156-587 Troubleshooting Expert - R81.20 (CCTE) Practice Questions
Prepare for 156-587 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 266 questions Current
- 156-585Legacy Troubleshooting Expert (CCTE) - R81 284 questions Locked
- Exam fee
- $200 USD
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 9
- Introduction to Advanced Troubleshooting10%
- Advanced Management Server Troubleshooting15%
- Advanced Troubleshooting with Logs and Events10%
- Advanced Gateway Troubleshooting15%
- Advanced Firewall Kernel Debugging15%
- Advanced Access Control Troubleshooting10%
- Advanced Identity Awareness Troubleshooting10%
- Advanced Site-to-Site VPN Troubleshooting10%
- Advanced Client-to-Site VPN Troubleshooting5%
- 1
You are troubleshooting a Mobile Access VPN issue where users are complaining that the SSL Network Extender (SNX) client fails to initialize and displays a generic connection error. You suspect a problem with the Mobile Access Portal. Which log file on the Security Gateway would contain the most relevant information for debugging the portal and SNX initialization process?
Show answer details
Correct answer: C
The
cvpnd(Check Point VPN Daemon) process is responsible for the Mobile Access Portal and SSL Network Extender (SNX) services. Its primary log file is$CVPNDIR/log/cvpnd.elg. This log contains detailed information about portal access, user authentication, SNX client negotiation, and initialization, making it the essential resource for troubleshooting these types of issues.$FWDIR/log/vpnd.elgis for IPsec VPNs, not Mobile Access. - 2
Case Study:
An e-commerce company has a primary data center with a Check Point cluster and a disaster recovery (DR) site with a standalone gateway. A route-based VPN is configured between the sites. During a DR test, the BGP session between the sites fails to establish over the VPN tunnel. The network team has confirmed that the Virtual Tunnel Interfaces (VTIs) are up on both sides and that static routes through the tunnel work correctly.
A kernel debug (
fw ctl zdebug + drop) on the primary site's gateway shows that BGP packets (TCP port 179) from the DR site are being dropped with the reasondropped by fw_early_nat_check. The NAT rulebase does not contain any rules that should match this traffic.What is the most likely cause of this drop?
Show answer details
Correct answer: D
The
fw_early_nat_checkdrop for traffic over a VTI, especially for dynamic routing protocols, is a classic symptom of the global propertyvpn_route_based_natbeing enabled. This property forces NAT on traffic entering a VTI, which breaks protocols like BGP that require direct, non-NATed communication between peers. The correct configuration for running dynamic routing over route-based VPNs is to disable this property in GuiDBedit to prevent the early NAT check from dropping the packets. - 3
A user reports that they are being blocked from accessing a legitimate partner website. The security administrator checks the logs and sees the traffic is being dropped by an Access Control rule. To understand exactly which part of the rule is causing the match (e.g., source, destination, service, etc.), the administrator wants to find the Universal Unique Identifier (UUID) of the specific rule in the logs. Where can this information be found in the SmartConsole Log View?
Show answer details
Correct answer: B
When you select a log entry in the SmartConsole Log View, the bottom pane displays detailed information. Within this pane, there is a 'Matched Rule' (or 'Rule') section. This section explicitly shows the Rule Number, Rule Name, and the Rule UUID. This UUID is the definitive identifier that can be used to query the management database via API or other tools to get all details about the rule that processed the traffic.
- 4
A system administrator needs to troubleshoot a failing AD Query connection from an Identity Awareness gateway to a domain controller. Which three actions are essential first steps for diagnosing this issue? (Select THREE).
Show answer details
Correct answer: A, B, D
- 5
A new administrator is learning about Check Point's core processes. They need to understand the relationship between the main user-mode daemons. Which diagram BEST represents the communication flow during a SmartConsole login and policy installation?
sequenceDiagram participant SC as SmartConsole participant SMS as Security Management Server participant GW as Security Gateway Note over SC, SMS: Initial Login SC->>SMS: Login Request (CPM, TCP/19009) SMS-->>SC: Authentication Response Note over SC, SMS: Policy Installation SC->>SMS: Initiate Policy Install (FWM, TCP/18190) SMS->>SMS: FWM verifies and compiles policy SMS->>GW: Transfer Policy (CPD, TCP/18211) GW-->>SMS: Acknowledge Transfer SMS-->>SC: Installation StatusShow answer details
Correct answer: C
The diagram incorrectly shows policy transfer occurring over TCP/18211 by the CPD process. Policy installation from the Management Server to the Security Gateway is handled by the CPD (Check Point Daemon) process over TCP port 18191, which is the SIC (Secure Internal Communication) port. The FWM process on the SMS handles the compilation and initiates the transfer, but the actual data transfer to the gateway's CPD uses 18191.
- 6
A financial services company is experiencing intermittent failures with their Management High Availability (MHA) synchronization. The primary Security Management Server (SMS) reports 'synchronization is running', but the secondary SMS shows a 'collision' state and fails to become active. A network trace reveals no packet loss between the management servers. Which initial command should a troubleshooting expert run on the primary SMS to diagnose the cause of the collision state?
Show answer details
Correct answer: D
The
ha_diagnostic.shscript is the designated tool for in-depth analysis of MHA issues. It specifically checks for database schema differences, object inconsistencies, and other factors that lead to a 'collision' state, which is often caused by out-of-band changes on one of the servers. Whilecpstat haprovides status, it doesn't diagnose the root cause of a collision. Restarting event processes (evstop/evstart) is unlikely to resolve a database-level conflict.mds_backupis for backups, not MHA diagnostics. - 7
During a performance audit of a Check Point R81.20 cluster, an administrator observes that traffic for a high-volume, trusted internal application is being handled by the Firewall Worker (fwk) processes instead of being accelerated by SecureXL. The rule for this traffic is placed at the top of the policy, and logs confirm it is being matched. Which of the following is the MOST likely reason for this behavior?
Show answer details
Correct answer: C
SecureXL cannot accelerate connections that require advanced logging. Setting the track option to 'Detailed Log' or 'Extended Log' forces the connection to be passed to the Firewall Worker (fwk) process for deeper inspection and logging, bypassing acceleration. This is a common reason for expected traffic not being offloaded. The cluster mode, dynamic NAT, and CoreXL instance count affect performance in other ways but do not inherently prevent SecureXL from accelerating a connection that is otherwise eligible.
- 8
A hospital's security team is troubleshooting an Identity Awareness issue where physicians using shared workstations cannot be uniquely identified, causing incorrect policy application. The current setup uses AD Query. The goal is to force each user to authenticate when they access a specific set of clinical research portals, regardless of any existing session from a previous user on the same machine. Which configuration change would BEST achieve this requirement?
Show answer details
Correct answer: C
Browser-Based Authentication (Captive Portal) is the ideal solution for this scenario. By setting it as a required action in the access control rule governing access to the clinical portals, the gateway will intercept the HTTP/S request and force the user to authenticate via a web page. This overrides any existing identity session for that workstation and ensures the current user is correctly identified for that specific destination. Terminal Server agent is for multi-user servers, not shared workstations. An Access Role is used for policy but doesn't force re-authentication. Decreasing session timeouts is a blunt instrument and doesn't guarantee immediate re-authentication.
- 9
A user is unable to connect to the corporate network using the Check Point Mobile Access VPN client. The connection fails during the key negotiation phase. The administrator runs
vpn debug truncon the Security Gateway and captures the IKE debug logs. The output contains the message:NO_PROPOSAL_CHOSEN. What are the two MOST likely causes of this error? (Select TWO).Show answer details
Correct answer: B, D
- 10
An administrator is troubleshooting a slow policy installation process to a remote Security Gateway. Which two processes on the Security Management Server are primarily responsible for compiling the policy and transferring it to the gateway? (Select TWO).
Show answer details
Correct answer: A, B
