
Updated Oct-2025 Exam Engine or PDF for the 156-836 Tests Free Updated Today!
Ultimate Guide to Prepare 156-836 with Accurate PDF Questions
NEW QUESTION # 21
What Maestro component is automatically designated the SMO Master?
- A. The first MHO configured is considered the SMO Master.
- B. The MDS that pushes policy to the SMO is considered the SMO Master.
- C. The SGM with the lowest member ID (the first one added to the security group.)
- D. The SGM with the highest member ID (the last one added to the security group.)
Answer: C
Explanation:
Explanation
The SMO Master is the SGM that is responsible for synchronizing the configuration and policy with the other SGMs in the security group. The SMO Master is automatically designated as the SGM with the lowest member ID, which is usually the first one added to the security group. The SMO Master can be changed manually if needed.
References:
*Maestro Frequently Asked Questions (FAQ), under "What is a Single Management Object (SMO)?"
*Check Point Jump Start Course: Maestro, under "Maestro Security Groups"
NEW QUESTION # 22
While looking at your system's correction statistics, you notice you have a correction rate approaching 100 percent. Is this a problem?
- A. In some scenarios, a correction rate approaching 100 percent of all connections is not unusual. This is not usually a cause for concern as the correction mechanism is fast and efficient.
- B. If correction rates are higher than 80 percent, latency is expected.
- C. A correction rate approaching 100 percent of all connections is unusual. This is a cause for concern because the SGMs may fail to process traffic.
- D. A correction rate above 90 percent indicates a need to disable Layer 4 Distribution.
Answer: C
Explanation:
Explanation
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23 3
*Check Point Maestro Frequently Asked Questions (FAQ), question 9 4
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
3:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
4:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
NEW QUESTION # 23
Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?
- A. When dynamic routing protocols, such as BGP or OSPF are used.
- B. When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.
- C. When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.
- D. When the SG is NATing a very high percentage of traffic passing through it.
Answer: A
Explanation:
This is the correct answer because Layer 4 distribution is not recommended when dynamic routing protocols are used in Maestro. Layer 4 distribution is a feature that adds the source and/or destination ports to the distribution equation, which can improve the load balancing among the SGMs. However, it can also cause issues with the correction layer, which is a mechanism that ensures the packets are processed by the correct SGM. Dynamic routing protocols, such as BGP or OSPF, use specific ports to exchange routing information and establish neighbor relationships. If Layer 4 distribution is enabled, it can interfere with the routing protocol packets and cause routing instability or failures.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-20
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-8
*Layer 4 Distribution - Yes or No? - Check Point CheckMates
*Support, Support Requests, Training ... - Check Point Software
NEW QUESTION # 24
In a dual MHO environment, MHO1 and MHO2 are connected to the SGM line cards in which way?
- A. MHO 1 is connected to the odd-numbered ports, while MHO2 is connected to even-numbered ports.
- B. MHO1 and MHO2 are connected to the line cards in any order administrators see fit.
- C. MHO1 and MHO2 are connected to the SGMs using the Sync cable.
- D. MHO 1 is connected to the even-numbered ports, while MHO2 is connected to odd-numbered ports.
Answer: D
Explanation:
Explanation
The correct way to connect MHO1 and MHO2 to the SGM line cards in a dual MHO environment is to use the even-numbered ports for MHO1 and the odd-numbered ports for MHO2. This is to ensure that each SGM has two downlinks to each MHO, and that the downlinks are balanced across the different NICs and links. This provides redundancy and high availability for the traffic flow between the SGMs and the MHOs.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 18
*Maestro Technical Training, Module 2: Maestro Security Groups and the Single Management Object, slide 16
NEW QUESTION # 25
What happens when you make changes from Clish on the SMO Master?
- A. The changes are synchronized to the MHO as a backup.
- B. Changes are only applied on the SMO Master.
- C. The changes are synchronized to the SMS/MDS as a backup.
- D. Changes are applied to all members in the SG.
Answer: B
Explanation:
Explanation
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.2: Security Group Configuration, page 2-10
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Configuration, page 2-9
*Security Group Configuration - Check Point Software
NEW QUESTION # 26
What Maestro component is automatically designated the SMO Master?
- A. The first MHO configured is considered the SMO Master.
- B. The MDS that pushes policy to the SMO is considered the SMO Master.
- C. The SGM with the lowest member ID (the first one added to the security group.)
- D. The SGM with the highest member ID (the last one added to the security group.)
Answer: C
Explanation:
The SMO Master is the SGM that is responsible for synchronizing the configuration and policy with the other SGMs in the security group. The SMO Master is automatically designated as the SGM with the lowest member ID, which is usually the first one added to the security group. The SMO Master can be changed manually if needed.
References:
*Maestro Frequently Asked Questions (FAQ), under "What is a Single Management Object (SMO)?"
*Check Point Jump Start Course: Maestro, under "Maestro Security Groups"
NEW QUESTION # 27
What command will be used for updating fwkern.conf file on all Appliances within Security Group?
- A. g_all update_conf_file
- B. vi
- C. g_update_kernel
- D. g_update_conf_file
Answer: D
NEW QUESTION # 28
What does the lldpctl command do?
- A. Discover orchestrators
- B. Show all devices discovered by LLDP protocol on all ports
- C. Show all devices discovered by LLDP protocol on uplink ports
- D. Show all devices discovered by LLDP protocol on downlink ports
Answer: B
Explanation:
Explanation
The lldpctl command is a tool to display information about the devices discovered by the Link Layer Discovery Protocol (LLDP) on all ports of the Maestro Orchestrator and the Security Group Members. LLDP is a protocol that enables devices to exchange information about their identity, capabilities, and configuration.
LLDP can help to discover the topology and connectivity of the Maestro environment.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.2: LLDP, page 4-9
*Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section:
LLDP, page 3-9
NEW QUESTION # 29
What can be learned from the output of sx_api_ports_dump.py command?
- A. Information about downlink ports only
- B. Information about backplane bonds
- C. Information about Security Groups
- D. Orchestrator port status
Answer: B
Explanation:
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3
NEW QUESTION # 30
When a VPN tunnel is formed with a Maestro SGM,
- A. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.
- B. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.
- C. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.
- D. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner.
Answer: D
NEW QUESTION # 31
What kinds of transceivers are supported on Orchestrator MHO-170?
- A. SFP, SFP+, SFP28
- B. SFP, QSFP, QSFP28
- C. QSFP, QSFP28
- D. SFP+, SFP28, QSFP
Answer: C
Explanation:
The Orchestrator MHO-170 supports QSFP and QSFP28 transceivers on its 32x 100 GbE ports. QSFP stands for Quad Small Form-factor Pluggable and QSFP28 is an enhanced version of QSFP that supports up to 28 Gbps per lane. These transceivers can provide high-speed and high-density connectivity for the Maestro environment.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Maestro Transceiver & DAC Inventory - Check Point CheckMates
NEW QUESTION # 32
Logs without a dedicated log file can be found in
- A. /var/log/junk.log.dbg
- B. $FWDIR/log/fw.log
- C. /var/log/messages
- D. $RTDIR/log/junk.log
Answer: C
Explanation:
Explanation
The /var/log/messages file is a general system log file that contains information about various system events, such as booting, shutdown, cron jobs, kernel messages, and other system services. Logs without a dedicated log file can be found in this file, as well as some Maestro Gaia Clishcommands that are not saved in the
/var/log/command_logger.log file.
References
*Maestro Audit Logs - Where are they? - Check Point CheckMates1
*sk172923: The /var/log/messages file does not save Maestro Gaia Clish commands2
*Maestro Expert (CCME) Course - Check Point Software, page 33
NEW QUESTION # 33
Where should sx_api_ports_dump.py command be ran?
- A. Orchestrator
- B. Security Group
- C. SMO Appliance
- D. Management server
Answer: A
Explanation:
The sx_api_ports_dump.py command should be run on the Orchestrator, which is the device that manages the communication and the configuration of the Security Groups and the SGMs. The command shows the port mapping and the traffic distribution for each Security Group, as well as the backplane bonds and the Orchestrator ports. The command does not work on the Management server, the Security Group, or the SMO Appliance, as they do not have the same role and functionality as the Orchestrator.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 31
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 3
NEW QUESTION # 34
What happens when you make changes from Clish on the SMO Master?
- A. The changes are synchronized to the MHO as a backup.
- B. Changes are only applied on the SMO Master.
- C. The changes are synchronized to the SMS/MDS as a backup.
- D. Changes are applied to all members in the SG.
Answer: B
Explanation:
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.2: Security Group Configuration, page 2-10
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Configuration, page 2-9
*Security Group Configuration - Check Point Software
NEW QUESTION # 35
What is an uplink interface used for?
- A. To connect Orchestrators to customer's infrastructure
- B. To connect in between Orchestrators
- C. To connect appliances to customer's infrastructure
- D. To connect in between appliances
Answer: A
Explanation:
An uplink interface in a Check Point Maestro environment is specifically used to connect Maestro Hyperscale Orchestrators (MHOs) to the customer's network infrastructure, such as switches, routers, or firewalls. These interfaces facilitate the transmission and reception of management and control traffic between the MHOs and the customer's network. They are critical for integrating the Maestro system with the external network environment.
Exact Extract:
"Uplink interfaces are used to connect Maestro Hyperscale Orchestrators (MHOs) to the customer's network infrastructure, such as switches, routers, or firewalls. They are also used to send and receive management and control traffic from the customer's network to the MHOs."
-Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 1: Introduction to Check Point Maestro, Lesson 1.3: Maestro Interfaces, page 1-10
-Check Point R81 Maestro Administration Guide, Chapter 1: Introduction to Check Point Maestro, Section:
Interfaces, page 1-8
Explanation of Options:
* A. To connect in between appliances: Incorrect, as uplink interfaces are not used to connect appliances (Security Group Members) to each other. This is typically handled by downlink interfaces or internal backplane connections.
* B. To connect appliances to customer's infrastructure: Incorrect, as appliances (SGMs) connect to the Orchestrators via downlink interfaces, not directly to the customer's infrastructure.
* C. To connect Orchestrators to customer's infrastructure: Correct, as uplink interfaces are explicitly designed for this purpose, as stated in the courseware and administration guide.
* D. To connect in between Orchestrators: Incorrect, as connections between Orchestrators (e.g., in a Dual-Site setup) are typically handled via site-sync ports, not uplink interfaces.
References:
Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 1: Introduction to Check Point Maestro, Lesson 1.3: Maestro Interfaces, page 1-10 Check Point R81 Maestro Administration Guide, Chapter 1: Introduction to Check Point Maestro, Section:
Interfaces, page 1-8
NEW QUESTION # 36
Each morning at 1:00 am, a series of automatic diagnostics on all the SGMs runs by automatic execution of which command?
- A. asg perf -v
- B. asg diag verify
- C. asg diag list
- D. hcp -r all
Answer: B
NEW QUESTION # 37
......
The CheckPoint 156-836 exam tests the candidate's knowledge on the latest technologies, platforms, and security methods used by Check Point Maestro. It covers a wide range of topics including configuration and management of Check Point Maestro, troubleshooting methods, and optimization techniques. To make sure that the candidates are fully equipped with the necessary knowledge, the exam requires a combination of multiple-choice and scenario-based questions.
Pass CheckPoint With DumpsTests Exam Dumps: https://pass4sure.dumpstests.com/156-836-latest-test-dumps.html