ExamGecko
Home Home / Checkpoint / 156-585

Checkpoint 156-585 Practice Test - Questions Answers, Page 10

Question list
Search
Search

List of questions

Search

Related questions











You need to run a kernel debug over a longer period of time as the problem occurs only once or twice a week. Therefore, you need to add a timestamp to the kernel debug and write the output to a file but you can’t afford to fill up all the remaining disk space and you only have 10 GB free for saving the debugs. What is the correct syntax for this?

A.
fw ctl kdebug -T -f -m 10 -s 1000000 -o debugfilename
A.
fw ctl kdebug -T -f -m 10 -s 1000000 -o debugfilename
Answers
B.
fw ctl kdebug -T -f -m 10 -s 1000000 > debugfilename
B.
fw ctl kdebug -T -f -m 10 -s 1000000 > debugfilename
Answers
C.
fw ctl kdebug -T -m 10 -s 1000000 -o debugfilename
C.
fw ctl kdebug -T -m 10 -s 1000000 -o debugfilename
Answers
D.
fw ctl debug -T -f -m 10 -s 1000000 -o debugfilename
D.
fw ctl debug -T -f -m 10 -s 1000000 -o debugfilename
Answers
Suggested answer: D

Check Point provides tools & commands to help you to identify issues about products and applications. Which Check Point command can help you to display status and statistics information for various Check Point products and applications?

A.
cpstat
A.
cpstat
Answers
B.
CPstat
B.
CPstat
Answers
C.
CPview
C.
CPview
Answers
D.
fwstat
D.
fwstat
Answers
Suggested answer: A

The customer is using Check Point appliances that were configured long ago by third-party administrators. Current policy includes different enabled IPS protections and Bypass Under Load function. Bypass Under Load is configured to disable IPS inspections of CPU and Memory usage is higher than 80%. The Customer reports that IPS protections are not working at all regardless of CPU and Memory usage.

What is the possible reason of such behavior?

A.
The kernel parameter ids_assume_stress is set to 0
A.
The kernel parameter ids_assume_stress is set to 0
Answers
B.
The kernel parameter ids_assume_stress is set to 1
B.
The kernel parameter ids_assume_stress is set to 1
Answers
C.
The kernel parameter ids_tolerance_no_stress is set to 10
C.
The kernel parameter ids_tolerance_no_stress is set to 10
Answers
D.
The kernel parameter ids_tolerance_stress is set to 10
D.
The kernel parameter ids_tolerance_stress is set to 10
Answers
Suggested answer: D

In Security Management High Availability, if the primary and secondary managements, running the same version of R80.x, are in a state of ‘Collision’, how can this be resolved?

A.
Administrator should manually synchronize the servers using SmartConsole
A.
Administrator should manually synchronize the servers using SmartConsole
Answers
B.
The Collision state does not happen in R80.x as the synchronizing automatically on every publish action
B.
The Collision state does not happen in R80.x as the synchronizing automatically on every publish action
Answers
C.
Reset the SIC of the secondary management server
C.
Reset the SIC of the secondary management server
Answers
D.
Run the command ‘fw send synch force’ on the primary server and ‘fw get sync quiet’ on the secondary server
D.
Run the command ‘fw send synch force’ on the primary server and ‘fw get sync quiet’ on the secondary server
Answers
Suggested answer: A

What is the most efficient way to view large fw monitor captures and run filters on the file?

A.
wireshark
A.
wireshark
Answers
B.
CLISH
B.
CLISH
Answers
C.
CLI
C.
CLI
Answers
D.
snoop
D.
snoop
Answers
Suggested answer: A

How does the URL Filtering Categorization occur in the kernel?

1. RAD provides the status of the search to the client.

2. The a-sync request is forwarded to the RAD User space via the RAD kernel for online categorization.

3. The online detection service responds with categories and the kernel cache is updated.

4. The kernel cache notifies the RAD kernel of hits and misses.

5. URL lookup initiated by the client.

6. URL lookup occurs in the kernel cache.

7. The client sends an a-sync request back to RAD If the URL was not found.

A.
5, 6, 7, 1, 3, 2, 4
A.
5, 6, 7, 1, 3, 2, 4
Answers
B.
5, 6, 2, 4, 1, 7, 3
B.
5, 6, 2, 4, 1, 7, 3
Answers
C.
5, 6, 4, 1, 7, 2, 3
C.
5, 6, 4, 1, 7, 2, 3
Answers
D.
5, 6, 3, 1, 2, 4, 7
D.
5, 6, 3, 1, 2, 4, 7
Answers
Suggested answer: C

To check the current status of hyper-threading, which command would you execute in expert mode?

A.
cat /proc/hypert_status
A.
cat /proc/hypert_status
Answers
B.
cat /proc/smt_status
B.
cat /proc/smt_status
Answers
C.
cat /proc/hypert_stat
C.
cat /proc/hypert_stat
Answers
D.
cat /proc/smt_stat
D.
cat /proc/smt_stat
Answers
Suggested answer: B

What is the correct syntax to set all debug flags for Unified Policy related issues?

A.
fw ctl debug -m UP all
A.
fw ctl debug -m UP all
Answers
B.
fw ctl debug -m up all
B.
fw ctl debug -m up all
Answers
C.
fw ctl kdebug -m UP all
C.
fw ctl kdebug -m UP all
Answers
D.
fw ctl debug -m fw all
D.
fw ctl debug -m fw all
Answers
Suggested answer: A

Some users from your organization have been reported some connection problems with CIFS since this morning. You suspect an IPS Issue after an automatic IPS update last night. So you want to perform a packet capture on uppercase I only directly after the IPS module (position 4 in the chain) to check if the packets pass the IPS. What command do you need to run?

A.
fw monitor -ml -pl 5 -e <filterexpression>
A.
fw monitor -ml -pl 5 -e <filterexpression>
Answers
B.
fw monitor -pi 5 -e <filterexpression>
B.
fw monitor -pi 5 -e <filterexpression>
Answers
C.
tcpdump -eni any <filterexpression>
C.
tcpdump -eni any <filterexpression>
Answers
D.
fw monitor -pl asm <filterexpression>
D.
fw monitor -pl asm <filterexpression>
Answers
Suggested answer: A

For TCP connections, when a packet arrives at the Firewall Kernel out of sequence or fragmented, which layer of IPS corrects this to allow for proper inspection?

A.
Passive Streaming Library
A.
Passive Streaming Library
Answers
B.
Protections
B.
Protections
Answers
C.
Protocol Parsers
C.
Protocol Parsers
Answers
D.
Context Management
D.
Context Management
Answers
Suggested answer: A
Total 114 questions
Go to page: of 12