156-315.81.20 Performance Tuning (SecureXL/CoreXL) Practice Question
An administrator is tuning a Check Point Security Gateway with CoreXL enabled. The administrator observes that the 'fwaccel stat' output shows that SecureXL is enabled, but the 'fwaccel stats' command indicates a high number of packets being handled by the 'PXL' path. Which of the following is the most likely reason for this behavior?
⚠ Common exam trap
The trap here is assuming that a high PXL count indicates a misconfiguration of SecureXL or CoreXL, when it can simply be a result of traffic that inherently cannot be accelerated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The connections are subject to a Security Policy rule that requires the 'ftp' security server, forcing packets to the PXL path.
A high number of packets in the PXL path indicates that SecureXL is not accelerating those connections. This typically occurs when connections require deep inspection by the firewall kernel, such as when a security server (e.g., FTP) is involved. Other reasons like SecureXL being disabled or CoreXL instance count do not cause PXL packets. The presence of a security server forces packets to the PXL path, which is the most likely cause here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SecureXL is disabled on the interface, causing all packets to be sent to the PXL path.
Why it's wrong here
If SecureXL were disabled on the interface, the 'fwaccel stat' command would show that SecureXL is disabled, not enabled. The scenario states that SecureXL is enabled, so the interface is not disabled. Additionally, disabling SecureXL on an interface would result in all packets being processed by the firewall kernel, but the 'fwaccel stat' would reflect that. Therefore, this is not the reason for the high PXL count.
- ✗
The gateway is using a large number of CoreXL instances, which reduces the efficiency of SecureXL and increases PXL packets.
Why it's wrong here
The number of CoreXL instances does not directly affect the efficiency of SecureXL or cause an increase in PXL packets. SecureXL and CoreXL are complementary technologies; SecureXL accelerates connections, while CoreXL distributes the remaining processing across cores. A large number of CoreXL instances can improve performance by utilizing more cores, but it does not force packets to the PXL path. The PXL path is used based on connection characteristics, not the number of CoreXL instances.
- ✗
The traffic is being processed by a CoreXL firewall instance that is not optimized, leading to a fallback to the PXL path.
Why it's wrong here
CoreXL instances do not cause a fallback to the PXL path. The PXL path is used when SecureXL cannot accelerate a connection, such as when it requires deep inspection or a security server. CoreXL instances handle the firewall processing for connections that are not accelerated. If a CoreXL instance is not optimized, it might cause high CPU usage, but it does not directly increase PXL packets. The PXL path is a result of SecureXL decisions, not CoreXL load.
- ✓
The connections are subject to a Security Policy rule that requires the 'ftp' security server, forcing packets to the PXL path.
Why this is correct
The 'ftp' security server is a resource that inspects FTP traffic, which cannot be accelerated by SecureXL. When a connection requires a security server, the packets are sent to the PXL path for deep inspection. This results in a high number of PXL packets. Since SecureXL is enabled but the traffic requires a resource, the PXL count will be high. This is a common scenario when FTP or other dynamic protocols are used, and it is the most likely reason given the information.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.