Pass the Checkpoint CCME 156-836 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?

Options:

A.

When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.


B.

When dynamic routing protocols, such as BGP or OSPF are used.


C.

When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.


D.

When the SG is NATing a very high percentage of traffic passing through it.


Expert Solution
Questions # 2:

What is the throughput penalty of Security Group?

Options:

A.

Depends on the type of Appliance


B.

1% per member


C.

10% per Security Group with no relation to the number of members


D.

5% per member


Expert Solution
Questions # 3:

What is a downlink interface used for?

Options:

A.

To connect appliances to Orchestrators


B.

To connect appliances to customer's infrastructure


C.

To connect in between Orchestrators


D.

To connect Orchestrators to customer's infrastructure


Expert Solution
Questions # 4:

In a Maestro Dual Site environment, what is the definition of the term Active Site.

Options:

A.

The Active Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover.


B.

The Active Site is the site where the SMO Master exists.


C.

There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.


D.

The Active Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.


Expert Solution
Questions # 5:

What is the Correction Layer mechanism?

Options:

A.

Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs.


B.

The load-balancing mechanism used by the MHO.


C.

The MHO's distribution algorithm which determines the handling SGM for a given connection.


D.

Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG.


Expert Solution
Questions # 6:

What is the purpose of interface bonding?

Options:

A.

A bond interface can be configured for high availability redundancy.


B.

A bond interface is used for passing synchronization traffic between the SGMs.


C.

For load sharing which increases connection throughput above that which is possible using one physical interface.


D.

A bond interface can be configured for high availability redundancy or for load sharing which increases connection throughput above that which is possible using one physical interface.


Expert Solution
Questions # 7:

What kinds of transceivers are supported on Orchestrator MHO-170?

Options:

A.

SFP, QSFP, QSFP28


B.

SFP+, SFP28, QSFP


C.

SFP, SFP+, SFP28


D.

QSFP, QSFP28


Expert Solution
Questions # 8:

Multiple SGs can exist in a Dual Site environment. Each SG can be configured in one of three ways. Which is not one of those ways?

Options:

A.

Two MHOs connected to two MHOs via load balancers.


B.

Two MHOs at same site connected to remote site MHOs via two different switches.


C.

Two MHOs at same site connected to remote site MHOs via single switch.


D.

Direct connectivity between Remote Site MHOs.2


Expert Solution
Questions # 9:

There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators?

Options:

A.

Any pair of available ports


B.

Port 1 in Slot 1 and Port 1 in Slot 2


C.

Port 1 in Slot 1 and Port 2 in Slot 1


D.

Port 1 in Slot 2 and Port 2 in Slot 1


Expert Solution
Questions # 10:

When security policy is installed

Options:

A.

All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.


B.

The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.


C.

All SGMs receive the security policy and simultaneous policy installation occurs.


D.

The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions