateway, what command can he use for this?
- A. show license status
- B. fw monitor license status
- C. cpstat antimalware -I subscription _status
- D. fwm lie print
Answer: A
NEW QUESTION 47
Check Point Access Control Daemons contains several daemons for Software Blades and features. Which Daemon is used for Application & Control Filtering?
- A. rad
- B. pdpd
- C. cprad
- D. pepd
Answer: A
NEW QUESTION 48
James is using the same filter expression in fw monitor for CITRIX very often and instead of typing this all the time he wants to add it as a macro to the fw monitor definition file. What's the name and location of this file?
- A. $FWDIR/conf/fwmonltor.def
- B. $FWDIR/lib/tcpip.def
- C. $FWDIR/lib/fw.monitor
- D. $FWDIR/lib/fwmonltor.def
Answer: D
NEW QUESTION 49
......
156-585 Exam Dumps, 156-585 Practice Test Questions: https://www.itcertmagic.com/CheckPoint/real-156-585-exam-prep-dumps.html
Free 156-585 Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=1yqtUaFce06dxdgIwm27v2kxK4PwA43Lf