nerdexam
Check_Point

156-215.80 · Question #333

If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security…

The correct answer is A. Rename the hostname of the Standby member to match exactly the hostname of the Active. When the Active Security Management Server is still operational, renaming the standby hostname is not part of the graceful failover procedure and should not be performed.

Deployment and Configuration

Question

If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed:

Options

  • ARename the hostname of the Standby member to match exactly the hostname of the Active
  • BChange the Standby Security Management Server to Active.
  • CChange the Active Security Management Server to Standby.
  • DManually synchronize the Active and Standby Security Management Servers.

How the community answered

(43 responses)
  • A
    56% (24)
  • B
    5% (2)
  • C
    14% (6)
  • D
    26% (11)

Why each option

When the Active Security Management Server is still operational, renaming the standby hostname is not part of the graceful failover procedure and should not be performed.

ARename the hostname of the Standby member to match exactly the hostname of the ActiveCorrect

Renaming the standby member's hostname to match the active is only relevant in a disaster recovery scenario where the active server is completely unrecoverable and cannot be demoted cleanly. When the active server is still responsible and functional, the correct procedure is to manually sync, demote the active to standby, then promote the standby - no hostname changes are needed. Performing a hostname rename unnecessarily risks identity conflicts and is explicitly excluded from the planned failover steps.

BChange the Standby Security Management Server to Active.

Promoting the standby to active is a required failover step to restore management continuity after the active is demoted.

CChange the Active Security Management Server to Standby.

Demoting the active server to standby is a required step to ensure a clean, controlled role transition without split-brain conditions.

DManually synchronize the Active and Standby Security Management Servers.

Manual synchronization is required before switching roles to ensure both servers share identical policy and object databases, preventing data loss.

Concept tested: Check Point SMS High Availability planned failover steps

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/HA-New-Active-Member.htm

Topics

#Management Server HA#active-standby failover#synchronization#data loss prevention

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice