
Nov-2021 CheckPoint 156-585 Actual Questions and 100% Cover Real Exam Questions
156-585 Free Exam Questions & Answers PDF Updated on Nov-2021
CheckPoint 156-585 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 17
What is the most efficient way to view large fw monitor captures and run filters on the file?
- A. CLI
- B. wireshark
- C. CLISH
- D. snoop
Answer: B
NEW QUESTION 18
What is the benefit of running "vpn debug trunc over "vpn debug on"?
- A. "vpn debug trunc* provides verbose capture
- B. No advantage one over the other
- C. "vpn debug trunc*truncates the capture hence the output contains minimal capture
- D. "vpn debug trunc" purges ike.elg and vpnd elg and creates limestarnp while starting ike debug and vpn debug
Answer: D
NEW QUESTION 19
If IPS protections that prevent SecureXL from accelerating traffic, such as Network Quota, Fingerprint Scrambling. TTL Masking etc, have to be used, what is a recommended practice to enhance the performance of the gateway?
- A. Upgrade the hardware to include more Cores and Memory
- B. Use the IPS exception mechanism
- C. Disable all such protections
- D. Disable SecureXL and use CoreXL
Answer: D
NEW QUESTION 20
Which of the following is a component of the Context Management Infrastructure used to collect signatures in user space from multiple sources, such as Application Control and IPS. and compiles them together into unified Pattern Matchers?
- A. cpas
- B. Context Loader
- C. CMI Loader
- D. PSL - Passive Signature Loader
Answer: C
NEW QUESTION 21
Check Point Access Control Daemons contains several daemons for Software Blades and features Which Daemon is usedfor Application & Control URL Filtering?
- A. pdpd
- B. cprad
- C. rad
- D. pepd
Answer: D
NEW QUESTION 22
You need to run a kernel debug over a longer period of time as the problem occurs only once or twice a week. Therefore, you need to add a timestamp to the kernel debug and write the output to a file but you can't afford to fill up all the remaining disk space and you only have 10 GB free for saving the debugs. What is the correct syntax for this?
- A. fw ctl kdebug -T -m 10 -s 1000000 -o debugfilename
- B. fw ctl debug -T -f -m 10 -s 1000000 -o debugfilename
- C. fw ctl kdebug -T -f -m 10 -s 1000000 -o debugfilename
- D. fw ctl kdebug -T -f -m 10 -s 1000000 > debugfilename
Answer: B
NEW QUESTION 23
What is the correct syntax to set all debug flags for Unified Policy related issues?
- A. fw ctl debug -m UP all
- B. fw ctl debug -m fw all
- C. fw ctl kdebug -m UP all
- D. fw ctl debug -m up all
Answer: A
NEW QUESTION 24
Which command(s) will turn off all vpn debug collection?
- A. vpn debug -a off
- B. vpn debug off
- C. vpn debug off and vpn debug ikeoff
- D. fw ctl debug 0
Answer: C
NEW QUESTION 25
What acceleration mode utlizes multi-core processing to assist with traffic processing?
- A. CoreXL
- B. Traffic Warping
- C. HyperThreading
- D. SecureXL
Answer: C
NEW QUESTION 26
RAD is initiated when Application Control and URL Filtering blades are active on the Security Gateway What is the purpose of the following RAD configuration file SFWDIR/conf/rad_settings.C?
- A. This file contains the information on how the Security Gateway reaches the Security Managers RAD service for Application Control and URL Filtering
- B. This file contains all the host name settings for the online application detection engine
- C. This file contains the location information tor Application Control and/or URL Filtering entitlements
- D. This file contains RAD proxy settings
Answer: A
NEW QUESTION 27
You are trying to establish a VPN tunnel between two Security Gateways but fail. What initial steps will you make to troubleshoot the issue
- A. collect debug of IKE and VPND daemon and collect kernel debug for fw module with vm, crypt, conn and drop flags
- B. capture traffic on both tunnel members and collect kernel debug for fw module with vm, crypt, conn and drop flags
- C. capture traffic on both tunnel members and collect kernel debug for fw module with vm, crypt, conn and drop flags, then collect debug of IKE and VPND daemon
- D. capture traffic on both tunnel members and collect debug of IKE and VPND daemon
Answer: D
NEW QUESTION 28
What file extension should be used with fw monitor to allow the output file to be imported and read in Wireshark?
- A. .tgz
- B. .pcap
- C. .exe
- D. .cap
Answer: D
NEW QUESTION 29
Which Threat Prevention daemon is the core Threat Emulator, engine and responsible for emulation files and communications with Threat Cloud?
- A. scrub
- B. inmsd
- C. ted
- D. ctasd
Answer: C
Explanation:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk97638
NEW QUESTION 30
What is the main SecureXL database for tracking acceleration status of traffic?
- A. cphwd_dev_identity_table
- B. cphwd_tmp1
- C. cphwd_dev_conn_table
- D. cphwd_db
Answer: B
NEW QUESTION 31
Which command can be run in Expert mode to verify the core dump settings?
- A. grep cdm /config/db/initial
- B. cat /etc/sysconfig/coredump/cdm.conf
- C. grep $FWDIR/config/db/initial
- D. grep cdm /config/db/coredump
Answer: C
NEW QUESTION 32
What table does the command "fwaccel conns" pull information from?
- A. sxl_connections
- B. SecureXLCon
- C. cphwd_db
- D. fwxl_conns
Answer: D
NEW QUESTION 33
What is the simplest and most efficient way to check all dropped packets in real time?
- A. fw ctl zdebug * drop in expert mode
- B. cat /dev/fwTlog in expert mode
- C. tail -f SFWDIR/log/fw log |grep drop in expert mode
- D. Smartlog
Answer: C
NEW QUESTION 34
Which of the following daemons is used for Threat Extraction?
- A. tex
- B. tedex
- C. scrubd
- D. extractd
Answer: C
NEW QUESTION 35
Which command do you need to execute to insert fw monitor after TCP streaming (out) in the outbound chain using absolute position? Given the chain was 1ffffe0, choose the correct answer.
- A. fw monitor -po -0x1ffffe0
- B. fw monitor -p0 ox1ffffe0
- C. fw monitor -po 1ffffe0
- D. fw monitor -p0 -ox1ffffe0
Answer: A
Explanation:
https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_PerformanceTuning_AdminGuide/Content/Topics-PTG/CLI/fw-monitor.htm
NEW QUESTION 36
What is the correct syntax to turn a VPN debug on and create new empty debug files?
- A. vpndebug trunc on
- B. vpn debug trunkon
- C. vpn kdebug on
- D. vpn debug truncon
Answer: B
NEW QUESTION 37
PostgreSQL is a powerful, open source relational database management system Check Point offers a command for viewing the database to interact with Postgres interactive shell Which command do you need to enter the PostgreSQL interactive shell?
- A. psql_c!ieni postgres cpm
- B. psql_client cpm postgres
- C. mysql_client cpm postgres
- D. mysql -u root
Answer: C
NEW QUESTION 38
You are running R80.XX on an open server and you see a high CPU utilization on your 12 CPU cores You now want to enable Hyperthreading to get more cores to gain some performance. What is the correct way to achieve this?
- A. Hyperthreading is not supported on open servers, on on Check Point Appliances
- B. just turn on HAT in the bios of the server and boot it
- C. just turn on HAT in the bios of the server and after it has booted enable it in cpconfig
- D. in dish run set HAT on
Answer: D
NEW QUESTION 39
Which one of the following is NOT considered a Solr core partition:
- A. CPM_0_Disabled
- B. CPM_Global_A
- C. CPM_Gtobal_R
- D. CPM_0_Revisions
Answer: A
NEW QUESTION 40
Which of the following is NOT a vpn debug command used for troubleshooting?
- A. vpn debug trunc
- B. vpn debug on TDERROR_ALL_ALL=5
- C. fw ctl debug -m fw + conn drop vm crypt
- D. pclient getdata sslvpn
Answer: D
NEW QUESTION 41
The customer is using Check Point appliances that were configured long ago by third-party administrators. Current policy includes different enabled IPS protections and Bypass Under Load function. Bypass Under Load is configured to disable IPS inspections of CPU and Memory usage is higher than 80%. The Customer reports that IPS protections are not working at all regardless of CPU and Memory usage.
What is the possible reason of such behavior?
- A. The kernel parameter ids_tolerance_stress is set to 10
- B. The kernel parameter ids_tolerance_no_stress is set to 10
- C. The kernel parameter ids_assume_stress is set to 0
- D. The kernel parameter ids_assume_stress is set to 1
Answer: A
NEW QUESTION 42
......
CheckPoint 156-585 Real 2021 Braindumps Mock Exam Dumps: https://www.test4engine.com/156-585_exam-latest-braindumps.html
Latest 156-585 Exam Dumps Recently Updated 116 Questions: https://drive.google.com/open?id=14_IR-xmugPXS_6SN46fxEY1T4_eQlE2-