156-587 Sample Questions

156-587 Sample Questions & Answers

Management-server problems, gateway issues and kernel debugging share the heaviest weighting, alongside basic Linux and command-line skills, log gaps, access-control checks, identity-awareness questions, and both site-to-site and remote VPN troubleshooting.

Launch the full 156-587 simulator →

Free 156-587 Sample Questions with Answers

Real questions from the Troubleshooting Expert - R81.20 (CCTE) practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Advanced Firewall Kernel Debugging · Configuring Kernel Debug Buffer

    A kernel debug using fw ctl zdebug is being performed on a production gateway to diagnose a connectivity issue. The administrator is concerned about the performance impact and wants to ensure the debug buffer does not overwrite important initial data too quickly. What is the correct command to increase the kernel debug buffer size to 2048 KB?

    Show answer & explanation

    Correct answer: B

    The correct command to set the kernel debug buffer size is fw ctl debug -buf . The fw ctl zdebug command is used to clear the buffer and view its contents, not to configure its size. The other options use incorrect syntax or commands.

  2. Question 2Beginner

    Advanced Identity Awareness Troubleshooting · Understanding Identity Awareness Processes

    True or False: When troubleshooting Identity Awareness, the pdp process runs on the Security Gateway (PEP) and is responsible for enforcing the identity-based policy.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Policy Decision Point (pdp) process is responsible for acquiring identities and making policy decisions, and it runs on the Security Management Server or a dedicated Identity Collector. The Policy Enforcement Point (pep) daemon runs on the Security Gateway and is responsible for enforcing the decisions made by the PDP.

  3. Question 3Intermediate

    Advanced Site-to-Site VPN Troubleshooting · Troubleshooting Dead Peer Detection (DPD)

    A retail company has deployed Check Point firewalls at its headquarters (HQ) and multiple branch offices. They are experiencing issues where the Site-to-Site VPN tunnels between HQ and the branches flap intermittently. The administrator suspects a Dead Peer Detection (DPD) issue. Which command should be used on the Security Gateway to view the current DPD timers and status for active tunnels?

    Show answer & explanation

    Correct answer: C

    The vpn shell utility provides an interactive mode for advanced VPN troubleshooting. Within this shell, the tunnels all command provides detailed information about all active tunnels, including their DPD status, timers, and sequence numbers. This is the most direct and comprehensive way to investigate DPD behavior. vpn tu is a TUI tool for basic tunnel management, fw ctl vpn iflist lists VPN-related kernel interfaces, and cpstat vpn -f all gives general status but not detailed DPD timers.

  4. Question 4Intermediate

    Advanced Troubleshooting with Logs and Events · Diagnosing Local Logging Issues

    An administrator notices that the /var/log/ partition on a Security Gateway is filling up rapidly with fw.log files. The gateway is configured to send logs to a dedicated Log Server, and connectivity between the two is stable. What is the MOST likely cause for the local logging?

    Show answer & explanation

    Correct answer: D

    In the gateway object's properties under 'Logs', there is a setting to 'Forward logs to Log Server'. Advanced options for this setting allow the gateway to start logging locally if the connection to the log server is lost or if the logging rate exceeds the connection's capacity. Even with stable connectivity, a very high log rate can trigger this local logging behavior, causing fw.log to be created and grow. This is the most common reason for unexpected local logging when a remote Log Server is configured.

  5. Question 5Advanced

    Advanced Gateway Troubleshooting · Advanced Packet Capture and Debugging Techniques

    A consultant is tasked with troubleshooting a complex application performance issue through a Check Point cluster. The traffic is encrypted (HTTPS) and uses multiple, short-lived TCP sessions. The consultant needs to see the full, unencrypted payload and correlate it with kernel-level decisions like NAT and routing for specific packets. Which combination of tools would be the MOST effective for this task?

    Show answer & explanation

    Correct answer: C

    fw monitor is the only standard tool that can show both kernel debug information and the packet data itself, across all inspection points (i, I, o, O). To see the unencrypted payload of HTTPS traffic, HTTPS Inspection must be enabled for that traffic flow. The -p all flag ensures fw monitor shows the packet data at every stage. This combination allows the consultant to see the decrypted application data and correlate it directly with kernel debug messages for NAT, routing, and policy decisions, providing a complete picture of the traffic flow.

  6. Question 6Advanced

    Advanced Access Control Troubleshooting · Optimizing Performance for High Connection Rate Applications

    Case Study:

    A global logistics company uses a Check Point R81.20 Maestro setup with two Security Groups (SG) for their primary data center. They have recently deployed a new inventory management application that communicates over a proprietary TCP protocol on port 15500. During peak hours, administrators receive alerts that the 'fwk' processes on several Security Gateway Modules (SGMs) in SG1 are spiking to 100% CPU, leading to packet drops and application timeouts. SG2, which handles different traffic, shows normal CPU levels.

    Analysis shows that SecureXL is enabled and should be accelerating this traffic, but the connection rate for the application is extremely high, involving thousands of new connections per second. The application traffic is allowed by a single rule with 'Log' as the tracking option. The security team needs to resolve the high CPU issue without compromising security for this critical application.

    Which action is the MOST appropriate first step to mitigate the high CPU on the 'fwk' processes?

    Show answer & explanation

    Correct answer: D

    The root cause of the high CPU on 'fwk' processes is the immense logging overhead from a high-connection-rate application. Each new connection must be processed by a Firewall Worker to generate a log, which consumes significant CPU resources. By changing the tracking option to 'None', the logging requirement is removed for new connections. This allows SecureXL to handle the connection setup (templating) without passing each one to a 'fwk' process, drastically reducing CPU load. While adding SGMs or creating custom applications are plausible actions, they don't address the core issue of logging overhead, which is the most immediate and effective problem to solve.

  7. Question 7Beginner

    Advanced Gateway Troubleshooting · Interpreting fw monitor Output

    When using fw monitor, what is the significance of the lowercase 'o' and uppercase 'O' inspection points in the output?

    Show answer & explanation

    Correct answer: D

    In the context of the fw monitor chain, the lowercase letters (i, o) represent inspection points before the Virtual Machine (firewall kernel) makes a forwarding decision. The uppercase letters (I, O) represent inspection points after the forwarding decision, just before the packet is sent to the network driver. 'VMAC' refers to the virtual MAC address used by the firewall kernel. Therefore, 'o' is before this stage, and 'O' is after, showing the packet as it is about to leave the gateway's OS.

  8. Question 8Intermediate

    Advanced Management Server Troubleshooting · Troubleshooting Secure Internal Communication (SIC)

    You are troubleshooting a policy installation failure where the error message on the Management Server indicates Installation failed. Reason: TCP connectivity failure (port = 18191). You have verified with netstat that the FWM process is listening on port 18191 on the remote gateway. Which of the following is the next logical step to diagnose this issue?

    Show answer & explanation

    Correct answer: D

    The error points to a TCP connectivity failure despite the process listening. This suggests something is blocking the connection. Since the gateway's own firewall policy could be blocking the connection from the management server, the most logical step is to check for drops at the kernel level. Running a kernel debug (fw ctl zdebug) during the policy push attempt will reveal if the gateway's own security policy is dropping the incoming SIC connection on port 18191 from the management server, a common cause for this specific error.

  9. Question 9Advanced

    Advanced Access Control Troubleshooting · Debugging Application Control

    A security engineer needs to investigate why certain traffic is not being properly identified by the Application Control blade. They need to debug the appscan daemon to understand how it is classifying the traffic. Which command would be used to enable debug mode for the Application Control daemon?

    Show answer & explanation

    Correct answer: B

    The rad_admin utility is the correct tool for managing and debugging the Application Control and URL Filtering daemons (rad). The command rad_admin debug all sets the debug level for all rad components to the highest level, which includes the appscan daemon. The output is typically written to $FWDIR/log/rad_messages. The other commands are for different daemons or are syntactically incorrect.

  10. Question 10Beginner

    Introduction to Advanced Troubleshooting · Using CPView for System Monitoring

    True or False: The CPView utility can only display real-time performance data and does not have the capability to show historical statistics.

    Show answer & explanation

    Correct answer: B

    This statement is false. CPView has a history mode that allows administrators to view performance data from the past. The utility collects and stores data at regular intervals, which can be accessed to troubleshoot issues that occurred previously. This is a critical feature for forensic analysis of performance problems.

Ready for the real thing?

The full 156-587 simulator has every exam-style question, timed mode, and instant scoring.