Skip to content

156-836 Maestro Expert R81.1 (CCME) Practice Questions

Prepare for 156-836 with more than an answer.

229 questions in the full set20 sample questionsUpdated Jan 24, 2026
Exam fee
$200 USD
Level
Specialist
Valid for
3 years
Domains covered on the exam 9
  1. Scalability and Hyperscale12%
  2. Maestro Security Groups and the Single Management Object15%
  3. Administrator Operations12%
  4. Traffic Flow13%
  5. System Diagnostics and Tracking Changes12%
  6. Troubleshooting12%
  7. Dual Orchestrator Environment12%
  8. Dual Site Environment10%
  9. Upgrades12%
  1. 1

    A new appliance is assigned to an existing Maestro R81.10 Security Group with add maestro security-group id 1 serial and the configuration is applied, but it does not become an active member. The appliance is physically connected and powered on. What is a common cause of this failure?

    Show answer details

    Correct answer: D

    A Security Group runs as one clustered gateway, so every Security Group Member must run the same software packages (version and Jumbo Hotfix Take) as the rest of the group. For this reason Check Point recommends enabling SMO Image Cloning (set smo image auto-clone state on) on the Security Group before adding appliances; it automatically clones all the required software packages to the new appliances. Since R81.10 different appliance models can be in the same Security Group (sk162373, with SMO Image Cloning disabled for mixed models), a license problem does not stop a member from joining the cluster, and the Orchestrator discovers appliances without a reboot.

  2. 2

    After configuring Security Groups on the Quantum Maestro Orchestrators (R81.10), what does Check Point recommend to save the Orchestrators' configuration?

    Show answer details

    Correct answer: C

    The R81.10 Maestro Administration Guide's workflow states: 'Best Practice - Create a Gaia Backup on the Quantum Maestro Orchestrators to save the configuration' (Gaia Administration Guide > Maintenance > System Backup; snapshots are also available). asg_config save saves the Gaia gClish configuration of a Security Group's SGMs, not the Orchestrator. The SmartConsole object holds policy and object settings, not the Orchestrator's Security Group topology. asg_info collects diagnostic data for support.

  3. 3

    A university is using a Maestro deployment to protect its campus network. The student dormitory network needs a more restrictive policy and the faculty network a more lenient one. The two networks must be managed as completely independent Security Gateways, each with its own policy and its own dedicated SGMs, on the same Maestro Orchestrators. Which architectural approach achieves this goal?

    Show answer details

    Correct answer: B

    This scenario is a classic use case for multiple Security Groups. By creating one Security Group for the student network and another for the faculty network, the administrator can treat them as two independent firewalls. Each group will have its own SMO, allowing a completely separate and distinct security policy to be installed on each one. This provides strong logical separation and simplifies policy management.

  4. 4

    An administrator is tasked with performing a full upgrade of a dual-site Maestro environment from R81.10 to R81.20. What is the correct high-level sequence of operations to minimize downtime and risk?

    Show answer details

    Correct answer: A

    The Dual Site upgrade procedure in the Maestro guide upgrades all Orchestrators first, and only then the Security Groups, one Orchestrator at a time. First, the Orchestrators on the Standby Site are upgraded. Next, each Security Group fails over to the upgraded site ("chassis_admin -c down" then "... up"), and the Orchestrators on the other site are upgraded. Then each Security Group is upgraded, one group at a time. The mode is set to Active/Standby - Primary Up with a site priority, and all members on the Standby Site are upgraded first. Then all members on the other site are upgraded, and the previous mode is restored. Upgrading both sites at once, or isolating a site, causes an outage or an unsupported state.

  5. 5

    A new administrator is trying to understand the traffic flow in a Maestro deployment. A simplified representation is shown below. What component is responsible for the 'Distribution Decision' step?

    flowchart TD A[External Traffic] --> B{Distribution Decision} B --> C[SGM 1] B --> D[SGM 2] B --> E[SGM n] C --> F[Internal Network] D --> F E --> F
    Show answer details

    Correct answer: D

    The Maestro Orchestrator acts as the load balancer and traffic director for the entire system. It receives all incoming traffic, applies a hashing algorithm based on the configured distribution mode, and makes the decision on which specific Security Gateway Module (SGM) will handle that connection. It is the central point for the 'Distribution Decision' shown in the diagram.

  6. 6

    A financial institution is deploying a Maestro R81.10 Dual Site environment in which the sites are connected through Layer 2 switches over a long-distance link. Which requirement applies to the connection between the Layer 2 switches on the two sites?

    Show answer details

    Correct answer: D

    The Quantum Maestro Getting Started Guide (Dual Site with switches) requires: 'Latency between the Layer 2 switches on different sites must be lower than 100ms' and 'Packet lost between the Layer 2 switches on different sites must be lower than 5%.' The sites synchronize both connections and configuration, so the inter-site path matters. Direct connection between sites is the best practice; the switch-based designs carry the Site Sync VLANs (default 3600/3601).

  7. 7

    An administrator is investigating a performance issue in a Maestro Security Group. They suspect that a small number of very heavy connections are being concentrated on a single Security Gateway Module (SGM), overwhelming it. Which command would provide the most direct evidence of this traffic distribution imbalance by showing the number of connections per SGM?

    Show answer details

    Correct answer: A

    "asg perf -v" adds a "Per SGM Distribution Summary" to the continuously updated asg perf view. The summary shows each Security Group Member's throughput, packet rate, connection rate, concurrent connections, core loads and memory usage, which makes a connection or load imbalance between members visible. "cphaprob stat" is not the Maestro tool for this. "asg stat -i tasks" shows which member runs the SMO and the other tasks. "asg monitor" continuously shows the same member and component status as "asg stat".

  8. 8

    A Maestro environment has two Orchestrators on one site. During a planned upgrade, the upgrade of the second Orchestrator fails. The first Orchestrator and all SGMs still run the old version. What is the documented way to recover the failed Orchestrator?

    Show answer details

    Correct answer: A

    The R81.10 guide has a procedure titled "Rolling Back a Failed Upgrade of a Maestro Orchestrator". It reverts the Orchestrator to its pre-upgrade configuration: Gaia settings, Security Group topology and physical port configuration. Work on one Orchestrator at a time. In Expert mode, stop the Orchestrator service with "orchd stop". Then, in Gaia Clish, restore the Gaia snapshot created automatically during the upgrade with "set snapshot revert". The Orchestrator reboots and reverts. After that, align date and time with the other Orchestrators and verify connectivity. Both Orchestrators then run the same version again, which is required. Rebooting, continuing the upgrade on the other Orchestrator, or copying files by SCP does not restore a consistent state.

  9. 9

    True or False: In a Maestro environment, the Single Management Object (SMO) IP address is a virtual IP that always resides on the designated SMO Master SGM.

    Show answer details

    Correct answer: B

    False. The Security Group has one management IP address, but all Security Appliances in the Security Group use this IPv4 address as their Gaia management IP address; it is not a virtual IP that moves to the SMO Master. The SMO Master (the Active Security Group Member with the lowest ID) handles the management tasks, such as policy installation and logging, and updates the other members.

  10. 10

    Which TWO statements about Layer 4 distribution in a Maestro R81.10 Security Group are correct? (Select TWO)

    Show answer details

    Correct answer: D, E

    R81.10 Admin Guide, Working with the Distribution Mode: "The default mode is Auto-Topology (Per-Port) and the Layer 4 distribution is enabled." With Layer 4 distribution enabled, User (Internal) mode assigns packets by Source Port + Destination IP, Network (External) mode by Source IP + Destination Port, and General mode by Source IP, Source Port, Destination IP and Destination Port. You enable or disable it in gClish with set distribution l4-mode {enabled|disabled} and check it with show distribution l4-mode. Maestro has no payload-offset (user-defined) distribution and no asg_user_distribution or g_asg_distribution_gslb_by_ip command.

    R81.10 Admin Guide, Working with the Distribution Mode: "The default mode is Auto-Topology (Per-Port) and the Layer 4 distribution is enabled." With Layer 4 distribution enabled, User (Internal) mode assigns packets by Source Port + Destination IP, Network (External) mode by Source IP + Destination Port, and General mode by Source IP, Source Port, Destination IP and Destination Port. You enable or disable it in gClish with set distribution l4-mode {enabled|disabled} and check it with show distribution l4-mode. Maestro has no payload-offset (user-defined) distribution and no asg_user_distribution or g_asg_distribution_gslb_by_ip command.

Create an account to continue.