Vendor: Checkpoint
Exam Code: 156-586
Exam Name: Check Point Certified Troubleshooting Expert - R81
Date: Dec 18, 2023
Demo Questions

Question 1
Where do you enable log indexing on the SMS?
  1. SMS object under 'Other'
  2. SMS object under 'Advanced'
  3. SMS object under 'Logs'
  4. SMS object under 'General Properties'
Correct answer: C
Question 2
What is the correct syntax to turn a VPN debug on and create new empty debug files?
  1. vpn debuq trunkon
  2. vpn debug truncon
  3. vpndebug trunc on
  4. vpn kdebug on
Correct answer: B
Question 3
Which of the following file is commonly associated with troubleshooting crashes on a system such as the Security Gateway?
  1. fw monitor
  2. CPMIL dump
  3. core dump
  4. tcpdump
Correct answer: C
Question 4
What is the best way to resolve an issue caused by a frozen process?
  1. Kill the process
  2. Restart the process
  3. Reboot the machine
  4. Power off the machine
Correct answer: C
Question 5
What is the Security Gateway directory where an administrator can find vpn debug log files generated during Site-to-Site VPN troubleshooting?
  1. /opt/CPsuiteR80/vpn/log/
  2. $FWDIR/conf/
  3. $FWDIR/log/
  4. $CPDIR/conf/
Correct answer: C
Question 6
In Mobile Access VPN, clientless access is done using a web browser. The primary communication path for these browser based connections is a process that allows numerous processes to utilize port 443 and redirects traffic to a designated port of the respective process. Which daemon handles this?
  1. Mobile Access Daemon (MAD)
  2. Connectra VPN Daemon (cvpnd)
  3. HTTPS Inspection Daemon (HID)
  4. Multi-portal Daemon
Correct answer: D
Question 7
SmartEvent utilizes the Log Server, Correlation Unit and SmartEvent Server to aggregate logs and identify security events. The three main processes that govern these SmartEvent components are:
  1. cpcu, cplog, cpse
  2. eventiasv, eventiarp,eventiacu
  3. cpsemd, cpsead, and DBSync
  4. fwd, secu, sesrv
Correct answer: C
Question 8
Which of these packet processing components stores Rule Base matching state-related information?
  1. Observers
  2. Classifiers
  3. Manager
  4. Handlers
Correct answer: D
Question 9
That is the proper command for allowing the system to create core files?
  1. $FWDIR/scripts/
  2. # set core-dump enable # save config
  3. > set core-dump enable > save config
  4. service core-dump start
Correct answer: C
Question 10
What is correct about the Resource Advisor (RAD) service on the Security Gateways?
  1. RAD functions completely in user space. The Pattern Matter (PM) module of the CMI looks up for URLs in the cache and if not found, contact the RAD process in user space to do online categorization
  2. RAD is completely loaded as a kernel module that looks up URL in cache and if not found connects online for categorization. There is no user space involvement in this process
  3. RAD is not a separate module, it is an integrated function of the W kernel module and does all operations in the kernel space
  4. RAD has a kernel module that looks up the kernel cache, notifies client about hits and misses and forwards a-sync requests to RAD user space module which is responsible for online categorization
Correct answer: D

