After kernel debug with “fw ctl debug” you received a huge amount of information. It was saved in a very large file that is difficult to open and analyze with standard text editors. Suggest a solution to solve this issue.
AReduce debug buffer to 1024KB and run debug for several times
BUse Check Point InfoView utility to analyze debug output
CUse “fw ctl zdebug” because of 1024KB buffer size
DDivide debug information into smaller files. Use “fw ctl kdebug -f -o “filename” -m 25 - s “1024”
Which of the following daemons is used for Threat Extraction?
Aextractd
Btedex
Ctex
Dscrubd
You modified kernel parameters and after rebooting the gateway, a lot of production traffic gets dropped and the gateway acts strangely. What should you do?
ARun command fw ctl set int fw1_kernel_all_disable=1
BRestore fwkern.conf from backup and reboot the gateway
Crun fw unloadlocal to remove parameters from kernel
DRemove all kernel parameters from fwkern.conf and reboot
RAD is initiated when Application Control and URL Filtering blades are active on the Security Gateway. What is the purpose of the following RAD configuration file $FWDIR/conf/rad_settings.C?
AThis file contains the location information for Application Control and/or URL Filtering entitlements
BThis file contains the information on how the Security Gateway reaches the Security Managers RAD service for Application Control and URL Filtering
CThis file contains RAD proxy settings
DThis file contains all the host name settings for the online application detection engine
Question 6
Troubleshooting Site-to-Site VPNs
0
Question 7
Troubleshooting Management Servers
Question 8
Troubleshooting Management Servers
Question 9
Troubleshooting Identity Awareness
Question 10
Troubleshooting Management Servers
Question 11
Troubleshooting Identity Awareness
Question 12
Troubleshooting Identity Awareness
Question 13
Troubleshooting Identity Awareness
Question 14
Troubleshooting Management Servers
Question 15
Troubleshooting Management Servers
Question 16
Troubleshooting Management Servers
Question 17
Troubleshooting Identity Awareness
Question 18
Troubleshooting Management Servers
Question 19
Troubleshooting Identity Awareness
Question 20
Troubleshooting Management Servers
Question 21
Troubleshooting Management Servers
Question 22
Troubleshooting Management Servers
Question 23
Troubleshooting Management Servers
Question 24
Troubleshooting Management Servers
Question 25
Troubleshooting Management Servers
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
What is the name of the VPN kernel process?
AVPND
BCVPND
CFWK
DVPNK
You need to run a kernel debug over a longer period of time as the problem occurs only once or twice a week. Therefore, you need to add a timestamp to the kernel debug and write the output to a file but you can’t afford to fill up all the remaining disk space and you only have 10 GB free for saving the debugs. What is the correct syntax for this?
You run cpwd_admin list on a Security Gateway and notice that the CPM process is not listed. Select best answer?
AThe output is different between gateway and Management server.
BCPM is not running and can’t be monitored by watch dog.
CIf you want to monitor CPM you have to manually add it to watch dog.
DCPM is not there because it has own monitoring system. Only lower processes are monitored by watch dog.
What is the kernel process for Content Awareness that collects the data from the contexts received from the CMI and decides if the file is matched by a data type?
Acntawmod
Bcntmgr
Cdlpda
Ddlpu
In Check Point’s Packet Processing Infrastructure, what is the role of Observers?
AObservers attach object IDs to traffic
BThey store Rule Base matching state related information
CObservers monitor the state of Check Point gateways and report it to the security manager
DObservers decide whether or not to publish a CLOB to the Security Policy
What is the shorthand reference for a classification object?
Aclassobj
BCLOB
CCOBJ
Dclass.obj
The packet processing infrastructure consists of 4 components. Which component contains the CLOB, the object that contains information about the packet that is needed to make security decisions?
AManager
BClassifiers
CHandlers
DObservers
Which of these packet processing components stores Rule Base matching state-related information?
AClassifiers
BManager
CHandlers
DObservers
User defined URLS and HTTPS Inspection User defined URLs on the Security Gateway are stored in which database file?
Ahttps_urlf.bin
Burlf_db.bin
Curlf_https.bin
Dhttps_db.bin
Which two files contain the Application Database on the Security Gateway?
Aapi_db.C and api_custom_db.C
Bapcl_db.C and apcl_custom_db.C
Capplication_db.C and application_custom_db.C
Dappi_db.C and appi_custom_db.C
URL Filtering is an essential part of Web Security in the Gateway. For the Security Gateway to perform a URL lookup when a client makes a URL request, where is the sync-request forwarded from if a sync-request is required?
AURLF Kernel Client
BRAD User Space
CRAD Kernel Space
DURLF Online Service
Which of the following inputs is suitable for debugging HTTPS inspection issues?
Avpn debug cptls on
Bfw debug tls on TDERROR_ALL_ALL=5
Cfw ctl debug -m fw + conn drop cptls
Dfw diag debug tls enable
What is the best way to resolve an issue caused by a frozen process?
APower off the machine
BRestart the process
CReboot the machine
DKill the process
Which of the following would NOT be a flag when debugging a unified policy?
Atls
Brulebase
Cclob
Dconnection
In the Security Management Architecture, what port and process SmartConsole uses to communicate with the management server?
ACPM and 18190
BFWM and 19009
CCPM and 19009
DCPM 19009 and 18191
The Check Point Watch Daemon (CPWD) monitors critical Check Point processes, terminating them or restarting them as needed to maintain consistent, stable operating conditions. When checking the status/output of CPWD you are able to see some columns like APP, PID, STAT, START, etc. What is the column “STAT” used for?
AShows the status of the monitored process
BShows how many times the WatchDog started the monitored process
CShows the WatchDog name of the monitored process
DShows what monitoring method WatchDog is using to track the process
Which of the following commands can be used to see the list of processes monitored by the Watch Dog process?
Acpstat fw -f watchdog
Bfw ctl get str watchdog
Ccpwd_admin list
Dps -ef | grep watchd
What process monitors, terminates, and restarts critical Check Point processes as necessary?
ACPM
BFWD
CCPWD
DFWM
You found out that $FWDIR/log/fw.log is constantly growing in size at a Security Gateway, what is the reason?
ATCP state logging is enabled
BIt’s not a problem the gateway is logging connections and also sessions
Cfw.log can grow when GW does not have space in logging directory
DThe GW is logging locally
What tool would you run to diagnose logging and indexing?