156-561 · Question #131
Which of the below are not possible in relation to the Check Point licensing model?
The correct answer is C. You use as many CloudGuard licenses as you have virtual cores in the VM (BYOL-Bring your. Option C is the not possible scenario because Check Point's BYOL licensing model does not operate on a per-virtual-core basis - you purchase and apply a single license to a CloudGuard gateway instance, regardless of how many vCPUs it has. Licensing is tied to the…
Question
Which of the below are not possible in relation to the Check Point licensing model?
Options
- AYou can re-use your existing open server license (BYOL-Bring your own license)
- BYou use the built-in license from the AWS market (PAYG-Pay As You Go)
- CYou use as many CloudGuard licenses as you have virtual cores in the VM (BYOL-Bring your
- DYou use a license for CloudGuard AWS you buy at CP (BYOL-Bring your own license)
How the community answered
(36 responses)- A3% (1)
- B3% (1)
- C86% (31)
- D8% (3)
Explanation
Option C is the not possible scenario because Check Point's BYOL licensing model does not operate on a per-virtual-core basis - you purchase and apply a single license to a CloudGuard gateway instance, regardless of how many vCPUs it has. Licensing is tied to the appliance/gateway itself, not scaled 1:1 with virtual cores.
Options A, B, and D are all valid and supported scenarios: A correctly describes BYOL by migrating an existing on-premises open server license to the cloud; B correctly describes the PAYG model available through the AWS Marketplace, where you pay hourly based on usage; and D is simply another valid BYOL path - purchasing a new CloudGuard AWS license directly from Check Point.
Memory tip: Think of BYOL as "one license for the box" - you bring your license (singular) to the cloud. The moment you see "one license per core," that's a red flag, because Check Point doesn't sell CloudGuard licenses that way.
Topics
Community Discussion
5The answer is C, and once you understand why, this one gets much easier to remember. CloudGuard licensing does not scale one-to-one with virtual cores in your VM, so the idea that you would need as many licenses as you have vCores is simply not how the model works. Options A, B, and D all describe real and supported scenarios, because Check Point genuinely does support BYOL from an existing open server license, BYOL purchased directly from Check Point, and PAYG through the AWS Marketplace. C is the odd one out because it describes a licensing ratio that does not exist in the Check Point model, making it the thing that is not possible.
Grace nailed the core point, but worth adding that the vCore-ratio misconception probably trips people up because some other vendors do use core-based licensing, so a card drilling the Check Point model specifically, not just "C is wrong," tends to stick better at review time.
C is correct, and it trips people up because it sounds reasonable on the surface. Check Point CloudGuard BYOL licensing is tied to the number of virtual cores the license was purchased for, not a one-to-one unlimited mapping where you grab a license per core however you want. The license has to match the specific vCPU count of the gateway you are deploying, so you cannot just stack or reuse licenses arbitrarily across different core counts. A, B, and D are all legitimate supported models, so the exam is testing whether you know BYOL has fixed entitlements, not a free-form per-core grab.
Saw this exact trap on my exam, C is wrong because BYOL ties to gateways not vCores.
I flagged C the first read because licensing tied to virtual core count is not how CloudGuard BYOL works, and I had drilled that card at a 21-day interval going into test day so it came up clean. BYOL ties to the gateway itself, not the core count, and that single fact was worth a dedicated card in my deck.