156-583 Troubleshooting Administrator - R82 (CCTA) Practice Questions
Prepare for 156-583 with more than an answer.
- Level
- Infinity Specialist Accreditation
- Valid for
- 2 years
Domains covered on the exam 10
- Introduction to Troubleshooting10%
- Traffic Monitoring Fundamentals10%
- Packet Capture Fundamentals10%
- Packet Capture Analysis Using CLI10%
- Packet Capture Analysis Using Wireshark10%
- Check Point Processes Troubleshooting10%
- SmartConsole Troubleshooting10%
- Log Collection Troubleshooting10%
- Identity Awareness Troubleshooting10%
- Application Control and URL Filtering Troubleshooting10%
- 1
The command to capture traffic using the Check Point PCAP tool on an R82 Security Gateway and save the output to a file named 'capture.pcap' is: _________
Show answer details
Correct answer: A
Per the R82 CLI Reference Guide (cppcap), the output file is set with '-o ', for example 'cppcap -i eth0 -f "host 192.168.3.57" -o /var/log/capture.pcap'. In cppcap, '-w' and '-W' only control rotation of the output files (file size / number of files) and are valid only together with '-o'. 'fw monitor' also writes a file with '-o'; its '-w' captures the entire packet.
- 2
When performing a packet capture on a high-throughput production gateway using 'fw monitor', what is the most critical limitation or impact the administrator must consider?
Show answer details
Correct answer: D
In R82, fw monitor also shows traffic accelerated by SecureXL, so it does not disable acceleration. The main risk on a busy gateway is resource load: the R82 CLI Reference Guide warns that '-p all' (insert the FW Monitor module at all chain positions) causes very high CPU load, that the output file can grow very fast (write it to /var/log/), and that under large volumes you should limit the capture with '-ci'/'-co' and tight filters (for example '-F', which applies to both accelerated and non-accelerated traffic).
- 3
Which of the following are valid methods to define a capture filter when using the 'fw monitor' command? (Select TWO)
Show answer details
Correct answer: B, D
Per the R82 CLI Reference Guide (fw monitor), filters can be defined with '-e ' (or '-f '), for example -e 'accept src=10.1.1.1;', or with the simple filter '-F " , , , , "', where 0 means any (e.g. -F '10.1.1.1,0,0,0,0'). The INSPECT filters do not apply to accelerated traffic, while '-F' applies to both accelerated and non-accelerated traffic (up to 5 '-F' filters, combined with OR). fw monitor has no '--bpf' or '-tcpdump' option.
Per the R82 CLI Reference Guide (fw monitor), filters can be defined with '-e ' (or '-f '), for example -e 'accept src=10.1.1.1;', or with the simple filter '-F " , , , , "', where 0 means any (e.g. -F '10.1.1.1,0,0,0,0'). The INSPECT filters do not apply to accelerated traffic, while '-F' applies to both accelerated and non-accelerated traffic (up to 5 '-F' filters, combined with OR). fw monitor has no '--bpf' or '-tcpdump' option.
- 4
When troubleshooting a complex routing issue on an R82 Security Gateway, Check Point Support requests a comprehensive system data collection. Which of the following tools is the BEST choice to gather the required OS, configuration, and routing information into a single compressed file?
Show answer details
Correct answer: C
The 'cpinfo' utility is a Check Point auto-diagnostic tool that collects comprehensive system data, including OS configuration, routing tables, and Check Point registry data, into a single compressed file. It is the standard tool requested by TAC for initial troubleshooting. 'cpview' provides performance statistics, and 'cpstat' only provides real-time status for specific components.
- 5
As a Troubleshooting Administrator, you are investigating a gateway performance issue that occurred over the weekend. Which TWO of the following tools can provide historical data for post-incident analysis? (Select TWO)
Show answer details
Correct answer: B, C
CPView History Mode stores gateway statistics (CPU, memory, network, blades) for 30 days and is opened with 'cpview -t' ('cpview --history') per sk101878. SmartConsole Logs & Monitor keeps historical logs and views for the period. 'cpstat' and 'top' show only the current state.
CPView History Mode stores gateway statistics (CPU, memory, network, blades) for 30 days and is opened with 'cpview -t' ('cpview --history') per sk101878. SmartConsole Logs & Monitor keeps historical logs and views for the period. 'cpstat' and 'top' show only the current state.
- 6
A financial institution recently upgraded their primary Security Gateways to R82. Following the upgrade, the monitoring system reports intermittent high CPU utilization.
The troubleshooting administrator connects via SSH and runs the 'top' command, noticing that several 'fwk' processes are consuming 90% of the CPU. The administrator needs to isolate whether the issue is caused by high connection rates, complex NAT rules, or deep packet inspection.
Which of the following workflows represents the BEST methodology to isolate the cause of the high CPU utilization in this USFW (User Space Firewall) environment?
Show answer details
Correct answer: B
When 'top' shows the fwk (CoreXL Firewall instance) processes consuming CPU, the least disruptive way to isolate the cause is to use CPView. Its CPU views show per-core and per-instance utilization, and 'CPU > Top-Connections' lists the heaviest connections per CoreXL Firewall instance (sk101878). Once you know the heavy connections and the loaded instance, you can tell high connection rates apart from specific heavy flows or inspection load. Restarting processes, running unfiltered captures on a loaded gateway, or only checking memory does not isolate the cause.
