Skip to main content

156-582 Real Exam Questions

Check Point Certified Troubleshooting Administrator - R81.20 (CCTA)

75 questions available · Page 1 of 8

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Running tcpdump causes a significant increase on CPU usage, what other option should you use?

  1. A

    fw monitor

  2. B

    Wait for out of business hours to do a packet capture

  3. C

    cppcap

  4. D

    You need to use tcpdump with -e option to decrease the length of packet in captures and it will utilize the less CPU

Show answer and explanation

Correct answer: C

Question 2 Single choice

The communication between the Security Management Server and Security Gateway to forward logs is done using the following process and port number:

  1. A

    fwd, TCP 257

  2. B

    cpm, 19009

  3. C

    fwm, TCP 18190

  4. D

    fwm, TCP 257

Show answer and explanation

Correct answer: A

Question 3 Single choice

What is the impact of an expired or missing contract file?

  1. A

    The existing protection settings will be removed in SmartConsole but protections are still being enforced by the Security Gateway.

  2. B

    The existing protection settings display in SmartConsole remain and during policy install the Security Gateway asks the administrator to put a new contract file during policy install.

  3. C

    The existing protection settings display in SmartConsole remain and the Security Gateway will use a
    14-day EVAL free license instead.

  4. D

    The existing protection settings display in SmartConsole remain but are not being enforced by the Security Gateway.

Show answer and explanation

Correct answer: D

Question 4 Single choice

Select the correct statement about service contracts.

  1. A

    Valid service contracts must be stored only on the Security Gateways that have Threat Prevention blades enabled

  2. B

    Service contracts are provided on paper only

  3. C

    Valid service contracts are only stored and required on the Primary Security Management Server and never downloaded on any other system

  4. D

    Valid service contracts must be stored on the Security Management Server before they can be downloaded to a Security Gateway

Show answer and explanation

Correct answer: D

Question 5 Single choice

How do you verify that Proxy ARP entries are loaded into the kernel?

  1. A

    fw ctl arp

  2. B

    show arp dynamic all

  3. C

    This information can be viewed in the logs, under NAT section of log, field: Proxy ARP entry

  4. D

    fw ctl get arp list all

Show answer and explanation

Correct answer: A

Question 6 Single choice

What are some measures you can take to prevent IPS false positives?

  1. A

    Capture packets, Update the IPS database, and Back up custom IPS files

  2. B

    Use Recommended IPS profile

  3. C

    Use IPS only in Detect mode

  4. D

    Exclude problematic services from being protected by IPS (sip, H.323, etc.)

Show answer and explanation

Correct answer: B

Question 7 Single choice

To verify that communication is working between the Security Management Server and the Security Gateway, which service port should be checked?

  1. A

    257

  2. B

    18209

  3. C

    259

  4. D

    19009

Show answer and explanation

Correct answer: A

Question 8 Single choice

The URL filtering cache limit exceeded.

What issues can this cause?

  1. A

    When URL filtering cache exceeds the limit, it will be disabled temporarily to overcome instability of the system

  2. B

    RAD process will spawn multiple times to help populate the cache

  3. C

    Resource Advisor (RAD) process on the Security Gateway consumes close to 100 percent of the CPU

  4. D

    Nothing, the Security Gateway dynamically raises the cache when needed

Show answer and explanation

Correct answer: C

Question 9 Single choice

After deploying a new Static NAT configuration, traffic is not getting through.

What command would you use to verify that the proxy ARP configuration has been loaded?

  1. A

    fw ctl conn

  2. B

    fw ctl arp

  3. C

    fw arp ctl

  4. D

    cp ctl arp

Show answer and explanation

Correct answer: B

Question 10 Single choice

After deploying a new Static NAT configuration, traffic is not getting through.

What command would you use to troubleshoot internal problems with the NAT traffic?

  1. A

    fw ctl kdebug + xlate xltrc nat

  2. B

    cp ctl zdebug + xlate xltrc nat

  3. C

    fw ctl zdebug + xlate xltrc nat

  4. D

    cp ctl kdebug + xlate xltrc nat

Show answer and explanation

Correct answer: C