
Pass Your CCME 156-836 Exam on Oct 11, 2025 with 90 Questions
156-836 Free Exam Study Guide! (Updated 90 Questions)
CheckPoint 156-836 certification exam is a comprehensive assessment of the candidate's knowledge in configuring and maintaining Maestro networks. 156-836 exam covers topics such as deploying and configuring Maestro in a network environment, managing Maestro gateways and clusters, configuring network segmentation, and optimizing network performance. 156-836 exam also tests the candidate's knowledge in troubleshooting common issues that may arise in a Maestro deployment.
CheckPoint 156-836 (Check Point Certified Maestro Expert - R81 (CCME)) exam is a certification exam that validates the skills and knowledge of professionals in the field of network security. 156-836 exam is designed for individuals who have significant experience in managing, deploying, and troubleshooting Check Point Maestro solutions. 156-836 exam measures the candidate's ability to operate and maintain complex enterprise networks using Check Point Maestro technology.
NEW QUESTION # 12
What is the default Distribution mode?
- A. Manual-General
- B. Auto-topology
- C. Network
- D. User
Answer: B
Explanation:
Explanation
Auto-topology is the default distribution mode for Maestro Security Groups. In this mode, the Orchestrator assigns packets to a Security Group Member based on the topology of the port defined in the gateway object.
Each port is either in user mode or network mode depending on the topology. User mode means that the port is connected to the internal network and network mode means that the port is connected to the external network.
The Orchestrator uses a hash function to map each source IP or destination IP to a specific SGM, depending on the mode of the port. This mode ensures that all packets with the same source IP or destination IP are processed by the same SGM, regardless of the port or protocol.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-18
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-7
*Lari Luoma | Lead Consultant | Maestro SME | Check Point Evangelist1, slide 16
NEW QUESTION # 13
What happens when you make changes from Clish on the SMO Master?
- A. The changes are synchronized to the MHO as a backup.
- B. The changes are synchronized to the SMS/MDS as a backup.
- C. Changes are applied to all members in the SG.
- D. Changes are only applied on the SMO Master.
Answer: D
Explanation:
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.2: Security Group Configuration, page 2-10
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Configuration, page 2-9
*Security Group Configuration - Check Point Software
NEW QUESTION # 14
Multiple SGs can exist in a Dual Site environment. Each SG can be configured in one of three ways. Which is not one of those ways?
- A. Direct connectivity between Remote Site MHOs.
- B. Two MHOs at same site connected to remote site MHOs via single switch.
- C. Two MHOs at same site connected to remote site MHOs via two different switches.
- D. Two MHOs connected to two MHOs via load balancers.
Answer: D
Explanation:
Explanation
This is not one of the ways to configure a Security Group in a Dual Site environment, because load balancers are not required or supported for the inter-site communication between the Maestro Orchestrators (MHOs).
The MHOs use the Site-Sync port and VLANs to synchronize the resources and connections across the sites.
The three valid scenarios for Dual Site configuration are:
*Direct connectivity between remote site Orchestrators: This scenario requires two orchestrators, one for each site, and a direct connection between them using the site-sync port.
*Two orchestrators on the same site are connected to the remote site orchestrators through two different switches: This scenario requires four orchestrators, two for each site, and a connection between them using the site-sync port and two external switches that support QinQ and MTU increment.
*Two orchestrators on the same site are connected to the remote site orchestrators through one switch: This scenario also requires four orchestrators, two for each site, and a connection between them using the site-sync port and one external switch that support QinQ and MTU increment.
References =
*Maestro Dual Site configuration with a direct connection through L2 switches
*[Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)]
*[Maestro Frequently Asked Questions (FAQ)]
NEW QUESTION # 15
What is the Correction Layer?
- A. Correction Layer is a daemon which corrects errors on Backplane interfaces
- B. Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute
- C. Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT
- D. Correction Layer is a mechanism which activated in case of asymmetric routing
Answer: C
Explanation:
The Correction Layer is a Maestro component that ensures that packets from the same connection are handled by the same Security Group Module (SGM) in a multi-appliance system. This is especially important when NAT is involved, as packets sent from the client to the server can be distributed to a different SGM than packets from the same session sent from the server to the client. The Correction Layer must then forward the packet to the correct SGM.
References:
*NAT and the Correction Layer on a Security Gateway - Check Point Software1
*Solved: Maestro queries - Check Point CheckMates
NEW QUESTION # 16
What is the maximum number of Appliances within the same Security Group?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Explanation
The maximum number of appliances within the same security group is 31. This is because a security group can have up to 31 Security Group Modules (SGMs) of the same or different models, and each SGM is an appliance that runs the Check Point software. A security group can span across multiple chassis, and each chassis can have up to 16 SGMs. However, the total number of SGMs in a security group cannot exceed 31.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 51
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 17
In a dual MHO environment, MHO1 and MHO2 are connected to the SGM line cards in which way?
- A. MHO1 and MHO2 are connected to the SGMs using the Sync cable.
- B. MHO 1 is connected to the odd-numbered ports, while MHO2 is connected to even-numbered ports.
- C. MHO 1 is connected to the even-numbered ports, while MHO2 is connected to odd-numbered ports.
- D. MHO1 and MHO2 are connected to the line cards in any order administrators see fit.
Answer: C
Explanation:
The correct way to connect MHO1 and MHO2 to the SGM line cards in a dual MHO environment is to use the even-numbered ports for MHO1 and the odd-numbered ports for MHO2. This is to ensure that each SGM has two downlinks to each MHO, and that the downlinks are balanced across the different NICs and links.
This provides redundancy and high availability for the traffic flow between the SGMs and the MHOs.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 18
*Maestro Technical Training, Module 2: Maestro Security Groups and the Single Management Object, slide 16
NEW QUESTION # 18
What is the purpose of g_tcpdump command?
- A. Collects traffic dump from all Active Appliances within Security Group
- B. The same as tcpdump, just on Scalable Platform
- C. Collects traffic dump from CIN network
- D. Collects traffic dump from Sync network
Answer: A
Explanation:
Explanation
_tcpdump" probably collects traffic dumps from all active appliances within a security group, aligning with the naming convention and function of similar commands in scalable platforms.
References
*Maestro Expert (CCME) Course - Check Point Software, page 331
*What is 'IN' and 'OUT' of g_tcpdump? - Check Point CheckMates2
*CHECK POINT MAESTRO EXPERT, page 23
NEW QUESTION # 19
Which command is used to set the number of sites in a Maestro environment?
- A. set maestro orchestrator-site-amount
- B. set maestro configuration orchestrator-site-amount
- C. set maestro configuration orchestrator-site-id
- D. set maestro configuration orchestrator-site-number
Answer: B
Explanation:
This command is used to set the number of sites in a Maestro environment, which can be either one or two.
The number of sites determines the site-sync configuration and the failover policies for the Security Groups and the Security Group Members. The default value is one, and it can be changed only before the first Security Group is created.
References =
*Maestro basic setup documentation - Page 2 - Check Point CheckMates
*Check Point R81.10 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 20
Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?
- A. IPS configuration files
- B. VPN configuration files
- C. Mobile Access configuration files.
- D. fwkern.conf files.
Answer: D
Explanation:
References
*Maestro R80.30SP Jumbo Hotfix Accumulator, Section: Important Notes
*Check Point Maestro R80.30SP with Gaia 3.10, Section: Known Limitations
*Check Point SNMP MIB files, Section: Revision History
NEW QUESTION # 21
During an upgrade, Is Multi-Version Clustering (MVC) supported?
- A. No, Maestro does not support MVC.
- B. Yes, MVC is supported as of R81 for Maestro.
- C. No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.
- D. Maestro supports MVC or full connectivity upgrade as of R80.40.
Answer: D
NEW QUESTION # 22
Is it possible to define distribution mode per interface?
- A. Yes, for both uplink and downlink interfaces
- B. Yes, only for downlink interfaces
- C. Yes, only for uplink interfaces
- D. No, only for the Security Group
Answer: A
Explanation:
Explanation
Maestro allows you to define the distribution mode per interface, which determines how traffic is distributed among the Security Group Modules (SGMs) in a Security Group. You can configure the distribution mode for each interface individually, or use the default mode for all interfaces. The distribution mode can be set for both uplink and downlink interfaces.
References =
*Check Point Maestro R81.X Administration Guide, page 62, section "Distribution Mode" 1
*Check Point Maestro R81.X Getting Started Guide, page 25, section "Distribution Mode" 2
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
NEW QUESTION # 23
What happens if the SMO Master fails?
- A. The next SGM with the current lowest SGM ID assumes the role of the SMO Master.
- B. A failover will occur on the MHO and traffic will continue to pass.
- C. The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.
- D. The Backup SMO Master will take over in the event of a failure with the SMO Master.
Answer: D
Explanation:
The SMO Master is the SGM that is responsible for managing the Security Group and communicating with the MHO. If the SMO Master fails, the Backup SMO Master, which is the SGM with the next lowest SGM ID, will take over the role of the SMO Master and ensure the continuity of the Security Group operations.
References = Maestro Expert (CCME) Course - Check Point Software, page 14; Check Point Accredited Maestro Expert - New exam a... - Check Point CheckMates, page 1.
NEW QUESTION # 24
What Maestro component is automatically designated the SMO Master?
- A. The first MHO configured is considered the SMO Master.
- B. The MDS that pushes policy to the SMO is considered the SMO Master.
- C. The SGM with the lowest member ID (the first one added to the security group.)
- D. The SGM with the highest member ID (the last one added to the security group.)
Answer: C
Explanation:
Explanation
The SMO Master is the SGM that is responsible for synchronizing the configuration and policy with the other SGMs in the security group. The SMO Master is automatically designated as the SGM with the lowest member ID, which is usually the first one added to the security group. The SMO Master can be changed manually if needed.
References:
*Maestro Frequently Asked Questions (FAQ), under "What is a Single Management Object (SMO)?"
*Check Point Jump Start Course: Maestro, under "Maestro Security Groups"
NEW QUESTION # 25
What is the purpose of g_tcpdump command?
- A. Collects traffic dump from all Active Appliances within Security Group
- B. The same as tcpdump, just on Scalable Platform
- C. Collects traffic dump from CIN network
- D. Collects traffic dump from Sync network
Answer: A
Explanation:
Explanation
_tcpdump" probably collects traffic dumps from all active appliances within a security group, aligning with the naming convention and function of similar commands in scalable platforms.
References
*Maestro Expert (CCME) Course - Check Point Software, page 331
*What is 'IN' and 'OUT' of g_tcpdump? - Check Point CheckMates2
*CHECK POINT MAESTRO EXPERT, page 23
NEW QUESTION # 26
What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?
- A. 1Gbps connectivity for Security Groups
- B. Reserved for internal purposes. Not in use
- C. Two Out-of-band interfaces for access to Orchestrator itself
- D. Out-of-band interface for access to Orchestrator itself and Serial Console connector
Answer: D
Explanation:
The RJ-45 connectors located at the front panel of the Orchestrator MHO-170 are used for out-of-band management and serial console access. One of them is a 1Gbps RJ-45 port that provides an out-of-band interface for accessing the Orchestrator itself for configuration and management purposes. The other one is a RJ-45 serial console port that provides a command-line interface for initial setup and troubleshooting.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates, page 4
NEW QUESTION # 27
What will happen in case of NAT of the traffic passing through Management network?
- A. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re- distribute traffic to other Appliances
- B. This traffic will pass with no inspection
- C. This traffic will not pass correction, since it will be dropped
- D. Orchestrator will disable NAT and traffic will pass with no issue
Answer: D
Explanation:
According to the Check Point MAESTRO R80.20SP Administration Manual1, NAT is not supported on the management network. If you configure NAT on the management network, the Orchestrator will disable NAT and allow the traffic to pass without translation. This is to ensure that the management traffic can reach the Security Group members and the SmartConsole without any issues.
References
*Check Point MAESTRO R80.20SP Administration Manual, page 291
NEW QUESTION # 28
To display processes that are consuming excessive system resources, users should use the_____ command.
- A. top
- B. asg stat -v
- C. asg_perf_hogs
- D. asg perf -v
Answer: C
Explanation:
The asg_perf_hogs command is a script that displays the processes that are consuming excessive system resources, such as CPU, memory, disk, and network, on the orchestrator and the appliances. It can help identify performance issues and bottlenecks in the Maestro environment.
References
*Software Provision and Performance hogs failed - Check Point CheckMates1
*CHECK POINT MAESTRO EXPERT, page 33
NEW QUESTION # 29
In a Maestro Dual Site environment, what is the definition of the term Active Site.
- A. The Active Site is the site currently handling the enforcement on traffic passing for a specific SG.Connections are synced within the SGMs in the Active Site.
- B. The Active Site is the site that is not handling any traffic for the specific SG, but itsconnections are synced to its SGMs from the MHOs to be ready in the event of a failover.
- C. There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.
- D. The Active Site is the site where the SMO Master exists.
Answer: A
Explanation:
Explanation
In a Maestro Dual Site environment, there are two sites that can host Security Group Members (SGMs) for each Security Group (SG). The Active Site is the one that is currently processing the traffic for a specific SG, while the Standby Site is the one that is ready to take over in case of a failover. The Active Site and the Standby Site can be different for different SGs, depending on the load balancing and failover policies. The Active Site and the Standby Site are synchronized by the Maestro Orchestrators (MHOs) using the Site-Sync port and VLANs.
References =
*Solved: Maestro dual site failover - Check Point CheckMates
*Maestro Dual Site configuration with a direct connection through L2 switches
NEW QUESTION # 30
What happens if the SMO Master fails?
- A. A failover will occur on the MHO and traffic will continue to pass.
- B. The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master.
- C. The Backup SMO Master will take over in the event of a failure with the SMO Master.
- D. The next SGM with the current lowest SGM ID assumes the role of the SMO Master.
Answer: D
Explanation:
Explanation
This aligns with the principle of redundancy in network systems, where the next available device with the lowest ID typically takes over management roles in case of a failure.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 91
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 31
What is the max amount of Orchestrators in Dual-site setup?
- A. 0
- B. 2 per Security Group
- C. 1
- D. 4 per Security Group
Answer: D
Explanation:
Explanation
A Dual Site setup can have either two or four orchestrators, depending on the scenario. However, the maximum number of orchestrators per Security Group is four, regardless of the number of sites. This is because each Security Group can have up to two orchestrators on each site, and each site can have up to two orchestrators. Therefore, the maximum number of orchestrators in a Dual Site setup is four per Security Group.
References =
*Maestro Frequently Asked Questions (FAQ)
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
NEW QUESTION # 32
There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?
- A. 100%/0%
- B. 33%/66%
- C. 50%/50%
- D. 66%/33%
Answer: C
Explanation:
Explanation
The proportion of traffic distribution done by Orchestrator depends on the traffic distribution mode that is configured for the Security Group. There are three modes: Round Robin, Load Sharing, andActive/Standby1.
*Round Robin mode distributes the traffic equally among all the appliances in the Security Group, regardless of the number of downlinks they have. This mode is suitable for scenarios where all the appliances have similar performance and capacity. In this mode, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
*Load Sharing mode distributes the traffic proportionally to the number of downlinks each appliance has. This mode is suitable for scenarios where the appliances have different performance and capacity. In this mode, the proportion of traffic distribution would be 33%/66% for two appliances with one and two downlinks respectively.
*Active/Standby mode distributes the traffic to only one appliance at a time, while the other appliances are in standby mode. This mode is suitable for scenarios where high availability is required. In this mode, the proportion of traffic distribution would be 100%/0% or 0%/100% for two appliances with one and two downlinks respectively, depending on which appliance is active.
Since the question does not specify the traffic distribution mode, the default mode is Round Robin2.
Therefore, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
NEW QUESTION # 33
......
156-836 Dumps for CCME Certified Exam Questions and Answer: https://www.testkingit.com/CheckPoint/latest-156-836-exam-dumps.html
Realistic Verified 156-836 exam dumps Q&As - 156-836 Free Update: https://drive.google.com/open?id=1t7WjOMvT4RE4nKBhwJnwTVT8ia_fwL-f