Exit demo 156-585 Check Point Certified Troubleshooting Expert (CCTE) PDF format · free preview

CheckPoint 156-585 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/156-585.html

Question 1
Single choice

You have configured IPS Bypass Under Load function with additional kernel parameters ids_tolerance_no_stress=15 and ids_tolerance_stress-15 For configuration you used the *fw ctl set' command After reboot you noticed that these parameters returned to their default values

What do you need to do to make this configuration work immediately and stay permanent?

A.

Set these parameters again with "fw ctl set" and edit appropriate parameters in $FWDIR/boot/modules/ fwkern.conf

B.

Use script $FWDIR/bin IpsSetBypass.sh to set these parameters

C.

Set these parameters again with "fw ctl set" and save configuration with "save config"

D.

Edit appropriate parameters in $FWDIR/boot/modules/fwkern.conf

Question 2
Single choice

How can you start debug of the Unified Policy with all possible flags turned on?

A.

fw ctl debug -m UP all

B.

fw ctl debug -m UnifiedPolicy all

C.

fw ctl debug -m fw + UP

D.

fw ctl debug -m UP *

Question 3
Single choice

What is NOT a benefit of the fw ctl zdebug command?

A.

Cannot be used to debug additional modules

B.

Collect debug messages from the kernel

C.

Clean the buffer

D.

Automatically allocate a 1MB buffer

Question 4
Single choice

How can you increase the ring buffer size to 1024 descriptors?

A.

set interface eth0 rx-ringsize 1024

B.

fw ctl int rx_ringsize 1024

C.

echo rx_ringsize=1024>>/etc/sysconfig/sysctl.conf

D.

dbedit>modify properties firewall_properties rx_ringsize 1024

Question 5
Single choice

What does SIM handle?

A.

Accelerating packets

B.

FW kernel to SXL kernel hand off

C.

OPSEC connects to SecureXL

D.

Hardware communication to the accelerator

Question 6
Single choice

Your users have some issues connecting Mobile Access VPN to the gateway.

How can you debug the tunnel establishment?

A.

in the file $CVPNDIR/conf/httpd.conf change the line loglevel .. To LogLevel debug and run cvpnrestart

B.

run vpn debug truncon

C.

run fw ctl zdebug -m sslvpn all

D.

in the file $VPNDIR/conf/httpd.conf the line Loglevel .. To LogLevel debug and run vpn restart

Question 7
Single choice

What components make up the Context Management Infrastructure?

A.

CMI Loader and Pattern Matcher

B.

CPMI and FW Loader

C.

CPX and FWM

D.

CPM and SOLR

Question 8
Single choice

To check the current status of hyper-threading, which command would you execute in expert mode?

A.

cat /proc/hypert_status

B.

cat /proc/smt_status

C.

cat /proc/hypert_stat

D.

cat /proc/smt_stat

Question 9
Single choice

After kernel debug with "fw ctl debug" you received a huge amount of information It was saved in a very large file that is difficult to open and analyze with standard text editors Suggest a solution to solve this issue.

A.

Use "fw ctl zdebug' because of 1024KB buffer size

B.

Divide debug information into smaller files Use "fw ctl kdebug -f -o "filename" -m 25 - s "1024"

C.

Reduce debug buffer to 1024KB and run debug for several times

D.

Use Check Point InfoView utility to analyze debug output

Question 10
Single choice

What are some measures you can take to prevent IPS false positives?

A.

Exclude problematic services from being protected by IPS (sip, H 323, etc )

B.

Use IPS only in Detect mode

C.

Use Recommended IPS profile

D.

Capture packets. Update the IPS database, and Back up custom IPS files

Showing 10 of 114 questions · Unlock the full set