Free 156-835 Sample Questions — Check Point Certified Maestro Expert

Free 156-835 sample questions for the Check Point Certified Maestro Expert exam. No account required: study at your own pace.

Want an interactive quiz? Take the full 156-835 practice test

Looking for more? Click here to get the full PDF with 67+ practice questions for $10 for offline study and deeper preparation.

Question 1

Which command will be used in order to restart Orchestrator service only?

  • A. orchd restart
  • B. cpstop; cpstart
  • C. reboot
  • D. service orchestrator restart
Show Answer
Correct Answer:
A. orchd restart
Question 2

What happens when you make changes from Clish on the SMO Master?

  • A. The changes are synchronized to the SMS/MDS as a backup
  • B. The changes are synchronized to the MHO as a backup
  • C. Changes are only applied on the SMO Master
  • D. Changes are applied to all members in the SG
Show Answer
Correct Answer:
C. Changes are only applied on the SMO Master
Question 3

What is the default IP range of CIN network (with no increment)?

  • A. 192.168.1.0
  • B. 198.51.100.0
  • C. The same as Management network
  • D. 192.0.2.0
Show Answer
Correct Answer:
B. 198.51.100.0
Question 4

How many power supplies are presented on MHO-140?

  • A. 2
  • B. 4
  • C. 1
  • D. 1 with option for 2
Show Answer
Correct Answer:
A. 2
Question 5

What is the minimal requirement for a Security Group?

  • A. 1 Appliance and 1 management port
  • B. 2 Appliances and 2 ports
  • C. 1 Appliance and 1 administrator with Multi-Domain admin permissions
  • D. None, it may be empty
Show Answer
Correct Answer:
A. 1 Appliance and 1 management port
Question 6

HealthCheck Point ____________.

  • A. performs a system health check and is meant to replace both a CPInfo and the health check script
  • B. can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization
  • C. is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system
Show Answer
Correct Answer:
D. undefined
Question 7

What cannot be learned from the output of asg perf -v -p command?

  • A. Average CPU usage on Appliances
  • B. Real-time throughput
  • C. Average CPU usage on Orchestrators
  • D. Per-path distribution
Show Answer
Correct Answer:
C. Average CPU usage on Orchestrators
Question 8

What is the default IP range of Sync network (with no increment)?

  • A. The same as Management network
  • B. 198.51.100.0
  • C. 192.0.2.0
  • D. 192.168.1.0
Show Answer
Correct Answer:
C. 192.0.2.0
Question 9

During an upgrade, is Multi-Version Clustering (MVC) supported?

  • A. No, Maestro does not support MVC because ClusterXL is disabled during an upgrade
  • B. No, Maestro does not support MVC
  • C. Maestro supports MVC or full connectivity upgrade as of R80.40.
  • D. Yes, MVC is supported as of R81 for Maestro
Show Answer
Correct Answer:
B. No, Maestro does not support MVC
Question 10

In what mode do MHOs process traffic?

  • A. MHOs process traffic in load sharing mode
  • B. MHOs process traffic in Active-Standby mode
  • C. MHOs process traffic in Active-Active mode
  • D. MHOs process traffic in VSLS mode
Show Answer
Correct Answer:
C. MHOs process traffic in Active-Active mode
Question 11

Logs without a dedicated log file can be found in

  • A. /var/log/junk.log.dbg
  • B. /var/log/messages
  • C. $RTDIR/log/junk.log
  • D. $FWDIR/log/fw.log
Show Answer
Correct Answer:
A. /var/log/junk.log.dbg
Question 12

What is a Security Group?

  • A. Logical group of computer and network resources
  • B. Group of security administrators
  • C. Group of security gateways
  • D. Group of appliances with enabled NGTX software blades
Show Answer
Correct Answer:
A. Logical group of computer and network resources
Question 13

What will happen in case of NAT of the traffic passing through Management network?

  • A. This traffic will not pass correction, since it will be dropped
  • B. This traffic will pass with no inspection
  • C. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances
  • D. Orchestrator will disable NAT and traffic will pass with no issue
Show Answer
Correct Answer:
A. This traffic will not pass correction, since it will be dropped
Question 14

What is an uplink interface used for?

  • A. To connect in between Orchestrators
  • B. To connect appliances to customer's infrastructure
  • C. To connect Orchestrators to customer's infrastructure
  • D. To connect in between appliances
Show Answer
Correct Answer:
C. To connect Orchestrators to customer's infrastructure
Question 15

What is the maximum amount of Appliances within Security group in Dual-Site configuration?

  • A. 16
  • B. 15
  • C. 28
  • D. 31
Show Answer
Correct Answer:
C. 28
Question 16

Is it possible to define distribution mode per interface?

  • A. Yes, only for downlink interfaces
  • B. No, only for the Security Group
  • C. Yes, only for uplink interfaces
  • D. Yes, for both uplink and downlink interfaces
Show Answer
Correct Answer:
A. Yes, only for downlink interfaces
Question 17

When security policy is installed:

  • A. All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy
  • B. The SMO Master receives the policy and performs a policy verification, the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy
  • C. All SGMs receive the security policy and simultaneous policy installation occurs
  • D. The policy is installed on the SMO. the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy
Show Answer
Correct Answer:
D. The policy is installed on the SMO. the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy
Question 18

What is the Iterator process?

  • A. Iterator is the process that simulates distribution in case of Appliance failure
  • B. Iterator is the process that follow Appliance recovery and simulates what was a distribution if recovered Appliance was alive
  • C. Iterator is the process that runs on the Orchestrator and calculates a distribution in case of Appliance failure
  • D. Iterator is the process that runs on the Orchestrator and calculates a distribution in case of Appliance recovery
Show Answer
Correct Answer:
B. Iterator is the process that follow Appliance recovery and simulates what was a distribution if recovered Appliance was alive
Question 19

What is the Orchestrator?

  • A. Load balancer
  • B. Network Switch
  • C. Manager of compute and network resources, load balancer and network switch
  • D. None of above
Show Answer
Correct Answer:
C. Manager of compute and network resources, load balancer and network switch
Question 20

What type of cluster can a Security Group can be compared to?

  • A. VSLS
  • B. Load Sharing Active /Active
  • C. Active / Backup
  • D. Active / Standby
Show Answer
Correct Answer:
B. Load Sharing Active /Active

Aced these? Get the Full Exam

Download the complete 156-835 study bundle with 67+ questions in a single printable PDF.