Exam Details

  • Exam Code
    :156-585
  • Exam Name
    :Check Point Certified Troubleshooting Expert
  • Certification
    :CCTE
  • Vendor
    :CheckPoint
  • Total Questions
    :114 Q&As
  • Last Updated
    :May 08, 2024

CheckPoint CCTE 156-585 Questions & Answers

  • Question 41:

    What is the buffer size set by the fw ctl zdebug command?

    A. 1 MB

    B. 1 GB

    C. 8MB

    D. 8GB

  • Question 42:

    The Check Pom! Firewall Kernel is the core component of the Gaia operating system and an integral part of the traffic inspection process There are two procedures available for debugging the firewall kernel

    Which procedure/command is used for troubleshooting packet drops and other kernel activites while using minimal resources (1 MB buffer)?

    A. fw ctl zdebug

    B. fw ctl debug/kdebug

    C. fwk ctl debug

    D. fw debug ctl

  • Question 43:

    What are the four ways to insert an FW Monitor into the firewall kernel chain?

    A. Relative position using location, relative position using alias, absolute position, all positions

    B. Absolute position using location, absolute position using alias, relative position, all positions

    C. Absolute position using location, relative position using alias, general position, all positions

    D. Relative position using geolocation, relative position using inertial navigation, absolute position, all positions

  • Question 44:

    You are trying to establish a VPN tunnel between two Security Gateways but fail. What initial steps will you make to troubleshoot the issue

    A. capture traffic on both tunnel members and collect debug of IKE and VPND daemon

    B. capture traffic on both tunnel members and collect kernel debug for fw module with vm, crypt, conn and drop flags, then collect debug of IKE and VPND daemon

    C. collect debug of IKE and VPND daemon and collect kernel debug for fw module with vm, crypt, conn and drop flags

    D. capture traffic on both tunnel members and collect kernel debug for fw module with vm, crypt, conn and drop flags

  • Question 45:

    What is the correct syntax to turn a VPN debug on and create new empty debug files?

    A. vpn debug truncon

    B. vpndebug trunc on

    C. vpn kdebug on

    D. vpn debug trunkon

  • Question 46:

    Rules within the Threat Prevention policy use the Malware database and network objects. Which directory is used for the Malware database?

    A. $FWDIR/conf/install_manager_tmp/ANTIMALWARE/conf/

    B. $CPDIR/conf/install_manager_lmp/ANTIMALWARE/conf/

    C. $FWDlR/conf/install_firewall_imp/ANTIMALWARE/conf/

    D. $FWDlR/log/install_manager_tmp/ANTIMALWARBlog?

  • Question 47:

    What is the name of the VPN kernel process?

    A. VPNK

    B. VPND

    C. CVPND

    D. FWK

  • Question 48:

    Jenna has to create a VPN tunnel to a CISCO ASA but has to set special property to renegotiate the Phase 2 tunnel after 10 MB of transferee1 data. This can not be configured in the smartconsole, so how can she modify this property?

    A. using GUIDBEDIT located in same directory as Smartconsole on the Windows client

    B. she need to install GUIDBEDIT which can be downloaded from the Usercenter

    C. she need to run GUIDBEDIT from CLISH which opens a graphical window on the smartcenter

    D. this cant be done anymore as GUIDBEDIT is not supported in R80 anymore

  • Question 49:

    Check Point Threat Prevention policies can contain multiple policy layers and each layer consists of its own Rule Base

    Which Threat Prevention daemon is used for Anti-virus?

    A. in.emaild.mta

    B. in.msd

    C. ctasd

    D. in emaild

  • Question 50:

    Which is the correct "fw monitor" syntax for creating a capture file for loading it into WireShark?

    A. fw monitor -e "accept;" >> Output.cap

    B. This cannot be accomplished as it is not supported with R80.10

    C. fw monitor -e "accept;" -file Output.cap

    D. fw monitor -e "accept;" -o Output.cap

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CheckPoint exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 156-585 exam preparations and CheckPoint certification application, do not hesitate to visit our Vcedump.com to find your solutions here.