
Free 156-836 Braindumps Download Updated on May 20, 2026 with 90 Questions
CheckPoint 156-836 Exam Practice Test Questions
CheckPoint 156-836 is a certification exam for Check Point Certified Maestro Experts that focuses on R81 version. Check Point Certified Maestro Expert - R81 (CCME) certification validates an individual's knowledge and skills in managing and operating the Check Point Maestro. 156-836 exam is designed for professionals who want to demonstrate their expertise in managing complex network infrastructures, security policies, and security solutions using Check Point Maestro.
The CCME certification is for those who want to be recognized as experts in Check Point's Maestro orchestration solution. Check Point Certified Maestro Expert - R81 (CCME) certification is ideal for IT professionals who specialize in network security and want to advance their career to the next level. The CheckPoint 156-836 exam is a challenging certification exam that evaluates the candidate's knowledge and skills in deploying and managing Check Point Maestro solutions. Passing 156-836 exam will demonstrate the candidate's ability to design and manage complex Maestro deployments and make them a highly sought-after professional in the network security industry.
NEW QUESTION # 26
Complete the sentence: Dual Orchestrators work as.______
- A. Active-Active cluster
- B. Active - Standby cluster
- C. Hot-Swap RAID
- D. Load Sharing cluster
Answer: A
Explanation:
Explanation
Dual Orchestrators work as an Active-Active cluster, which means that both Orchestrators are active and share the load of the traffic that is sent to and from the Security Group Members (SGMs). Active-Active cluster provides better performance and scalability than Active-Standby cluster, which only uses one Orchestrator at a time and keeps the other as a backup. Active-Active cluster also allows for faster failover and recovery in case of an Orchestrator failure, as the surviving Orchestrator can take over the traffic without interruption.
References
*Maestro Expert (CCME) Course - Check Point Software, page 25
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 2
NEW QUESTION # 27
In a Maestro Dual Site environment, what is the definition of the term Active Site.
- A. There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.
- B. The Active Site is the site currently handling the enforcement on traffic passing for a specific SG.Connections are synced within the SGMs in the Active Site.
- C. The Active Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover.
- D. The Active Site is the site where the SMO Master exists.
Answer: B
Explanation:
In a Maestro Dual Site environment, there are two sites that can host Security Group Members (SGMs) for each Security Group (SG). The Active Site is the one that is currently processing the traffic for a specific SG, while the Standby Site is the one that is ready to take over in case of a failover. The Active Site and the Standby Site can be different for different SGs, depending on the load balancing and failover policies. The Active Site and the Standby Site are synchronized by the Maestro Orchestrators (MHOs) using the Site-Sync port and VLANs.
References =
*Solved: Maestro dual site failover - Check Point CheckMates
*Maestro Dual Site configuration with a direct connection through L2 switches
NEW QUESTION # 28
For the MHO-175, which ports are Management ports?
- A. Ports 27 - 47 are Management ports.
- B. Ports 49 - 55 are Management ports.
- C. Ports 5 - 26 are Management ports.
- D. Ports 1 - 4 are Management ports.
Answer: D
Explanation:
According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 -
47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751
NEW QUESTION # 29
What type of license is required for an MHO?
- A. The MHO does not require a license.
- B. The MHO requires a VSX license.
- C. The MHO requires a NGTP license.
- D. A license is needed for each attached SGM.
Answer: A
Explanation:
Explanation
The MHO (Maestro Hyperscale Orchestrator) does not require a license by itself, but each SGM (Security Group Module) that is attached to the MHO needs a license. The license type depends on the features and blades that are enabled on the SGM. For example, if the SGM is running VSX, it needs a VSX license.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 71
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 30
What is one benefit of a Dual MHO environment?
- A. Dual MHOs allow additional SGMs to be added to the SG.
- B. Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.
- C. Dual MHOs allow better synchronization to occur between SGMs.
- D. Dual MHOs can be used to achieve increased scalability and redundancy.
.
Answer: D
Explanation:
Explanation
One of the benefits of a Dual MHO environment is that it can provide both scalability and redundancy to the Maestro system. Scalability means that the system can handle more traffic and SGMs as the demand grows, and redundancy means that the system can survive the failure of one or more components without losing functionality or performance. Dual MHOs can achieve these benefits by distributing the load and the management tasks among two orchestrators, and by providing backup and failover mechanisms for each other.
References
*Maestro Expert (CCME) Course - Check Point Software, page 251
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 22
*Check Point Certified Maestro Expert (CCME) R81.X, page 23
NEW QUESTION # 31
While looking at your system's correction statistics, you notice you have a correction rate approaching 100 percent. Is this a problem?
- A. In some scenarios, a correction rate approaching 100 percent of all connections is not unusual. This is not usually a cause for concern as the correction mechanism is fast and efficient.
- B. A correction rate approaching 100 percent of all connections is unusual. This is a cause for concern because the SGMs may fail to process traffic.
- C. If correction rates are higher than 80 percent, latency is expected.
- D. A correction rate above 90 percent indicates a need to disable Layer 4 Distribution.
Answer: B
Explanation:
Explanation
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23 3
*Check Point Maestro Frequently Asked Questions (FAQ), question 9 4
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
3:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
4:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
NEW QUESTION # 32
What happens if you apply a hotfix using gClish?
- A. Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A."
- B. If you apply a hotfix using gclish, the operation will fail because an outage would occur.
- C. If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so.
- D. If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time.
Answer: A
Explanation:
Explanation
This is the correct answer because it describes the hotfix installation process using gClish on a Maestro Security Group. gClish is the global Clish that allows users to run commands on all UP SG members of the current Security Group at once. When a hotfix is applied using gClish, the SG members are divided into two logical groups: "A" and "B". The members of group "A" install the hotfix and reboot first, while the members of group "B" wait for their turn. After all the members of group "A" are back online, the members of group
"B" install the hotfix and reboot.This way, the SG maintains high availability and does not cause an outage.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-11
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-9
*Global Expert Mode Commands - Check Point CheckMates
NEW QUESTION # 33
Which command do you use to find bottlenecks in the system that are affecting performance, even functionality in some cases?
- A. asg stat -v
- B. asg diag verify
- C. asg perf -v
- D. asg monitor
Answer: C
Explanation:
Explanation
The asg perf -v command is used to find bottlenecks in the system that are affecting performance, even functionality in some cases. The asg perf -v command displays the performance statistics of the Security Group Modules (SGMs) in the Security Group, such as throughput, packet rate, CPU utilization, memory usage, and more. The asg perf -v command also shows the distribution mode and the correction rate of each SGM, which can indicate potential issues with asymmetric routing or load balancing. The asg perf -v command can help identify which SGMs are overloaded, underutilized, or misconfigured, and provide insights for troubleshooting and optimization.
References =
*Check Point Maestro R81.X Administration Guide, page 67, section "asg perf" 1
*Check Point Maestro R81.X Getting Started Guide, page 29, section "asg perf" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 26
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
NEW QUESTION # 34
What can be learned from the output of sx_api_ports_dump.py command?
- A. Information about Security Groups
- B. Information about backplane bonds
- C. Orchestrator port status
- D. Information about downlink ports only
Answer: B
Explanation:
Explanation
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3
NEW QUESTION # 35
Logs without a dedicated log file can be found in
- A. $RTDIR/log/junk.log
- B. $FWDIR/log/fw.log
- C. /var/log/junk.log.dbg
- D. /var/log/messages
Answer: D
Explanation:
The /var/log/messages file is a general system log file that contains information about various system events, such as booting, shutdown, cron jobs, kernel messages, and other system services. Logs without a dedicated log file can be found in this file, as well as some Maestro Gaia Clish commands that are not saved in the /var
/log/command_logger.log file.
References
*Maestro Audit Logs - Where are they? - Check Point CheckMates1
*sk172923: The /var/log/messages file does not save Maestro Gaia Clish commands2
*Maestro Expert (CCME) Course - Check Point Software, page 33
NEW QUESTION # 36
Do all MHOs need to be upgraded before starting the SGM upgrades?
- A. All MHOs must first be upgraded before starting the SGM upgrades However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHOs.
- B. During the upgrade process all SGMs should be upgraded before upgrading all of the MHOs.
- C. A minimum of one of the MHOs should be upgraded before starting the SGM upgrades. However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHO
- D. MHOs do not need to be upgraded at all because Maestro supports the use of different versions between the MHOs and SGMs.
Answer: A
Explanation:
Explanation
This is the correct answer because it follows the upgrade order and procedure specified in the R81.10 and R81.20 Administration Guides for Maestro environments. The MHOs are responsible for managing and synchronizing the SGMs, so they must be upgraded to the target version before the SGMs. However, the SGMs can be upgraded one by one or in batches, as long as they are compatible with the MHOs. The upgrade process also supports Multi-Version Clustering, which allows different versions of SGMs to operate in the same Security Group with zero downtime.
References =
*Check Point R81.10 for Scalable Platforms - Check Point Software
*Check Point R81.20 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 37
What is the maximum number of Appliances within Security group in Dual-Site configuration?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 38
What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?
- A. Reserved for internal purposes. Not in use
- B. Out-of-band interface for access to Orchestrator itself and Serial Console connector
- C. Two Out-of-band interfaces for access to Orchestrator itself
- D. 1Gbps connectivity for Security Groups
Answer: B
Explanation:
The RJ-45 connectors located at the front panel of the Orchestrator MHO-170 are used for out-of-band management and serial console access. One of them is a 1Gbps RJ-45 port that provides an out-of-band interface for accessing the Orchestrator itself for configuration and management purposes. The other one is a RJ-45 serial console port that provides a command-line interface for initial setup and troubleshooting.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates, page 4
NEW QUESTION # 39
Where should sx_api_ports_dump.py command be ran?
- A. Security Group
- B. Management server
- C. SMO Appliance
- D. Orchestrator
Answer: D
Explanation:
The sx_api_ports_dump.py command should be run on the Orchestrator, which is the device that manages the communication and the configuration of the Security Groups and the SGMs. The command shows the port mapping and the traffic distribution for each Security Group, as well as the backplane bonds and the Orchestrator ports. The command does not work on the Management server, the Security Group, or the SMO Appliance, as they do not have the same role and functionality as the Orchestrator.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 31
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 3
NEW QUESTION # 40
In what mode do MHOs process traffic?
- A. MHOs process traffic in VSLS mode
- B. MHOs process traffic in Active-Active mode
- C. MHOs process traffic in Active-Standby mode
- D. MHOs process traffic in load sharing mode
Answer: B
Explanation:
MHOs process traffic in Active-Active mode, which means that both MHOs are active and share theload of the traffic that is sent to and from the SGMs. Active-Active mode provides better performance and scalability than Active-Standby mode, which only uses one MHO at a time and keeps the other as a backup. Active- Active mode also allows for faster failover and recovery in case of an MHO failure, as the surviving MHO can take over the traffic without interruption.
References
*Maestro Expert (CCME) Course - Check Point Software, page 25
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 2
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 2
NEW QUESTION # 41
What is the maximum number of Appliances within the same Security Group?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Explanation
The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 51
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 42
What is the purpose of interface bonding?
- A. For load sharing which increases connection throughput above that which is possible using one physical interface.
- B. A bond interface can be configured for high availability redundancy or for load sharing which increases connection throughput above that which is possible using one physical interface.
- C. A bond interface can be configured for high availability redundancy.
- D. A bond interface is used for passing synchronization traffic between the SGMs.
Answer: B
NEW QUESTION # 43
What command can be run to show which SGM is selected to receive traffic?
- A. asg calc
- B. dxl calc
- C. asg monitor
- D. g_tcpdump
Answer: A
Explanation:
Explanation
The asg calc command is a tool to show which SGM is selected to receive traffic based on the distribution mode and the packet parameters. It takes the port number, the source IP, the destination IP, and optionally the source port and the destination port as arguments and returns the SGM ID and the hash value. For example, asg calc 1 10.0.0.1 20.0.0.2 1234 80 will show which SGM will receive the traffic from 10.0.0.1:1234 to
20.0.0.2:80 on port 1.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using theCommand Line Interface and WebUI, Lesson 4.1: asg calc, page 4-5
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: asg calc, page 4-5
*asg calc - Check Point Software
NEW QUESTION # 44
What command can be run to show which SGM is selected to receive traffic?
- A. asg calc
- B. dxl calc
- C. asg monitor
- D. g_tcpdump
Answer: A
Explanation:
The asg calc command is a tool to show which SGM is selected to receive traffic based on the distribution mode and the packet parameters. It takes the port number, the source IP, the destination IP, and optionally the source port and the destination port as arguments and returns the SGM ID and the hash value. For example, asg calc 1 10.0.0.1 20.0.0.2 1234 80 will show which SGM will receive the traffic from 10.0.0.1:1234 to
20.0.0.2:80 on port 1.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.1: asg calc, page 4-5
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: asg calc, page 4-5
*asg calc - Check Point Software
NEW QUESTION # 45
In case of Correction, where is information about Owner stored?
- A. In Connection table of Target Appliances
- B. In Correction tables of all Appliances participating in Correction Layer flow
- C. In Correction table of Target Appliance
- D. In Connection tables of all Appliances participating in Correction Layer flow
Answer: B
Explanation:
The Correction Layer is a mechanism that handles asymmetric connections in systems with several cluster members. It allows traffic flow to be handled by a single cluster member, even if the flow is asymmetric1 The Correction Layer works as follows:
*When a packet arrives at a cluster member, it checks if it is the owner of the connection. If yes, it processes the packet normally. If not, it checks the Correction table to find the owner of the connection.
*If the owner is found in the Correction table, the packet is forwarded to the owner with a Correction Layer header. The owner then processes the packet and removes the Correction Layer header before sending it to the destination.
*If the owner is not found in the Correction table, the packet is forwarded to the Maestro Orchestrator (MHO) with a Correction Layer header. The MHO then checks its own Correction table to find the owner of the connection. If the owner is found, the MHO forwards the packet to the owner with a Correction Layer header.
If the owner is not found, the MHO drops the packet and sends an ICMP error message to the source.
*The Correction tables are updated by the MHO whenever a new connection is established or an existing connection is terminated. The MHO sends Correction Layer messages to all cluster members to inform them about the owner of each connection2
NEW QUESTION # 46
What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?
- A. Reserved for internal purposes. Not in use.
- B. Additional ports used as uplinks
- C. Out-of-band interfaces for access to Orchestrator itself
- D. 1Gbps connectivity for Security Groups
Answer: C
Explanation:
The Management ports located on the Rear Panel of the Orchestrator MHO-140 are out-of-band interfaces that provide access to the Orchestrator itself for configuration and management purposes. They are not used for traffic distribution or connectivity to the Security Groups or the external networks. They are 1Gbps RJ-45 ports that can be connected to a switch or a router.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates2, page 4
NEW QUESTION # 47
What type of cluster can a Security Group be compared to?
- A. VSLS
- B. Active / Standby
- C. Active / Backup
- D. Load Sharing Active / Active
Answer: D
Explanation:
A Security Group (SG) in Check Point Maestro is comparable to a Load Sharing Active/Active cluster. This is because a Security Group consists of multiple Security Group Members (SGMs) that actively share the traffic load, provide high availability, and ensure scalability. Each SGM processes traffic according to the Security Group policy and synchronizes its state with other members, similar to how a Load Sharing Active/Active cluster distributes traffic across multiple nodes.
Exact Extract:
"A Security Group can be compared to a Load Sharing Active/Active cluster because it consists of multiple Security Group Members that share the traffic load and provide high availability and scalability. Each Security Group Member is an active firewall that processes traffic according to the Security Group policy and synchronizes its state with other members. The Maestro Orchestrator acts as a load balancer that distributes the traffic among the Security Group Members based on their capacity and availability."
-Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4
-Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3 Explanation of Options:
* A. Load Sharing Active / Active: Correct, as the Security Group operates like a Load Sharing Active
/Active cluster, with all SGMs actively processing traffic and sharing the load, as described in the documentation.
* B. VSLS: Incorrect, as Virtual System Load Sharing (VSLS) is a specific Check Point clustering mode for Virtual Systems, not directly comparable to a Security Group's architecture.
* C. Active / Backup: Incorrect, as this implies only one node is active while others are passive, which does not align with the active load-sharing nature of Security Groups.
* D. Active / Standby: Incorrect, as this also implies a single active node with standby nodes, whereas all SGMs in a Security Group are active.
References:
Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4 Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3
NEW QUESTION # 48
What is the throughput penalty of Security Group?
- A. 1% per member
- B. 10% per Security Group with no relation to the number of members
- C. Depends on the type of Appliance
- D. 5% per member
Answer: A
Explanation:
Check Point reduced throughput degradation to 1% per added SGMs. For example, the overall throughput degradation is 10% for 10 SGMs in a Security Group. Check Point aims to reduce this even further in the future. https://supportcenter.checkpoint.com/supportcenter/portal?
eventSubmit_doGoviewsolutiondetails=&solutionid=sk147853
NEW QUESTION # 49
What type of cluster can a Security Group can be compared to?
- A. VSLS
- B. Active / Standby
- C. Active / Backup
- D. Load Sharing Active / Active
Answer: D
Explanation:
A Security Group can be compared to a Load Sharing Active / Active cluster because it consists of multiple Security Group Members that share the traffic load and provide high availability and scalability. Each Security Group Member is an active firewall that processes traffic according to the Security Group policy and synchronizes its state with other members. The Maestro Orchestrator acts as a load balancer that distributes the traffic among the Security Group Members based on their capacity and availability.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3
NEW QUESTION # 50
......
The Check Point Maestro solution provides IT professionals with the ability to manage and scale their security infrastructure with ease, allowing them to secure their networks and applications without compromising performance or availability. The CCME certification exam covers a range of topics, including the architecture of the Check Point Maestro solution, the deployment and configuration of Maestro clusters, and the management of multiple gateways and security policies.
Updated Verified 156-836 dumps Q&As - Pass Guarantee or Full Refund: https://www.actual4exams.com/156-836-valid-dump.html
Updated Certification Exam 156-836 Dumps - Practice Test Questions: https://drive.google.com/open?id=1zrTPy7ohU1sT2Copph2yjhWntFthAZMy