CheckPoint 156-835 practice test

Check Point Certified Maestro Expert

Last exam update: Feb 17 ,2026
Page 1 out of 5. Viewing questions 1-15 out of 64

Question 1

For a VSX configuration – Which statement is wrong?

  • A. All Virtual Systems exist on the SMO
  • B. All Virtual Systems exist on all Appliances
  • C. VSX configuration is the same on all Appliances within the same Security Group
  • D. Each Appliance owns different Virtual Systems
Mark Question:
Answer:

B


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be
connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two
Orchestrators?

  • A. Port 1 in Slot 1 and Port 2 in Slot 1
  • B. Port 1 in Slot 2 and Port 2 in Slot 1
  • C. Any pair of available ports
  • D. Port 1 in Slot 1 and Port 1 in Slot 2
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?

  • A. Two Out-of-band interfaces for access to Orchestrator itself
  • B. Out-of-band interface for access to Orchestrator itself and Serial Console connector
  • C. 1Gbps connectivity for Security Groups
  • D. Reserved for internal purposes. Not in use
Mark Question:
Answer:

B


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

Splitter cannot be used __________.

  • A. To connect single port on orchestrator to multiple Appliances
  • B. To connect single port on Appliance to multiple ports on the orchestrator
  • C. To connect single port on orchestrator to the same Appliance
  • D. To connect single port on orchestrator to multiple port on external switch
Mark Question:
Answer:

B


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

What will happen in case of NAT of the traffic passing through Management network?

  • A. This traffic will not pass correction, since it will be dropped
  • B. This traffic will pass with no inspection
  • C. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances
  • D. Orchestrator will disable NAT and traffic will pass with no issue
Mark Question:
Answer:

A


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

One single Appliance supports 1M concurrent connections. How many concurrent connections will
support Security Group of 2 Appliances?

  • A. 2M
  • B. 500K
  • C. 4M
  • D. 1M
Mark Question:
Answer:

A


Explanation:
One single Appliance supports 1M concurrent connections, so a Security Group of 2 Appliances will
support 2M concurrent connections.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails
=&solutionid=sk91380
How to troubleshoot Gaia Portal (WebUI)
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails
=&solutionid=sk91380
https://downloads.checkpoint.com/dc/download.htm?ID=103853
VSX R81 Administration Guide
https://downloads.checkpoint.com/dc/download.htm?ID=103853
https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10-List-of-all-Resolved-
Issues.htm
List of All Resolved Issues and New Features
https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10-List-of-all-Resolved-
Issues.htm

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

What does asg monitor command do?

  • A. Monitor health status of entire system
  • B. This command does not exist
  • C. Monitor traffic on Appliances in Security Group
  • D. Show real-time cluster status of Appliances in Security Group
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

There are two appliances within the same Security Group. One of them is connected by One
downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be
proportion
of
traffic distribution done by Orchestrator?

  • A. 66%/33%
  • B. 100%/0%
  • C. 50%/50%
  • D. 33%/66%
Mark Question:
Answer:

C


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

Which licenses should be issued for the Orchestrator?

  • A. No licenses are required for Orchestrator
  • B. The Orchestrator is considered a Management server, hence it's licensed the same way
  • C. The Orchestrator requires NGTX license
  • D. Depends on Software Blades enabled on connected appliances
Mark Question:
Answer:

A


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

What cannot be learned from the output of lldpctl?

  • A. Distribution mode
  • B. Orchestrator’s IP
  • C. Serial number of Appliance
  • D. Appliance model
Mark Question:
Answer:

A


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

What is the default Distribution mode?

  • A. User
  • B. Auto-topology
  • C. Manual-General
  • D. Network
Mark Question:
Answer:

B


Explanation:
In Check Point firewall, the default Distribution mode is Auto-topology. Auto-topology uses the built-
in algorithm to automatically determine the best way to distribute the traffic across the firewall
cluster, based on the topology of the network and the current load on the cluster members.
Auto-topology takes into account the available bandwidth and the CPU utilization of each cluster
member, and then makes decisions on how to distribute the traffic across the cluster in real-time. It
is a dynamic and adaptive mode that ensures the best use of the available resources and the highest
level of performance.

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

What is the purpose of g_tcpdump command?

  • A. Collects traffic dump from Sync network
  • B. The same as tcpdump, just on Scalable Platform
  • C. Collects traffic dump from CIN network
  • D. Collects traffic dump from all Active Appliances within Security Group
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?

  • A. Reserved for internal purposes. Not in use.
  • B. Out-of-band interfaces for access to Orchestrator itself.
  • C. 1Gbps connectivity for Security Groups.
  • D. Additional ports used as uplinks.
Mark Question:
Answer:

B


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

What kind of cluster Dual-Site can be compared to?

  • A. Active-Standby or VSLS
  • B. VSLS only
  • C. Active-Active
  • D. Active-Standby only
Mark Question:
Answer:

A


Explanation:
A Dual-Site cluster is a type of cluster that combines the features of both Active-Standby and VSLS
(Virtual Systems Load Sharing) clusters. Dual-Site clusters allow you to have two active clusters, one
at each site, and the traffic is distributed between the two sites based on predefined rules and
priorities.
A Dual-Site cluster can be compared to an Active-Standby cluster because one of the clusters is
running in a passive mode and is only activated in case of a failure or a planned maintenance of the
active cluster. And also can be compared to a VSLS cluster because both clusters are active and share
the traffic load.
It's a type of High Availability solution that provides redundancy and failover capabilities across two
geographically separated sites. In case of a failure or a outage on one site, the traffic is automatically
redirected to the other site, ensuring that the service is not interrupted.

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

There's a 23800 appliance with quad NIC in slot 5. What would be the name of port 3 on this NIC?

  • A. ethBP3-05
  • B. ethsBP5-03
  • C. ethsBP3-05
  • D. ethsBP-05
Mark Question:
Answer:

B


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2