156-315.81.20 Performance Tuning (SecureXL/CoreXL) Practice Question
A security administrator notices that a Check Point Security Gateway with SecureXL enabled is still forwarding a portion of traffic through the Firewall Kernel path. The administrator runs 'fwaccel stats -s' and observes a high number of 'Accelerated conns' but also a substantial number of 'Non-accelerated conns'. The administrator wants to identify which traffic is not being accelerated. Which command should be used to view detailed information about non-accelerated connections?
⚠ Common exam trap
The trap here is assuming that 'fwaccel stats -s' provides per-connection details, when it only shows summary counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
fwaccel conns -l
To identify which connections are not accelerated by SecureXL, the administrator must list the active connections and their acceleration status. The command 'fwaccel conns -l' provides a detailed list of connections, including those that are not accelerated, along with the reason. This allows the administrator to correlate specific traffic with non-acceleration causes, such as features that are incompatible with SecureXL. The other commands provide aggregate statistics or debug drops unrelated to acceleration status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
fwaccel conns -l
Why this is correct
The command 'fwaccel conns -l' lists all current connections, including those that are not accelerated, and provides details such as the source, destination, and the reason for non-acceleration. By examining this output, the administrator can pinpoint exactly which traffic is not being accelerated and why, enabling targeted troubleshooting. This is the correct tool for diagnosing specific connections that bypass SecureXL.
- ✗
fwaccel conns -s
Why it's wrong here
The command 'fwaccel conns -s' displays summary statistics for accelerated connections, not detailed information about non-accelerated ones. It provides counts of connections in various states but does not list the specific non-accelerated connections or the reasons they are not accelerated. To diagnose why traffic bypasses SecureXL, the administrator needs to see the actual connections and their properties, which this command does not provide.
- ✗
fw ctl zdebug drop
Why it's wrong here
'fw ctl zdebug drop' is used to debug dropped packets by the firewall, not to analyze accelerated versus non-accelerated connections. It provides information about packets that are dropped due to policy or other reasons, but it does not indicate whether a connection is accelerated or not. Using this command would not help the administrator understand why some connections are not being accelerated by SecureXL.
- ✗
fwaccel stats -s
Why it's wrong here
Running 'fwaccel stats -s' again would only re-display the same summary statistics that the administrator already observed. It shows aggregate counters such as accelerated and non-accelerated connections but does not list individual non-accelerated connections or the reasons for their exclusion. This command is useful for a high-level overview but insufficient for identifying specific traffic that bypasses SecureXL.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.