156-551 Check Point Certified VSX Specialist - R81 (CCVS) Practice Questions
Prepare for 156-551 with more than an answer.
- Exam fee
- $250 USD
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 6
- VSX Architecture and Components20%
- VSX Installation and Configuration25%
- VSX Routing and Networking20%
- VSX High Availability and Clustering20%
- VSX Management and Optimization15%
- VSX Troubleshooting and Maintenance20%
- 1
What is the primary benefit of the VSX Provisioning Tool (vsx_provisioning_tool) over manually creating each Virtual System in SmartConsole?
Show answer details
Correct answer: B
The VSX Provisioning Tool is the vsx_provisioning_tool command. It runs from the command line of the Security Management Server or Domain Management Server (or a SmartConsole computer with -s) and adds, modifies and removes Virtual Devices (VS, VS in bridge mode, VSW, VR), their interfaces and routes, from the -o option or from an input file (-f) of commands grouped in transactions. This allows automation of VSX provisioning. It is not a SmartConsole GUI feature and does not use templates.
- 2
True or False: In a VSX VSLS cluster, it is possible to have VSID 2 active on member A and VSID 3 active on member B simultaneously.
Show answer details
Correct answer: A
This statement is true and describes the fundamental principle of Virtual System Load Sharing (VSLS). In VSLS mode, the cluster actively distributes the Virtual Systems among the physical members. This allows different VSs to be active on different members at the same time, effectively sharing the overall workload across the cluster's hardware.
- 3
What does the
vsx_util upgradecommand do during a VSX major version upgrade?Show answer details
Correct answer: A
'vsx_util upgrade' runs in Expert mode on the Security Management Server (or Main Domain Management Server) and upgrades the version of the VSX Gateway / VSX Cluster object in the management database; it does not touch the gateways or take snapshots. The gateways are upgraded separately, and the change can be reverted with 'vsx_util downgrade' only if no configuration changes were made after the upgrade (R81.10 VSX Admin Guide; Installation and Upgrade Guide).
- 4
A new VSX cluster is being installed. The administrator has completed the Gaia First Time Configuration Wizard on both members. What is the next critical step that must be performed in SmartConsole to establish the VSX cluster?
Show answer details
Correct answer: C
After the initial Gaia configuration, the management server needs to be made aware of the cluster members. This is done by creating a new VSX Cluster object in SmartConsole. During this object creation wizard, the administrator must initialize Secure Internal Communication (SIC) with each physical member of the cluster. This establishes the trusted connection required for policy installation and management.
- 5
A company is migrating from a physical firewall infrastructure to a single VSX Gateway. They need to replicate a DMZ environment that was previously handled by a dedicated physical firewall. The DMZ hosts web servers that need to be accessible from the internet but should not be able to initiate connections to the internal corporate network.
Which VSX components should be used to create a logically equivalent DMZ?
graph TD Internet -->|Traffic| VS_External[VS External] VS_External -->|Routed| VR[Virtual Router] VR -->|Routed| VS_DMZ[VS DMZ] VR -->|Routed| VS_Internal[VS Internal]Show answer details
Correct answer: A
The standard and most secure way to replicate a physical DMZ in VSX is to create a dedicated Virtual System for the DMZ. This VS will have its own security policy, interfaces (physical or VLAN), and routing configuration. Another separate Virtual System would be created for the internal network. Communication between the zones (Internet, DMZ, Internal) can then be controlled via a Virtual Router or external routing, with security policies on each VS enforcing the access rules.
- 6
An administrator is troubleshooting state synchronization on a VSX cluster member (R81.10). Which Expert-mode command shows the Delta Sync statistics (for example lost and retransmitted sync packets)?
Show answer details
Correct answer: C
The Expert-mode command 'cphaprob syncstat' (Gaia Clish: 'show cluster statistics sync') shows the Delta Sync transport statistics (sent/received updates, lost/retransmitted packets, queue sizes), and 'cphaprob -reset syncstat' resets them (R81.10 ClusterXL Admin Guide). vsx_util has no sync sub-command; 'cphaprob -a if' shows interfaces and 'fw ctl multik stat' shows CoreXL instances.
- 7
A security architect is designing a multi-tenant VSX environment. The design requires traffic between two specific Virtual Systems, VS_A (VSID 2) and VS_B (VSID 3), to be routed internally. Which set of components is essential for this configuration?
Show answer details
Correct answer: D
To achieve Layer 3 routing between Virtual Systems within a single VSX Gateway, a Virtual Router (VR) is required. Each Virtual System then connects to this VR using a special virtual interface called a Warp Link. The VR handles the routing decisions to forward traffic between the networks associated with each VS. A Virtual Switch provides only Layer 2 connectivity. A shared physical interface or bridge mode are not used for this type of internal routing.
- 8
A consultant is tasked with deploying a new Virtual System on an existing VSX R81.10 Gateway. The traffic for this new VS will arrive on physical interface eth3, tagged for VLAN 200. Which TWO of the following objects must be created and configured in SmartConsole to facilitate this? (Select TWO)
Show answer details
Correct answer: C, D
You need a Virtual System object (the new virtual firewall). In its Topology you add a Regular interface on eth3 with VLAN Tag 200 (VSX names it eth3.200). For more than one VLAN or Virtual System on the same port, eth3 is marked as a VLAN Trunk on the VSX Gateway object's Physical Interfaces page. A Bond, a Virtual Router or a Virtual Switch is not required for this scenario.
You need a Virtual System object (the new virtual firewall). In its Topology you add a Regular interface on eth3 with VLAN Tag 200 (VSX names it eth3.200). For more than one VLAN or Virtual System on the same port, eth3 is marked as a VLAN Trunk on the VSX Gateway object's Physical Interfaces page. A Bond, a Virtual Router or a Virtual Switch is not required for this scenario.
- 9
A junior administrator is configuring a new 8-core VSX Gateway and needs to enable CoreXL for performance optimization. Which standard Check Point utility provides the interactive menu to enable CoreXL and define the number of firewall instances?
Show answer details
Correct answer: C
cpconfigis the primary command-line, menu-driven utility for initial and fundamental configuration of a Check Point gateway, including a VSX Gateway. It allows an administrator to enable or disable features like ClusterXL and CoreXL, and to set the number of firewall kernel instances for CoreXL. The other commands are used for different specific tasks:vsx_utilfor VSX maintenance,fwaccelfor SecureXL, andcphaconffor clustering. - 10
A financial services company has a two-member VSX cluster that was upgraded to R81.10 and still runs in High Availability mode. All Virtual Systems are Active on member A, which is overloaded, mainly by VS_Trading (VSID 10); member B is idle in Standby. The team wants member B to process VS_Trading's traffic while all other Virtual Systems stay Active on member A and still keep a Standby peer, without buying new hardware.
Which approach meets these requirements?
Show answer details
Correct answer: A
In a VSLS cluster each Virtual System is Active on exactly one member at a time (a single VS is not split across members). Load is spread by making different Virtual Systems Active on different members. A cluster that was upgraded to R81.10 in High Availability mode is converted with 'vsx_util convert_cluster' (after enabling Per Virtual System State and ClusterXL for Bridge Active/Standby in cpconfig on each member), and 'vsx_util vsls' option 'Manually set priority and weight' then sets priority 0 (Active) on member B for VS_Trading while the other Virtual Systems keep priority 0 on member A and priority 1 (Standby) on member B, so they still have an Active/Standby peer. There is no 'Per-VS High Availability' mixed mode; in High Availability mode all VSs are Active on the same member. (R81.10 VSX Administration Guide p161-162, p187-188, p192, p201)
