Courseiva

156-315.81.20 Performance Tuning (SecureXL/CoreXL) Practice Question

A security administrator is troubleshooting a performance issue on an R81 Security Gateway. The administrator runs 'fwaccel stats -s' and observes that a large number of connections are being handled by the Firewall path instead of being accelerated. The administrator wants to identify which specific connections are not being accelerated. Which command should be used to view the acceleration status of active connections?

⚠ Common exam trap

The trap here is assuming that 'fwaccel stats' provides per-connection details, when it only gives aggregate statistics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fwaccel conns

To identify which specific connections are not being accelerated, the administrator must view the SecureXL connection table. The 'fwaccel conns' command lists active connections and indicates whether each is accelerated or handled by the Firewall path. This granular view is essential for troubleshooting why certain traffic bypasses acceleration, as it provides details like source, destination, and the reason for non-acceleration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    fwaccel conns

    Why this is correct

    The 'fwaccel conns' command displays the SecureXL connection table, showing which connections are accelerated and which are handled by the Firewall path. It provides details such as the source and destination IP addresses, ports, and the acceleration status (e.g., 'A' for accelerated, 'F' for firewall). This allows the administrator to pinpoint exactly which traffic is not being accelerated and investigate the reason.

  • ✗

    fwaccel stats

    Why it's wrong here

    'fwaccel stats' shows global SecureXL statistics, such as the number of accelerated packets and connections, but it does not provide per-connection details. It aggregates data, so the administrator cannot identify specific connections that are not accelerated. To see individual connections, 'fwaccel conns' is required. Using 'fwaccel stats' alone would not reveal which particular flows are bypassing acceleration.

  • ✗

    fw monitor -e 'accel;'

    Why it's wrong here

    'fw monitor' captures packets on the gateway, but the expression 'accel;' is not a valid filter for acceleration status. 'fw monitor' is used for packet capture and analysis, not for querying the SecureXL connection table. It would not show whether a connection is accelerated or not; it only shows packet contents. This command is inappropriate for identifying non-accelerated connections.

  • ✗

    cpview -t

    Why it's wrong here

    'cpview' provides real-time performance monitoring, including SecureXL statistics, but it does not list individual connections with their acceleration status. The '-t' flag is not standard for this purpose. While cpview can show overall acceleration rates, it lacks the granularity to identify specific non-accelerated connections. The administrator needs per-connection data, which cpview does not offer.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.