View Full Checkpoint 156-587 Exam Dumps and Practice Test Dumps.
Question 121
Which CLI command displays real-time connection acceleration statistics and drop reasons in SecureXL?
- sim stat -d
- fwaccel stats -s
- fw ctl accstat
- cpstat securexl -f default
Correct Answer: 2
Explanation:
Executing fwaccel stats -s (or fw accel stats) displays high-level summary statistics directly from the SecureXL acceleration driver. The generated terminal output breaks down accelerated connections, connection creation rates, template usage, and dropped packet metrics. System administrators use this command to evaluate offload efficiency, monitor Fast Path connection rates, verify that traffic is accelerating properly, and identify hardware or software drop causes across network interfaces without affecting active gateway throughput or stability.
Question 122
Which daemon process coordinates automatic core dump generation when a user-space process crashes?
- crashd
- cpwatchdog
- cpwd
- systemd
Correct Answer: 3
Explanation:
The Check Point WatchDog daemon (cpwd) monitors user-space processes on Gaia OS, such as fwd, cpm, and pdpd. When a monitored daemon encounters an unhandled exception or process crash, cpwd intercepts the exit signal, generates a core dump file in $FWDIR/log/ for post-mortem analysis, and logs the failure event. It then automatically restarts the failed service, ensuring high system availability while preserving diagnostic memory dumps for Check Point Technical Support investigations.
Question 123
Where is the local cache file for Identity Awareness user sessions stored on a Security Gateway?
- $FWDIR/database/pdpd_cache.db
- $FWDIR/state/pdpd_state.txt
- $FWDIR/conf/identity_cache.conf
- /var/log/pdp_sessions.db
Correct Answer: 2
Explanation:
The Policy Decision Point daemon (pdpd) stores active IP-to-user identity mappings and session states in $FWDIR/state/pdpd_state.txt. This local state file maintains persistent user identity information across process restarts and node updates. System administrators inspect or dump this session state file using pdp tracker commands when troubleshooting missing user identities, verifying Active Directory log ingestion, or diagnosing access enforcement failures across identity-enabled security rules.
Question 124
Which command enables maximum debug verbosity for the Firewall Management daemon fwm?
- fwm debug on
- fw debug fwm on TDERROR_ALL_ALL=5
- set fwm debug enable
- fwm -d start
Correct Answer: 2
Explanation:
Executing fw debug fwm on TDERROR_ALL_ALL=5 turns on verbose user-space debugging for the Firewall Management daemon (fwm). Setting the TDERROR_ALL_ALL=5 variable forces fwm to log comprehensive execution traces, database transaction details, and policy compilation steps directly to $FWDIR/log/fwm.elg. System engineers use this high-verbosity setting when isolating complex database lock errors, rulebase compilation failures, or SmartConsole management connection issues.
Question 125
Which network interface card feature distributes incoming network traffic across multiple CPU cores at the hardware level?
- Multi-Queue (RSS)
- CoreXL
- SecureXL
- ClusterXL
Correct Answer: 1
Explanation:
Multi-Queue, leveraging Receive Side Scaling (RSS), allows a Network Interface Card (NIC) to distribute incoming packet processing across multiple CPU cores at the hardware driver level. Instead of directing all network interface interrupts to a single CPU core, Multi-Queue assigns hardware receive queues to individual cores running Secure Network Distributor (SND) instances. This hardware-level distribution prevents CPU core bottlenecks, lowers latency, and ensures high packet throughput on multi-gigabit network interfaces.
Question 126
Which command displays the status of active ClusterXL sync transport connections between members?
- cphaprob syncstat
- cphaprob state
- fw ctl sync display
- show cluster sync
Correct Answer: 1
Explanation:
The cphaprob syncstat command displays operational statistics for ClusterXL state synchronization across cluster nodes. The output details synchronization transport protocol efficiency, total sync updates sent and received, dropped delta sync packets, and queue retransmission counts. Network engineers monitor cphaprob syncstat to confirm that cluster members replicate state tables reliably, identify underlying sync network congestion, and prevent state desynchronization issues that could trigger dropped connections during failover events.
Question 127
Which path in SecureXL handles traffic requiring layer-7 application pattern matching?
- Accelerated Path (Fast Path)
- Medium Path (PXL)
- Slow Path (F2F)
- Direct Path
Correct Answer: 2
Explanation:
The Medium Path (PXL) in SecureXL handles connections that require partial acceleration combined with layer-7 application inspection. In this path, SecureXL performs network-layer operations (such as IP checks and NAT) in the fast path while handing off payload data buffers to CoreXL worker instances for pattern matching by the Context Management Infrastructure (CMI). This hybrid approach reduces CPU overhead compared to full Slow Path (F2F) inspection while enforcing comprehensive Application Control, IPS, and Threat Prevention policies.
Question 128
Which daemon process manages automated Threat Emulation file uploads and cloud sandboxing analysis?
- scrubd
- ted
- in.emaild.mta
- rad
Correct Answer: 2
Explanation:
The Threat Emulation daemon (ted) manages sandboxing analysis workflows, file extraction, and cloud inspection requests on Security Gateways. When a file matches a Threat Emulation inspection rule, ted intercepts the file, hashes the payload, checks local or ThreatCloud verdict caches, and transmits suspicious files to local emulation appliances or cloud sandboxes. Monitoring ted process execution via $FWDIR/log/ted.elg allows administrators to troubleshoot file queuing delays, cloud sandbox connection timeouts, and inspection verdict updates.
Question 129
Which environment variable references the primary installation directory for Check Point common components?
- $FWDIR
- $CPDIR
- $CPMDIR
- $GAIADIR
Correct Answer: 2
Explanation:
The $CPDIR environment variable points to the base directory for shared Check Point software components, libraries, and utilities across Gaia OS (typically /opt/CPshrd-R80.XX). Central framework services—such as Secure Internal Communication (SIC) modules, licensing tools (cplic), database drivers, and administrative execution utilities—reside within $CPDIR. System scripts and operational daemons reference $CPDIR/bin and $CPDIR/conf to execute core system operations and maintain software component compatibility.
Question 130
Which command is used to display active dynamic kernel connection limits and current usage in real time?
- cpstat fw -f connections
- fw ctl pstat
- sim stat -c
- show active connections
Correct Answer: 2
Explanation:
Executing fw ctl pstat reads internal memory allocation counters directly from the kernel driver, displaying the current number of active connections alongside maximum capacity limits. Security engineers monitor these state table limits during high-throughput traffic spikes to verify that the gateway has sufficient state memory headroom. Identifying table utilization via fw ctl pstat allows administrators to adjust state limits before reaching capacity bounds that cause traffic drops.
Question 131
Which process handles database object management and multi-user change locking on R80+ Management Servers?
- fwm
- cpm
- cpd
- postgres
Correct Answer: 2
Explanation:
The Check Point Management (CPM) daemon acts as the primary orchestration service on R80+ Management Servers, handling database transactions, multi-user change locking, and API requests. Operating as a Java-based application server, CPM coordinates object modifications within the underlying PostgreSQL database, enforces session isolation during concurrent administration sessions, and manages database schema integrity. Network administrators rely on CPM stability to ensure smooth policy editing, object management, and configuration deployment across SmartConsole clients.
Question 132
Which configuration file stores static affinity bindings for physical network interfaces and CoreXL workers?
- $FWDIR/conf/affinity.conf
- $FWDIR/boot/modules/fwkern.conf
- /etc/sysconfig/network.conf
- $FWDIR/conf/local.app
Correct Answer: 1
Explanation:
Manual CPU core allocations for physical Network Interface Cards (NICs), Secure Network Distributor (SND) cores, and CoreXL worker instances (fw_worker) are defined in $FWDIR/conf/affinity.conf. Editing this configuration file overrides default dynamic affinity algorithms, allowing administrators to pin interface IRQ processing to specific CPU cores. Correctly tuning affinity.conf prevents cross-core processing contention, balances interface workloads, and maximizes throughput on multi-core Security Gateways under heavy network traffic loads.
Question 133
Which CLI tool displays active licence details and expiration dates on a Security Gateway?
- cplic print
- show license all
- fw ctl lic -v
- cpstat license
Correct Answer: 1
Explanation:
The cplic print utility displays all software licenses currently installed on a Check Point gateway or management server. Running cplic print outputs details including active license keys, feature signatures, expiration dates, container IPs, and signature strings. System administrators use cplic print to verify license validity, confirm software blade entitlements, diagnose evaluation license expirations, and ensure that feature licenses are properly applied across enterprise security deployments.
Question 134
Which daemon process processes AD Query event logs collected from Windows Domain Controllers?
- pdpd
- adlogd
- pepd
- cpd
Correct Answer: 2
Explanation:
The adlogd daemon manages Active Directory event log monitoring when using AD Query for Identity Awareness. It establishes background connections to configured Windows Domain Controllers via WMI or Windows API protocols, scanning security event logs for user authentication events (such as Event IDs 4624 and 4625). adlogd extracts IP-to-username mappings from these log streams and forwards normalized identity data to pdpd, allowing the gateway to enforce user-based security rules without requiring client endpoint software.
Question 135
What is the function of the command fwaccel off?
- Permanently removes SecureXL driver modules from the kernel boot image
- Temporarily disables SecureXL acceleration, forcing traffic to the slow path
- Resets connection templates without turning off hardware offloading
- Disables CoreXL firewall instances across all CPU cores
Correct Answer: 2
Explanation:
Executing fwaccel off (or fw accel off) instantly disables SecureXL acceleration drivers on an active gateway without requiring an OS reboot or service restart. Disabling acceleration bypasses Fast Path templates and Medium Path processing, forcing all network traffic through the Slow Path (Firewall-to-Firewall) for stateful evaluation by CoreXL instances. Security engineers use fwaccel off during troubleshooting to isolate acceleration bugs, verify rulebase processing, and establish baseline firewall performance without hardware offloading.
Question 136
Which log file records diagnostic information for SOLR indexing operations on a Management Server?
- $FWDIR/log/solr.elg
- $RTDIR/log/smartlog_solr.log
- $FWDIR/log/smartlog.elg
- /var/log/solr_indexing.log
Correct Answer: 1
Explanation:
The $FWDIR/log/solr.elg log file records runtime diagnostic traces, index creation events, and memory usage details for the Apache Solr search daemon (solr). Because solr indexes incoming log records to power fast search queries within SmartConsole and SmartLog, administrators review solr.elg when experiencing slow log query responses, index desynchronization issues, or index corruption errors on Management and Log Servers.
Question 137
Which command displays the hardware CPU core distribution for all active CoreXL firewall instances?
- fw ctl multik stat
- cpconfig corexl list
- top -p fw_worker
- show corexl cores
Correct Answer: 1
Explanation:
The fw ctl multik stat command provides real-time operational metrics for all active CoreXL firewall worker instances (fw_worker) running on a gateway. The generated output table details assigned Firewall Instance IDs, active core CPU affinities, current processing loads, and queue allocations. Network engineers use fw ctl multik stat to verify balanced load distribution across processing cores, confirm that CoreXL instances handle traffic efficiently, and identify performance bottlenecks caused by uneven CPU utilization across gateway cores.
Question 138
Which process handles logging transport on TCP port 257 on a Security Gateway?
- fwd
- cpd
- cpm
- logd
Correct Answer: 1
Explanation:
The Firewall Daemon (FWD) manages log collection and transport on Check Point Security Gateways. Operating in user space, FWD collects log records generated by kernel inspection modules, formats the entries, and transmits them over an encrypted TCP port 257 connection to the target Log Server or Security Management Server. Using a dedicated TCP connection ensures reliable, ordered log delivery, preventing log data loss during network instability or peak traffic periods.
Question 139
What is the function of the command cphaprob state?
- Displays the operational ClusterXL High Availability state of all cluster nodes
- Lists active state sync connections across cluster heartbeat interfaces
- Forces an immediate failover to a standby cluster member
- Clears dropped sync packet counters on all cluster interfaces
Correct Answer: 1
Explanation:
Executing cphaprob state displays the current High Availability state of all cluster members within a ClusterXL deployment. The command outputs the local node state (such as Active, Standby, Down, or Pivot) along with the reported states of peer cluster nodes over heartbeat links. Network engineers use cphaprob state during maintenance routines, failover testing, and health checks to confirm node redundancy, verify expected HA roles, and ensure cluster members respond appropriately to interface or hardware failures.
Question 140
Which CLI tool is used to monitor real-time CPU, memory, interface, and blade performance metrics in an interactive GUI?
- cpview
- top
- ntop
- fw ctl pstat
Correct Answer: 1
Explanation:
cpview is an interactive, text-based visual monitoring tool embedded in Gaia OS. Running cpview opens a dynamic interface that displays real-time performance data across system components, including CPU core utilization, memory allocations, network interface traffic, SecureXL offload paths, CoreXL worker loads, and individual software blade statistics. System administrators rely on cpview during live performance troubleshooting to identify resource bottlenecks, evaluate historical utilization trends, and monitor system health under heavy network traffic.