試験科目:「Check Point Certified Security Master」
問題と解答:全295問

>> 156-115.77受験対策


156-115.77受験対策はCheckPointのひとつの認証試験でIT業界でとても歓迎があって、ますます多くの人が156-115.77受験対策「Check Point Certified Security Master」認証試験に申し込んですがその認証試験が簡単に合格できません。準備することが時間と労力がかかります。でも、Pass4Testは君の多くの貴重な時間とエネルギーを節約することを助けることができます。


NO.1 Which command should you use to stop kernel module debugging (excluding SecureXL)?
A. fw debug fwd off
B. fw ctl zdebug - all
C. fw debug fwd off; vpn debug off
D. fw ctl debug 0
Answer: D

156-115.77受験料過去問   

NO.2 How do you set up Port Address Translation?
A. Port Address Translation is not support in Check Point environment
B. Edit the service in SmartDashboard, click on the NAT tab and specify the translated port.
C. Create a manual NAT rule and specify the source and destination ports.
D. Since Hide NAT changes to random high ports it is by definition PAT (Port Address Translation).
Answer: C


NO.3 ACME Corp has a cluster consisting of two 13500 appliances. As the Firewall Administrator,
you notice that on an output of top, you are seeing high CPU usage of the cores assigned as SNDs, but
low CPU usage on cores assigned to individual fw_worker_X processes. What command should you
run next to performance tune your cluster?
A. fwaccel off - this will turn off SecureXL, which is causing your SNDs to be running high in the first
B. fwaccel stats -s - this will show you the acceleration profile of your connections and potentially why
your SNDs are running high while other cores are running low.
C. fw ctl debug -m cluster + all - this will show you all the connections being processed by ClusterXL
and explain the high CPU usage on your appliance.
D. fw tab -t connections -s - this will show you a summary of your connections table, and allow you to
determine whether there is too much traffic traversing your firewall.
Answer: B

156-115.77最新な問題集   
Topic 8, Enable CoreXL

NO.4 You are trying to troubleshoot a NAT issue on your network, and you use a kernel debug to
verify a connection is correctly translated to its NAT address. What flags should you use for the kernel
A. fw ctl debug -m fw + conn drop ld
B. fw ctl debug -m nat + conn drop fw xlate xltrc
C. fw ctl debug -m nat + conn drop nat xlate xltrc
D. fw ctl debug -m fw + conn drop nat vm xlate xltrc
Answer: D

NO.5 When VPN user-based authentication fails, which of the following debug logs is essential to
understanding the issue?
A. Vpnd.elg
B. fw monitor trace
C. IKE.elg
D. VPN-1 kernel debug logs
Answer: C


NO.6 Where do you configure the file user.def to change the encryption domain of the Security
A. Endpoint Client
B. Security Gateway
C. Management Server
D. interoperable device
Answer: C

NO.7 Which of the following statements about Full HA support with IPv6 is NOT true?
A. Mirrored Interfaces must have IPv4 addresses.
B. Sync traffic must be IPv4.
C. IPv6 does not support a Secondary Management Server.
D. There is no Dynamic Routing with IPv6.
Answer: C

Topic 11, Advanced VPN

NO.8 You run the command fw tab -t connections -s on both members in the cluster. Both members
report differing values for "vals" and "peaks". Which may NOT be a reason for this difference?
A. SGMs in a 61k environment only sync selective parts of the connections table.
B. Standby member does not synchronize until a failover is needed.
C. Heavily used short-lived services have had synchronization disabled for performance
D. Synchronization is not working between the two members
Answer: B

156-115.77日本語版   

