156-836 Certification - Valid Exam Dumps Questions Study Guide! (Updated 90 Questions) [Q25-Q47]

Share

156-836 Certification – Valid Exam Dumps Questions Study Guide! (Updated 90 Questions)

156-836 Dumps are Available for Instant Access using TestInsides


Individuals who have the CCSE R80 or higher certification are eligible to take the CheckPoint 156-836 exam. They must have prior experience working with Check Point Maestro and are expected to demonstrate advanced proficiency in this area. Check Point Certified Maestro Expert - R81 (CCME) certification is ideal for professionals working in the fields of network administration, IT security, and technology consulting.


To prepare for the exam, Check Point offers several training options, including an online self-study course, instructor-led courses, and hands-on lab sessions. Additionally, candidates can access a wealth of study materials, including practice exams, study guides, and documentation on the Check Point website. It is recommended that candidates have at least six months of experience working with Check Point Maestro before taking the exam.

 

NEW QUESTION # 25
What is one benefit of a Dual MHO environment?

  • A. Dual MHOs can be used to achieve increased scalability and redundancy.
    .
  • B. Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.
  • C. Dual MHOs allow better synchronization to occur between SGMs.
  • D. Dual MHOs allow additional SGMs to be added to the SG.

Answer: A

Explanation:
Explanation
One of the benefits of a Dual MHO environment is that it can provide both scalability and redundancy to the Maestro system. Scalability means that the system can handle more traffic and SGMs as the demand grows, and redundancy means that the system can survive the failure of one or more components without losing functionality or performance. Dual MHOs can achieve these benefits by distributing the load and the management tasks among two orchestrators, and by providing backup and failover mechanisms for each other.
References
*Maestro Expert (CCME) Course - Check Point Software, page 251
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 22
*Check Point Certified Maestro Expert (CCME) R81.X, page 23


NEW QUESTION # 26
How many orchestrators may Dual-Site include?

  • A. 0
  • B. 2 or 4
  • C. 1
  • D. Only 4

Answer: B

Explanation:
Explanation
A Dual Site environment can include either two or four orchestrators, depending on the scenario. There are three primary scenarios for Dual Site configuration:
*Direct connectivity between remote site orchestrators: This scenario requires two orchestrators, one for each site, and a direct connection between them using the site-sync port.
*Two orchestrators on the same site are connected to the remote site orchestrators through two different switches: This scenario requires four orchestrators, two for each site, and a connection between them using the site-sync port and two external switches that support QinQ and MTU increment.
*Two orchestrators on the same site are connected to the remote site orchestrators through one switch: This scenario also requires four orchestrators, two for each site, and a connection between them using the site-sync port and one external switch that supports QinQ and MTU increment.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
*Maestro Frequently Asked Questions (FAQ)


NEW QUESTION # 27
What happens when you make changes from Clish on the SMO Master?

  • A. The changes are synchronized to the SMS/MDS as a backup.
  • B. Changes are only applied on the SMO Master.
  • C. The changes are synchronized to the MHO as a backup.
  • D. Changes are applied to all members in the SG.

Answer: B

Explanation:
Explanation
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.2: Security Group Configuration, page 2-10
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Configuration, page 2-9
*Security Group Configuration - Check Point Software


NEW QUESTION # 28
What is the maximum number of Appliances within the same Security Group?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

Explanation:
Explanation
The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 51
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline


NEW QUESTION # 29
Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL.

  • A. SecureXL
  • B. hypersync
  • C. Fast Accelerator
  • D. rate limiting

Answer: A

Explanation:
SecureXL is typically used to accelerate trusted traffic, including non-F2F (face-to-face) traffic, through a secure, fast path.
References =
*SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above 1
*SecureXL Fast Accelerator - Need to clarify packet flow 2
1: https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk156672 2: https://community.checkpoint.com/t5
/Security-Gateways/SecureXL-Fast-Accelerator-Need-to-clarify-packet-flow/td-p/114651


NEW QUESTION # 30
Is it possible to define distribution mode per interface?

  • A. Yes, for both uplink and downlink interfaces
  • B. Yes, only for uplink interfaces
  • C. Yes, only for downlink interfaces
  • D. No, only for the Security Group

Answer: A

Explanation:
Maestro allows you to define the distribution mode per interface, which determines how traffic is distributed among the Security Group Modules (SGMs) in a Security Group. You can configure the distribution mode for each interface individually, or use the default mode for all interfaces. The distribution mode can be set for both uplink and downlink interfaces.
References =
*Check Point Maestro R81.X Administration Guide, page 62, section "Distribution Mode" 1
*Check Point Maestro R81.X Getting Started Guide, page 25, section "Distribution Mode" 2
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.
checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm


NEW QUESTION # 31
What happens if the SMO Master fails?

  • A. The next SGM with the current lowest SGM ID assumes the role of the SMO Master.
  • B. The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.
  • C. The Backup SMO Master will take over in the event of a failure with the SMO Master.
  • D. A failover will occur on the MHO and traffic will continue to pass.

Answer: C

Explanation:
The SMO Master is the SGM that is responsible for managing the Security Group and communicating with the MHO. If the SMO Master fails, the Backup SMO Master, which is the SGM with the next lowest SGM ID, will take over the role of the SMO Master and ensure the continuity of the Security Group operations.
References = Maestro Expert (CCME) Course - Check Point Software, page 14; Check Point Accredited Maestro Expert - New exam a... - Check Point CheckMates, page 1.


NEW QUESTION # 32
When a VPN tunnel is formed with a Maestro SGM,

  • A. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.
  • B. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.
  • C. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner.
  • D. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.

Answer: C


NEW QUESTION # 33
What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?

  • A. 1Gbps connectivity for Security Groups
  • B. Reserved for internal purposes. Not in use.
  • C. Out-of-band interfaces for access to Orchestrator itself
  • D. Additional ports used as uplinks

Answer: C

Explanation:
Explanation
The Management ports located on the Rear Panel of the Orchestrator MHO-140 are out-of-band interfaces that provide access to the Orchestrator itself for configuration and management purposes. They are not used for traffic distribution or connectivity to the Security Groups or the external networks. They are 1Gbps RJ-45 ports that can be connected to a switch or a router.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates2, page 4


NEW QUESTION # 34
Complete the sentence: Dual Orchestrators work as.______

  • A. Load Sharing cluster
  • B. Active-Active cluster
  • C. Active - Standby cluster
  • D. Hot-Swap RAID

Answer: B

Explanation:
Dual Orchestrators work as an Active-Active cluster, which means that both Orchestrators are active and share the load of the traffic that is sent to and from the Security Group Members (SGMs). Active-Active cluster provides better performance and scalability than Active-Standby cluster, which only uses one Orchestrator at a time and keeps the other as a backup. Active-Active cluster also allows for faster failover and recovery in case of an Orchestrator failure, as the surviving Orchestrator can take over the traffic without interruption.
References
*Maestro Expert (CCME) Course - Check Point Software, page 25
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 2


NEW QUESTION # 35
What kinds of transceivers are supported on Orchestrator MHO-140?

  • A. SFP+, SFP28, QSFP
  • B. SFP, SFP+, QSFP, QSFP28
  • C. SFP, QSFP, QSFP28
  • D. SFP, SFP+, SFP28

Answer: D

Explanation:
Explanation
According to the Maestro Hyperscale Orchestrator Datasheet1, the Orchestrator MHO-140 supports the following transceiver types: SFP, SFP+, SFP28. These transceivers can be used for the management, uplink, and downlink ports of the Orchestrator. The SFP transceivers support 1 GbE, the SFP+ transceivers support 10 GbE, and the SFP28 transceivers support 25 GbE.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software, page 2


NEW QUESTION # 36
What does the lldpctl command do?

  • A. Show all devices discovered by LLDP protocol on downlink ports
  • B. Show all devices discovered by LLDP protocol on uplink ports
  • C. Show all devices discovered by LLDP protocol on all ports
  • D. Discover orchestrators

Answer: C

Explanation:
Explanation
The lldpctl command is a tool to display information about the devices discovered by the Link Layer Discovery Protocol (LLDP) on all ports of the Maestro Orchestrator and the Security Group Members. LLDP is a protocol that enables devices to exchange information about their identity, capabilities, and configuration.
LLDP can help to discover the topology and connectivity of the Maestro environment.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.2: LLDP, page 4-9
*Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section:
LLDP, page 3-9


NEW QUESTION # 37
Maestro allows running commands globally in Expert mode by using global prefixes, such as:

  • A. all
  • B. g_all
  • C. asg all
  • D. global

Answer: B

Explanation:
The g_all prefix is used to run commands globally in Expert mode on all Security Group Members of the current Security Group. For example, g_all cpstop will stop the Check Point services on all SGMs. The other prefixes are not valid for global commands in Expert mode.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-11
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-9
*Global Expert Mode Commands - Check Point CheckMates


NEW QUESTION # 38
What is the command 'asg diag' used for?

  • A. Asg diag is used for system diagnostics
  • B. Asg diag is used for system backup
  • C. Asg diag used for system diagnostics on Chassis only. It does not exist on Maestro
  • D. Asg diag is used for creating traffic flow diagrams

Answer: A

Explanation:
Explanation
The asg diag command is used for system diagnostics on both Maestro and Chassis systems. The asg diag command can perform various tests and checks on the system components, such as hardware, software, network, clock, ARP, and more. The asg diag command can help identify and troubleshoot any issues or errors that may affect the system functionality or performance.
References =
*Check Point Maestro R81.X Administration Guide, page 66, section "asg diag" 1
*Check Point Maestro R81.X Getting Started Guide, page 28, section "asg diag" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 25
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M


NEW QUESTION # 39
There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?

  • A. 0
  • B. 1
  • C. Between 2 and 4
  • D. All 10

Answer: C

Explanation:
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23
*Check Point Maestro Frequently Asked Questions (FAQ), question 9
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.
checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%
20Maestro%20under%20the%20hood%202022.pptx :https://supportcenter.checkpoint.com/supportcenter
/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk147853&partition=Basic&product=Maestro


NEW QUESTION # 40
What is the maximum number of Appliances within Security group in Dual-Site configuration?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D


NEW QUESTION # 41
Which command is used to set the number of sites in a Maestro environment?

  • A. set maestro configuration orchestrator-site-amount
  • B. set maestro configuration orchestrator-site-number
  • C. set maestro configuration orchestrator-site-id
  • D. set maestro orchestrator-site-amount

Answer: A

Explanation:
Explanation
This command is used to set the number of sites in a Maestro environment, which can be either one or two.
The number of sites determines the site-sync configuration and the failover policies for the Security Groups and the Security Group Members. The default value is one, and it can be changed only before the first Security Group is created.
References =
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT


NEW QUESTION # 42
Logs without a dedicated log file can be found in

  • A. $FWDIR/log/fw.log
  • B. $RTDIR/log/junk.log
  • C. /var/log/junk.log.dbg
  • D. /var/log/messages

Answer: D

Explanation:
Explanation
The /var/log/messages file is a general system log file that contains information about various system events, such as booting, shutdown, cron jobs, kernel messages, and other system services. Logs without a dedicated log file can be found in this file, as well as some Maestro Gaia Clishcommands that are not saved in the
/var/log/command_logger.log file.
References
*Maestro Audit Logs - Where are they? - Check Point CheckMates1
*sk172923: The /var/log/messages file does not save Maestro Gaia Clish commands2
*Maestro Expert (CCME) Course - Check Point Software, page 33


NEW QUESTION # 43
Where should sx_api_ports_dump.py command be ran?

  • A. Management server
  • B. SMO Appliance
  • C. Security Group
  • D. Orchestrator

Answer: D

Explanation:
The sx_api_ports_dump.py command should be run on the Orchestrator, which is the device that manages the communication and the configuration of the Security Groups and the SGMs. The command shows the port mapping and the traffic distribution for each Security Group, as well as the backplane bonds and the Orchestrator ports. The command does not work on the Management server, the Security Group, or the SMO Appliance, as they do not have the same role and functionality as the Orchestrator.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 31
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 3


NEW QUESTION # 44
When security policy is installed

  • A. The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other membersretrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.
  • B. The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.
  • C. All SGMs receive the security policy and simultaneous policy installation occurs.
  • D. All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.

Answer: A

Explanation:
Explanation
This is the correct answer because it describes the security policy installation flow for a Maestro Security Group. The SMO Master is the Security Group Member that acts as the leader and the single point of contact for the Management Server. The SMO Master verifies the policy and installs it first, then notifies the other SGMs that a new policy is available. The other SGMs fetch the policy from the SMO Master and install it in parallel.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.3: Security Policy Installation, page 2-15
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Policy Installation, page 2-13
*Policy installation flow - Check Point Software


NEW QUESTION # 45
HealthCheck Point _____

  • A. performs a system health check and is meant to replace both a CPInfo and the health check script.
  • B. is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.
  • C. is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.
  • D. can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.

Answer: B

Explanation:
HealthCheck Point (HCP) is a tool that can perform various tests and checks on the system components of the Security Group Modules (SGMs), such as hardware, software, network, clock, ARP, and more. It can also display the performance statistics of the SGMs, such as throughput, packet rate, CPU utilization, memory usage, and more. Additionally, HCP can provide a graphical representation of the Firewall topology for the Security Group, showing the connections and statuses of the SGMs and the Orchestrators. Furthermore, HCP can generate a report of the critical and informative events that occurred on the system, such as configuration changes, errors, warnings, and alerts. HCP can help identify and troubleshoot any issues or errors that may affect the system functionality or performance.
References =
*HealthCheck Point (HCP) Release Updates - Check Point Software 1
*Professional Services Healthcheck - Check Point Software 2
*HealthCheck Point - Check Point CheckMates 3


NEW QUESTION # 46
Where should sx_api_ports_dump.py command be ran?

  • A. Management server
  • B. SMO Appliance
  • C. Security Group
  • D. Orchestrator

Answer: D

Explanation:
Explanation
The sx_api_ports_dump.py command should be run on the Orchestrator, which is the device that manages the communication and the configuration of the Security Groups and the SGMs. The command shows the port mapping and the traffic distribution for each Security Group, as well as the backplane bonds and the Orchestrator ports. The command does not work on the Management server, the Security Group, or the SMO Appliance, as they do not have the same role and functionality as the Orchestrator.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 31
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 3


NEW QUESTION # 47
......


To prepare for the CCME certification exam, candidates are required to have a solid understanding of networking and security principles, as well as experience in managing complex network infrastructures. They are also recommended to undergo training in Check Point Maestro and to familiarize themselves with the latest features and functionalities of the solution. There are numerous resources available online, including study guides, practice exams, and training courses, that can help candidates prepare for the exam.

 

CheckPoint 156-836 Exam Practice Test Questions: https://www.testinsides.top/156-836-dumps-review.html

156-836 Dumps 2026 - New CheckPoint 156-836 Exam Questions: https://drive.google.com/open?id=1H823ioTpTsljZme7OafTgW0R8vWYEqk-