ExamGecko
Home / Checkpoint / 156-836 / List of questions
Ask Question

Checkpoint 156-836 Practice Test - Questions Answers, Page 2

List of questions

Question 11

Report Export Collapse

What is an uplink interface used for?

To connect in between appliances
To connect in between appliances
To connect appliances to customer's infrastructure
To connect appliances to customer's infrastructure
To connect Orchestrators to customer's infrastructure
To connect Orchestrators to customer's infrastructure
To connect in between Orchestrators
To connect in between Orchestrators
Suggested answer: C
Explanation:

Uplink interfaces are used to connect Maestro Hyperscale Orchestrators (MHOs) to the customer's network infrastructure, such as switches, routers, or firewalls. They are also used to send and receive management and control traffic from the customer's network to the MHOs.

* Maestro Expert (CCME) Course - Check Point Software, page 41

* Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline

asked 16/09/2024
Quintin van Rooyen
51 questions

Question 12

Report Export Collapse

What is a security group?

A solution for Security Gateway redundancy and Load Sharing.
A solution for Security Gateway redundancy and Load Sharing.
A set of appliances of the same model that are collectively managed by the MHO.
A set of appliances of the same model that are collectively managed by the MHO.
A set of network interfaces and individual SGMs assigned to a logical group.
A set of network interfaces and individual SGMs assigned to a logical group.
A set of objects in SmartConsole that are responsible for enforcing an access policy.
A set of objects in SmartConsole that are responsible for enforcing an access policy.
Suggested answer: A
Explanation:

Security groups are used to simplify management and policy enforcement across multiple devices or network segments, often offering redundancy and load balancing features

asked 16/09/2024
Andres Mauricio Rodriguez
41 questions

Question 13

Report Export Collapse

What is the Orchestrator?

Network Switch
Network Switch
Manager of compute and network resources, load balancer and network switch
Manager of compute and network resources, load balancer and network switch
Load balancer
Load balancer
None of above
None of above
Suggested answer: B
Explanation:

The Orchestrator is a Maestro component that manages the compute and network resources of the Security Group Modules (SGMs) in a Security Group. It also acts as a load balancer and a network switch, distributing traffic among the SGMs and connecting them to the customer's network infrastructure.

* Maestro Expert (CCME) Course - Check Point Software, page 41

* Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline

asked 16/09/2024
Timothy Brown
35 questions

Question 14

Report Export Collapse

What is the Correction Layer?

Correction Layer is a daemon which corrects errors on Backplane interfaces
Correction Layer is a daemon which corrects errors on Backplane interfaces
Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT
Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT
Correction Layer is a mechanism which activated in case of asymmetric routing
Correction Layer is a mechanism which activated in case of asymmetric routing
Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute
Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute
Suggested answer: B
Explanation:

The Correction Layer is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT is involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.

* NAT and the Correction Layer on a Security Gateway - Check Point Software1

* Solved: Maestro queries - Check Point CheckMates

asked 16/09/2024
Aurelio Chavez
53 questions

Question 15

Report Export Collapse

What is the Correction Layer mechanism?

Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.
Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.
The load-balancing mechanism used by the MHO.
The load-balancing mechanism used by the MHO.
The MHO's distribution algorithm which determines the handling SGM for a given connection.
The MHO's distribution algorithm which determines the handling SGM for a given connection.
Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.
Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.
Suggested answer: A
Explanation:

The Correction Layer mechanism is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT or VPNs are involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.

* NAT and the Correction Layer on a VSX Gateway - Check Point Software1

* Solved: Maestro queries - Check Point CheckMates

asked 16/09/2024
Xiaoyi Wu
45 questions

Question 16

Report Export Collapse

What is the maximum number of Appliances within Security group in Dual-Site configuration?

28
28
31
31
15
15
16
16
Suggested answer: A
asked 16/09/2024
Andrew Oliphant
41 questions

Question 17

Report Export Collapse

At a minimum, how many management and Uplink ports does a SG require?

Only one of the two interfaces is needed for the Security Group.
Only one of the two interfaces is needed for the Security Group.
Neither are required.
Neither are required.
Two of each.
Two of each.
One each.
One each.
Suggested answer: D
Explanation:

A Security Group (SG) requires at least one management port and one uplink port to function properly. The management port is used to connect the SG to the Maestro Hyperscale Orchestrator (MHO) and the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. The uplink port is used to connect the SG to the customer's network infrastructure, such as switches, routers, or firewalls. The uplink port is also used to send and receive traffic from the customer's network to the SG.

* Maestro Expert (CCME) Course - Check Point Software, page 41

* Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline

asked 16/09/2024
Nadja Burkart
37 questions

Question 18

Report Export Collapse

What is the maximum number of Appliances within the same Security Group?

31
31
8
8
52
52
16
16
Suggested answer: A
Explanation:

The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.

* Maestro Expert (CCME) Course - Check Point Software, page 51

* Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline

asked 16/09/2024
Neftali Baez-Feliciano
38 questions

Question 19

Report Export Collapse

For the MHO-175, which ports are Management ports?

Ports 49 - 55 are Management ports.
Ports 49 - 55 are Management ports.
Ports 1 - 4 are Management ports.
Ports 1 - 4 are Management ports.
Ports 27 - 47 are Management ports.
Ports 27 - 47 are Management ports.
Ports 5 - 26 are Management ports.
Ports 5 - 26 are Management ports.
Suggested answer: B
Explanation:

According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 - 47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.

* Maestro Expert (CCME) Course - Check Point Software, page 42

* Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3

* Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751

asked 16/09/2024
Fahim Thanawala
50 questions

Question 20

Report Export Collapse

What kinds of transceivers are supported on Orchestrator MHO-140?

SFP, QSFP, QSFP28
SFP, QSFP, QSFP28
SFP+, SFP28, QSFP
SFP+, SFP28, QSFP
SFP, SFP+, SFP28
SFP, SFP+, SFP28
SFP, SFP+, QSFP, QSFP28
SFP, SFP+, QSFP, QSFP28
Suggested answer: C
Explanation:

According to the Maestro Hyperscale Orchestrator Datasheet1, the Orchestrator MHO-140 supports the following transceiver types: SFP, SFP+, SFP28. These transceivers can be used for the management, uplink, and downlink ports of the Orchestrator. The SFP transceivers support 1 GbE, the SFP+ transceivers support 10 GbE, and the SFP28 transceivers support 25 GbE.

* Maestro Expert (CCME) Course - Check Point Software, page 42

* Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3

* Maestro Hyperscale Orchestrator Datasheet - Check Point Software, page 2

asked 16/09/2024
Sean Kell
46 questions
Total 94 questions
Go to page: of 10