Certbus > CheckPoint > Checkpoint Certifications > 156-585 > 156-585 Online Practice Questions and Answers

156-585 Online Practice Questions and Answers

Questions 4

What is the best way to resolve an issue caused by a frozen process?

A. Reboot the machine

B. Restart the process

C. Kill the process

D. Power off the machine

Browse 114 Q&As
Questions 5

What acceleration mode utilizes multi-core processing to assist with traffic processing?

A. CoreXL

B. SecureXL

C. HyperThreading

D. Traffic Warping

Browse 114 Q&As
Questions 6

How does the URL Filtering Categorization occur in the kernel?

1.

RAD provides the status of the search to the client.

2.

The a-sync request is forwarded to the RAD User space via the RAD kernel for online categorization.

3.

The online detection service responds with categories and the kernel cache is updated.

4.

The kernel cache notifies the RAD kernel of hits and misses.

5.

URL lookup initiated by the client.

6.

URL lookup occurs in the kernel cache.

7.

The client sends an a-sync request back to RAD If the URL was not found.

A. 5, 6, 7, 1, 3, 2, 4

B. 5, 6, 2, 4, 1, 7, 3

C. 5, 6, 4, 1, 7, 2, 3

D. 5, 6, 3, 1, 2, 4, 7

Browse 114 Q&As
Questions 7

Which command can be run in Expert mode to verify the core dump settings?

A. grep cdm /config/db/coredump

B. grep cdm /config/db/initial

C. grep $FWDIR/config/db/initial

D. cat /etc/sysconfig/coredump/cdm.conf

Browse 114 Q&As
Questions 8

What is the main SecureXL database for tracking acceleration status of traffic?

A. cphwd_db

B. cphwd_tmp1

C. cphwd_dev_conn_table

D. cphwd_dev_identity_table

Browse 114 Q&As
Questions 9

When debugging is enabled on firewall kernel module using the `fw ctl debug' command with required options, many debug messages are provided by the kernel that help the administrator to identify issues. Which of the following is true about these debug messages generated by the kernel module?

A. Messages are written to a buffer and collected using `fw ctl kdebug'

B. Messages are written to console and also /var/log/messages file

C. Messages are written to /etc/dmesg file

D. Messages are written to $FWDIR/log/fw.elg

Browse 114 Q&As
Questions 10

Which of the following is NOT a valid "fwaccel" parameter?

A. stat

B. stats

C. templates

D. packets

Browse 114 Q&As
Questions 11

What is the buffer size set by the fw ctl zdebug command?

A. 1 MB

B. 1 GB

C. 8MB

D. 8GB

Browse 114 Q&As
Questions 12

Which daemon governs the Mobile Access VPN blade and works with VPND to create Mobile Access VPN connections? It also handles interactions between HTTPS and the Multi-Portal Daemon.

A. Connectra VPN Daemon - cvpnd

B. Mobile Access Daemon - MAD

C. mvpnd

D. SSL VPN Daemon - sslvpnd

Browse 114 Q&As
Questions 13

If IPS protections that prevent SecureXL from accelerating traffic, such as Network Quota, Fingerprint Scrambling. TTL Masking etc, have to be used, what is a recommended practice to enhance the performance of the gateway?

A. Use the IPS exception mechanism

B. Disable all such protections

C. Disable SecureXL and use CoreXL

D. Upgrade the hardware to include more Cores and Memory

Browse 114 Q&As
Questions 14

Vanessa is reviewing ike.elg file to troubleshoot failed site-to-site VPN connection After sending Mam Mode Packet 5 the response from the peer is PAYLOAD-MALFORMED" What is the reason for failed VPN connection?

A. The authentication on Phase 1 is causing the problem.Pre-shared key on local gateway encrypted by the hash algorithm created in Packet 3 and Packet 4 doesn't match with the hash on the peer gateway generated by encrypting its preshared key

B. The authentication on Phase 2 is causing the problem Pre-shared key on local gateway encrypted by the hash algorithm created in Packets 1 and 2 doesn't match with the hash on the peer gateway generated by encrypting its pre-shared key

C. The authentication on Quick Mode is causing the problem Pre-shared key on local gateway encrypted by the hash algorithm created in Packets 3 and 4 doesn't match with the hash on the peer gateway generated by encrypting its preshared key

D. The authentication on Phase 1 is causing the problem Pre-shared key on local gateway encrypted by the hash algorithm doesn't match with the hash on the peer gateway generated by encrypting its pre-shared key created in Packet 1 and Packet 2

Browse 114 Q&As
Questions 15

Which Daemon should be debugged for HTTPS Inspection related issues?

A. FWD

B. HTTPD

C. WSTLSO

D. VPND

Browse 114 Q&As
Questions 16

Which of the following inputs is suitable for debugging HTTPS inspection issues?

A. vpn debug cptls on

B. fw ctl debug 璵 fw + conn drop cptls

C. fw diag debug tls enable

D. fw debug tls on TDERROR_ALL_ALL=5

Browse 114 Q&As
Questions 17

What command is used to find out which port Multi-Portal has assigned to the Mobile Access Portal?

A. mpclient getdata sslvpn

B. netstat -nap | grep mobile

C. mpclient getdata mobi

D. netstat getdata sslvpn

Browse 114 Q&As
Questions 18

RAD is initiated when Application Control and URL Filtering blades are active on the Security Gateway What is the purpose of the following RAD configuration file SFWDIR/conf/rad_settings.C?

A. This file contains the location information tor Application Control and/or URL Filtering entitlements

B. This file contains the information on how the Security Gateway reaches the Security Managers RAD service for Application Control and URL Filtering

C. This file contains RAD proxy settings

D. This file contains all the host name settings for the online application detection engine

Browse 114 Q&As
Exam Code: 156-585
Exam Name: Check Point Certified Troubleshooting Expert (CCTE)
Last Update: Mar 18, 2025
Questions: 114 Q&As

PDF

$49.99

VCE

$55.99

PDF + VCE

$65.99