156-587 Exam Questions
120 real 156-587 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1
What Check Point process controls logging?
- Question #2
Which of the following daemons is used for Threat Extraction?
- Question #3
If the cpsemd process of SmartEvent has crashed or is having trouble coming up, then it usually indicates that __________.
- Question #4
Your users are having trouble opening a Web page and you need to troubleshoot it. You open the Smart Console, and you get the following message when you navigate to the Logs and Mo...
- Question #5
You do not see logs in the SMS. When you login on the SMS shell and run cpwd_admin list you notice that the RFL process is with status T. What command can you run to try to resolve...
- Question #6
Where do you enable log indexing on the SMS?
- Question #7
What is the correct syntax to turn a VPN debug on and create new empty debug files?
- Question #8
Which of the following file is commonly associated with troubleshooting crashes on a system such as the Security Gateway?
- Question #9
When a User process or program suddenly crashes, a core dump is often used to examine the problem. Which command is used to enable the core-dumping via GAIA clish?
- Question #10
The management configuration stored in the Postgres database is partitioned into several relational database domains. What is the purpose of the Global Domain?
- Question #11
What is the most efficient way to read an IKEv2 Debug?
- Question #12
Which of the following is a component of the Context Management Infrastructure used to collect signatures in user space from multiple sources, such as Application Control and IPS,...
- Question #13
VPN issues may result from misconfiguration, communication failure, or incompatible default configurations between peers. Which basic command syntax needs to be used for troublesho...
- Question #14
User defined URLS and HTTPS Inspection User defined URLs on the Security Gateway are stored in which database file?
- Question #15
What process monitors, terminates, and restarts critical Check Point processes as necessary?
- Question #16
Which process is responsible for the generation of certificates?
- Question #17
You are using the Identity Collector with Identity Awareness in large environment. Users report that they cannot access resources on Internet. You identify that the traffic is matc...
- Question #18
What are the four main database domains?
- Question #19
Captive Portal, PDP and PEP run in what space?
- Question #20
Which Daemon should be debugged for HTTPS Inspection related issues?
- Question #21
The two procedures available for debugging in the firewall kernel are
- Question #22
In Check Point's Packet Processing Infrastructure, what is the role of Observers?
- Question #23
You need to run a kernel debug over a longer period of time as the problem occurs only once or twice a week. Therefore, you need to add a timestamp to the kernel debug and write th...
- Question #24
How can you start debug of the Unified Policy with all possible flags turned on?
- Question #25
What is the kernel process for Content Awareness that collects the data from the contexts received from the CMI and decides if the file is matched by a data type?
- Question #26
For Identity Awareness, what is the PDP process?
- Question #27
What is the simplest and most efficient way to check all dropped packets in real time?
- Question #28
After kernel debug with "fw ctl debug" you received a huge amount of information. It was saved in a very large file that is difficult to open and analyze with standard text editors...
- Question #29
You are seeing output from the previous kernel debug. What command should you use to avoid that?
- Question #30
Which of the following would NOT be a flag when debugging a unified policy?
- Question #31
Which of the following inputs is suitable for debugging HTTPS inspection issues?
- Question #32
The Check Point Firewall Kernel is the core component of the Gaia operating system and an integral part of the traffic inspection process. There are two procedures available for de...
- Question #33
URL Filtering is an essential part of Web Security in the Gateway. For the Security Gateway to perform a URL lookup when a client makes a URL request, where is the sync-request for...
- Question #34
What function receives the AD log event information?
- Question #35
Your users have some issues connecting with Mobile Access VPN to your gateway. How can you debug the tunnel establishment?
- Question #36
Which type of NAT allows both incoming and outgoing connections?
- Question #37
You have just acquired new licenses for your Check Point security Gateway. You need to attach the new license. What is the object in the Security Console where you can attach the l...
- Question #38
As a security administrator/engineer in your company, you have noticed that your HQ Check Point Security Management Server is not receiving logs from your HQ Check Point Gateway/Cl...
- Question #39
Check Point Threat Prevention policies can contain multiple policy layers and each layer consists of its own Rule Base. Which Threat Prevention daemon is used for Anti-virus?
- Question #40
Which command shows the installed licenses and contracts on a Check Point device?
- Question #41
Which of these packet processing components stores Rule Base matching state-related information?
- Question #42
That is the proper command for allowing the system to create core files?
- Question #43
What is correct about the Resource Advisor (RAD) service on the Security Gateways?
- Question #44
Which of the following is contained in the System Domain of the Postgres database?
- Question #45
Where will the usermode core files located?
- Question #46
When dealing with monolithic operating systems such as Gaia, where are system calls initiated from to achieve a required system level function?
- Question #47
What cli command is run on the GW to verify communication to the Identity Collector?
- Question #48
You receive reports that Users cannot browse internet sites. You are using identity awareness with AD Query and Identity Collector in addition you have the Browser Based Authentica...
- Question #49
Which of the following commands can be used to see the list of processes monitored by the Watch Dog process?
- Question #50
The FileApp parser in the Content Awareness engine does not extract text from which of the following file types?