Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

156-836 Exam Dumps - Check Point Certified Maestro Expert - R81 (CCME)

Question # 4

Which licenses should be issued for the Orchestrator?

A.

No licenses are required for Orchestrator

B.

Depends on Software Blades enabled on connected appliances

C.

The Orchestrator is considered a Management server, hence it's licensed the same way

D.

The Orchestrator requires NGTX license

Full Access
Question # 5

What is the maximum number of Appliances within Security group in Dual-Site configuration?

A.

28

B.

31

C.

15

D.

16

Full Access
Question # 6

What Maestro component is automatically designated the SMO Master?

A.

The SGM with the lowest member ID (the first one added to the security group.)

B.

The MDS that pushes policy to the SMO is considered the SMO Master.

C.

The first MHO configured is considered the SMO Master.

D.

The SGM with the highest member ID (the last one added to the security group.)

Full Access
Question # 7

Which distribution mode assigns packets to an SGM based solely on the packet destination IP?

A.

User mode

B.

Manual mode

C.

Network mode

D.

Auto-topology mode

Full Access
Question # 8

What is the throughput penalty of Security Group?

A.

Depends on the type of Appliance

B.

1% per member

C.

10% per Security Group with no relation to the number of members

D.

5% per member

Full Access
Question # 9

What is the max amount of Orchestrators in Dual-site setup?

A.

2 per Security Group

B.

4 per Security Group

C.

2

D.

4

Full Access
Question # 10

Which command should be used to restart Orchestrator service only?

A.

orchd restart

B.

reboot

C.

service orchestrator restart

D.

cpstop; cpstart

Full Access
Question # 11

What is the Correction Layer mechanism?

A.

Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.

B.

The load-balancing mechanism used by the MHO.

C.

The MHO's distribution algorithm which determines the handling SGM for a given connection.

D.

Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.

Full Access
Question # 12

What is a security group?

A.

A solution for Security Gateway redundancy and Load Sharing.

B.

A set of appliances of the same model that are collectively managed by the MHO.

C.

A set of network interfaces and individual SGMs assigned to a logical group.

D.

A set of objects in SmartConsole that are responsible for enforcing an access policy.

Full Access
Question # 13

Where should sx_api_ports_dump.py command be ran?

A.

Management server

B.

Security Group

C.

Orchestrator

D.

SMO Appliance

Full Access
Question # 14

What is the Correction Layer?

A.

Correction Layer is a daemon which corrects errors on Backplane interfaces

B.

Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT

C.

Correction Layer is a mechanism which activated in case of asymmetric routing

D.

Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute

Full Access
Question # 15

What Maestro component acts as a load balancer and network switch?

A.

Security Switching Module (SSM)

B.

Maestro Hyperscale Orchestrator (MHO)

C.

Security Group (SG)

D.

Security Gateway Module (SGM)

Full Access
Question # 16

What Maestro component is automatically designated the SMO Master?

A.

The SGM with the lowest member ID (the first one added to the security group.)

B.

The MDS that pushes policy to the SMO is considered the SMO Master.

C.

The first MHO configured is considered the SMO Master.

D.

The SGM with the highest member ID (the last one added to the security group.)

Full Access
Question # 17

After you import the R81.10 software package, what do you use to verify that it is possible to upgrade an MHO or SG?

A.

Run HCP. One of the tests will list upgrade eligibility status for the MHO or SG.

B.

Run the Pre-Upgrade Verifier to make sure it is possible to upgrade

C.

Nothing. CPUSE will run a verification during the upgrade process to ensure the package is compatible.

D.

The package is verified during the import process and a warning or error will be displayed at that time.

Full Access
Question # 18

What is an uplink interface used for?

A.

To connect in between appliances

B.

To connect appliances to customer's infrastructure

C.

To connect Orchestrators to customer's infrastructure

D.

To connect in between Orchestrators

Full Access
Question # 19

What type of cluster can a Security Group can be compared to?

A.

Load Sharing Active / Active

B.

VSLS

C.

Active / Backup

D.

Active / Standby

Full Access
Question # 20

There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators?

A.

Any pair of available ports

B.

Port 1 in Slot 1 and Port 1 in Slot 2

C.

Port 1 in Slot 1 and Port 2 in Slot 1

D.

Port 1 in Slot 2 and Port 2 in Slot 1

Full Access
Question # 21

When a VPN tunnel is formed with a Maestro SGM,

A.

The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

B.

SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connectionand tunnel owner.

C.

The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.

D.

The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.

Full Access
Question # 22

What does asg monitor command do?

A.

This command does not exist

B.

Monitor health status of entire system

C.

Monitor traffic on Appliances in Security Group

D.

Show real-time cluster status of Appliances in Security Group

Full Access