
Easy To Download CheckPoint 156-836 Exam Dumps Updated 90 Questions
New Updated 156-836 Exam Questions 2026
The CheckPoint 156-836 exam consists of 90 multiple-choice questions and is delivered through Pearson VUE, a leading provider of computer-based testing. Candidates are given 90 minutes to complete the exam and must score at least 70% to pass. 156-836 exam covers topics such as Maestro management and configuration, troubleshooting, and deployment best practices.
NEW QUESTION # 19
What is the difference between Dual-Site and Dual-Room?
- A. Dual-Room is a kind of Dual-Site deployment within the same building
- B. They are the same
- C. Dual-Room is a Single-Site deployment where all Appliances are connected to both orchestrators
- D. Dual-Room is Active / Standby and Dual-Site is Active / Active
Answer: A
Explanation:
References =
*[Maestro Frequently Asked Questions (FAQ)]
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 20
The drop_monitor command is useful for
- A. Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR
- B. Monitoring Check Point code drops
- C. Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs.
- D. Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops.
Answer: D
Explanation:
Explanation
The drop_monitor command is a tool that monitors and displays the packets that are dropped by the Check Point code or the Gaia OS on the orchestrator and the appliances. It can help troubleshoot network issues and optimize performance. The command shows the drop reason, source, destination, protocol, and port of the dropped packets, as well as the interface and the module that dropped them.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates1
*Support, Support Requests, Training ... - Check Point Software2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge
NEW QUESTION # 21
Which command is used to set the number of sites in a Maestro environment?
- A. set maestro configuration orchestrator-site-number
- B. set maestro configuration orchestrator-site-amount
- C. set maestro configuration orchestrator-site-id
- D. set maestro orchestrator-site-amount
Answer: B
Explanation:
Explanation
This command is used to set the number of sites in a Maestro environment, which can be either one or two.
The number of sites determines the site-sync configuration and the failover policies for the Security Groups and the Security Group Members. The default value is one, and it can be changed only before the first Security Group is created.
References =
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 22
There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?
- A. 100%/0%
- B. 50%/50%
- C. 66%/33%
- D. 33%/66%
Answer: D
NEW QUESTION # 23
What is the max amount of Orchestrators in Dual-site setup?
- A. 0
- B. 2 per Security Group
- C. 4 per Security Group
- D. 1
Answer: C
Explanation:
A Dual Site setup can have either two or four orchestrators, depending on the scenario. However, the maximum number of orchestrators per Security Group is four, regardless of the number of sites. This is because each Security Group can have up to two orchestrators on each site, and each site can have up to two orchestrators. Therefore, the maximum number of orchestrators in a Dual Site setup is four per Security Group.
References =
*Maestro Frequently Asked Questions (FAQ)
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
NEW QUESTION # 24
What cannot be learned from the output of asg monitor command?
- A. Port status
- B. Security Policy status
- C. Uptime
- D. Appliances cluster status
Answer: B
Explanation:
Explanation
The asg monitor command is a tool to display the status and statistics of the Maestro Security Group Members and the Orchestrators. It shows information such as uptime, port status, CPU usage, memory usage, traffic distribution, and appliances cluster status. However, it does not show the security policy status, such as the policy name, installation time, or revision. To view the security policy status, other commands such as asg policy or fw stat can be used.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.1: asg monitor, page 4-3
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: asg monitor, page 4-3
*asg monitor - Check Point Software
NEW QUESTION # 25
When a VPN tunnel is formed with a Maestro SGM,
- A. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.
- B. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.
- C. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.
- D. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner.
Answer: D
NEW QUESTION # 26
The _______ command will allow users to update the specified file on all SGMs.
- A. g_cat
- B. g_update_conf_file
- C. g_all"
- D. sed
Answer: B
Explanation:
Explanation
The g_update_conf_file command is a global command that allows users to update the specified file on all Security Group Members of the current Security Group. The command takes the file name and the parameter-value pair as arguments and updates the file accordingly. For example, g_update_conf_file fwkern.conf fwha_enable_arp=1 will add or modify the fwha_enable_arp parameter in the fwkern.conf file on all SGMs.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-12
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-10
*Maestro Commands for Security Groups - Check Point CheckMates
NEW QUESTION # 27
What is the purpose of g_tcpdump command?
- A. The same as tcpdump, just on Scalable Platform
- B. Collects traffic dump from CIN network
- C. Collects traffic dump from all Active Appliances within Security Group
- D. Collects traffic dump from Sync network
Answer: C
Explanation:
_tcpdump" probably collects traffic dumps from all active appliances within a security group, aligning with the naming convention and function of similar commands in scalable platforms.
References
*Maestro Expert (CCME) Course - Check Point Software, page 331
*What is 'IN' and 'OUT' of g_tcpdump? - Check Point CheckMates2
*CHECK POINT MAESTRO EXPERT, page 23
NEW QUESTION # 28
What type of license is required for an MHO?
- A. The MHO does not require a license.
- B. The MHO requires a VSX license.
- C. The MHO requires a NGTP license.
- D. A license is needed for each attached SGM.
Answer: A
Explanation:
The MHO (Maestro Hyperscale Orchestrator) does not require a license by itself, but each SGM (Security Group Module) that is attached to the MHO needs a license. The license type depends on the features and blades that are enabled on the SGM. For example, if the SGM is running VSX, it needs a VSX license.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 71
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 29
Maestro allows running commands globally in Expert mode by using global prefixes, such as:
- A. asg all
- B. g_all
- C. all
- D. global
Answer: B
Explanation:
Explanation
The g_all prefix is used to run commands globally in Expert mode on all Security Group Members of the current Security Group. For example, g_all cpstop will stop the Check Point services on all SGMs. The other prefixes are not valid for global commands in Expert mode.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-11
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-9
*Global Expert Mode Commands - Check Point CheckMates
NEW QUESTION # 30
Which command is used to set the number of sites in a Maestro environment?
- A. set maestro configuration orchestrator-site-number
- B. set maestro configuration orchestrator-site-amount
- C. set maestro configuration orchestrator-site-id
- D. set maestro orchestrator-site-amount
Answer: B
Explanation:
This command is used to set the number of sites in a Maestro environment, which can be either one or two.
The number of sites determines the site-sync configuration and the failover policies for the Security Groups and the Security Group Members. The default value is one, and it can be changed only before the first Security Group is created.
References =
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 31
Which licenses should be issued for the Orchestrator?
- A. The Orchestrator is considered a Management server, hence it's licensed the same way
- B. Depends on Software Blades enabled on connected appliances
- C. The Orchestrator requires NGTX license
- D. No licenses are required for Orchestrator
Answer: D
Explanation:
Orchestrators in many network environments do not require separate licenses, as they primarily function to manage and distribute network traffic.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 1: Introduction to Check Point Maestro, Lesson 1.2: Maestro Licensing, page 1-8
*Check Point R81 Maestro Administration Guide, Chapter 1: Introduction to Check Point Maestro, Section:
Maestro Licensing, page 1-6
*Activation of a Quantum Maestro Orchestrator - Check Point Software
NEW QUESTION # 32
What is the Correction Layer mechanism?
- A. Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.
- B. The load-balancing mechanism used by the MHO.
- C. Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.
- D. The MHO's distribution algorithm which determines the handling SGM for a given connection.
Answer: C
Explanation:
The Correction Layer mechanism is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system.This is especially important when NAT or VPNs are involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.
References:
*NAT and the Correction Layer on a VSX Gateway - Check Point Software1
*Solved: Maestro queries - Check Point CheckMates
NEW QUESTION # 33
For the MHO-175, which ports are Management ports?
- A. Ports 1 - 4 are Management ports.
- B. Ports 5 - 26 are Management ports.
- C. Ports 27 - 47 are Management ports.
- D. Ports 49 - 55 are Management ports.
Answer: A
Explanation:
According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 -
47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751
NEW QUESTION # 34
What happens if you apply a hotfix using gClish?
- A. Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A."
- B. If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so.
- C. If you apply a hotfix using gclish, the operation will fail because an outage would occur.
- D. If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time.
Answer: B
Explanation:
According to the Installing and Uninstalling a Hotfix on Quantum Maestro Orchestrators, page 1, when you apply a hotfix using gclish, the MHO distributes the hotfix to all SGMs in the SecurityGroup. The SGMs install the hotfix and reboot one by one, in ascending order of their SGM IDs. The SGMs wait for the previous SGM to finish rebooting before starting their own reboot. This ensures that there is no outage for the entire Security Group.
References = Installing and Uninstalling a Hotfix on Quantum Maestro Orchestrators, page 1; Maestro R81.10 Jumbo Hotfix install - Check Point CheckMates, page 1.
NEW QUESTION # 35
After you import the R81.10 software package, what do you use to verify that it is possible to upgrade an MHO or SG?
- A. Run the Pre-Upgrade Verifier to make sure it is possible to upgrade
- B. Run HCP. One of the tests will list upgrade eligibility status for the MHO or SG.
- C. The package is verified during the import process and a warning or error will be displayed at that time.
- D. Nothing. CPUSE will run a verification during the upgrade process to ensure the package is compatible.
Answer: A
Explanation:
Explanation
The Pre-Upgrade Verifier is a tool that checks the compatibility and readiness of the Maestro environment for the upgrade process. It verifies the current version, the target version, the hardware requirements, the configuration settings, and the license validity of the Maestro Orchestrators and the Security Groups. It also identifies any potential issues or risks that might affect the upgrade and provides recommendations on how to resolve them. The Pre-Upgrade Verifier should be run before importing the R81.10 software package and before performing the actual upgrade.
References =
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 36
When working with Maestro, what is the difference between using Clish and gClish?
- A. Clish commands apply only to a specific SG member. gClish commands apply to all UP SG members, by default.
- B. Clish commands are for testing purposes only and cannot be saved, gClish commands apply to all SG members, by default.
- C. Clish commands apply to all UP SG members, by default. gClish commands apply to all SG members, by default.
- D. Clish commands are run on the SG members. gClish commands are run on the MHO and applied to all connected SG members in a specified group.
Answer: D
NEW QUESTION # 37
What happens when you make changes from Clish on the SMO Master?
- A. Changes are applied to all members in the SG.
- B. The changes are synchronized to the MHO as a backup.
- C. Changes are only applied on the SMO Master.
- D. The changes are synchronized to the SMS/MDS as a backup.
Answer: C
Explanation:
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.2: Security Group Configuration, page 2-10
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Configuration, page 2-9
*Security Group Configuration - Check Point Software
NEW QUESTION # 38
There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?
- A. 0
- B. Between 2 and 4
- C. All 10
- D. 1
Answer: B
Explanation:
Explanation
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23
*Check Point Maestro Frequently Asked Questions (FAQ), question 9
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
NEW QUESTION # 39
What is the throughput penalty of Security Group?
- A. 5% per member
- B. Depends on the type of Appliance
- C. 10% per Security Group with no relation to the number of members
- D. 1% per member
Answer: D
Explanation:
Check Point reduced throughput degradation to 1% per added SGMs. For example, the overall throughput degradation is 10% for 10 SGMs in a Security Group. Check Point aims to reduce this even further in the future. https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk147853
NEW QUESTION # 40
While looking at your system's correction statistics, you notice you have a correction rate approaching 100 percent. Is this a problem?
- A. A correction rate above 90 percent indicates a need to disable Layer 4 Distribution.
- B. If correction rates are higher than 80 percent, latency is expected.
- C. A correction rate approaching 100 percent of all connections is unusual. This is a cause for concern because the SGMs may fail to process traffic.
- D. In some scenarios, a correction rate approaching 100 percent of all connections is not unusual. This is not usually a cause for concern as the correction mechanism is fast and efficient.
Answer: C
Explanation:
Explanation
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23 3
*Check Point Maestro Frequently Asked Questions (FAQ), question 9 4
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
3:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
4:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
NEW QUESTION # 41
What is one benefit of a Dual MHO environment?
- A. Dual MHOs allow better synchronization to occur between SGMs.
- B. Dual MHOs can be used to achieve increased scalability and redundancy..
- C. Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.
- D. Dual MHOs allow additional SGMs to be added to the SG.
Answer: B
Explanation:
One of the benefits of a Dual MHO environment is that it can provide both scalability and redundancy to the Maestro system. Scalability means that the system can handle more traffic and SGMs as the demand grows, and redundancy means that the system can survive the failure of one or more components without losing functionality or performance. Dual MHOs can achieve these benefits by distributing the load and the management tasks among two orchestrators, and by providing backup and failover mechanisms for each other.
References
*Maestro Expert (CCME) Course - Check Point Software, page 251
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 22
*Check Point Certified Maestro Expert (CCME) R81.X, page 23
NEW QUESTION # 42
What Maestro component acts as a load balancer and network switch?
- A. Maestro Hyperscale Orchestrator (MHO)
- B. Security Group (SG)
- C. Security Switching Module (SSM)
- D. Security Gateway Module (SGM)
Answer: A
Explanation:
*The Quantum Maestro Orchestrator uses the Distribution Mode to assign incoming traffic to Security Group Members.
*Reference: Working with the Distribution Mode
NEW QUESTION # 43
......
Updated Free CheckPoint 156-836 Test Engine Questions with 90 Q&As: https://dumpstorrent.actualpdf.com/156-836-real-questions.html
