156-315.81.20 · domain
Gateway Deployment and Upgrades
This domain covers deploying and upgrading Check Point Security Gateways: CPUSE in-place upgrades and upgrade_export, Zero Touch Provisioning, and post-upgrade verification. Questions test whether you can choose the right upgrade method, meet provisioning prerequisites, and diagnose gateway-to-Management-Server communication failures after an upgrade.
Focused practice
Practice Gateway Deployment and Upgrades questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Gateway Deployment and Upgrades
Be able to select and run a CPUSE in-place upgrade or upgrade_export path, verify SIC and gateway-to-Management-Server communication afterward, and confirm ZTP prerequisites. The single most important thing: validate connectivity and SIC status after any upgrade before declaring success.
CPUSE In-Place Upgrade versus upgrade_export and fresh installation trade-offs
Diagnosing gateway-to-Management-Server communication failures after upgrade, including SIC and fwd.elg
Zero Touch Provisioning prerequisites: DHCP, internet access, and provisioning profile
Gateway deployment options: standalone versus distributed, and Gaia First Time Configuration Wizard
Watch out for
Common Gateway Deployment and Upgrades exam traps
- ▸Assuming CPUSE always preserves everything; snapshots and backups still matter before an in-place upgrade
- ▸Forgetting to verify SIC and Management reachability after upgrade, then blaming the upgrade itself
- ▸Treating ZTP as plug-and-play; it requires DHCP, internet connectivity, and a configured profile
Question index
All Gateway Deployment and Upgrades questions (28)
Click any question to see the full explanation, or start a practice session above.
Before performing an R81.20 upgrade on a gateway, what is the best practice to verify that the current configuration is compatible?
Medium2A security administrator is deploying a new R81.20 Security Gateway in a high-traffic data center. The gateway has four physical interfaces: eth0 (management), eth1, eth2, and eth3 (all 10 Gbps). To optimize throughput and CPU utilization, the administrator wants to combine eth1, eth2, and eth3 into a single logical interface using 802.3ad Link Aggregation (LACP). After configuring the bond interface in Gaia, the administrator notices that traffic is not being distributed evenly across the member interfaces and overall throughput is lower than expected. Which of the following is the most likely cause?
Hard3You are upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE 'In-Place Upgrade' method. After the upgrade, you notice the gateway is not communicating with the Management Server. Which file should you check first to identify potential SIC-related errors during the boot process?
Medium4During a Connectivity Upgrade of a cluster, what happens to the traffic when the first member (Member A) is being upgraded and is currently down?
Medium5An administrator is preparing to upgrade a Security Gateway from R80.40 to R81.20 using the CPUSE Web UI. Before initiating the upgrade, the administrator wants to ensure that all required packages are available and that the repository is up to date. Which action should the administrator take first?
Medium6An administrator is deploying a new R81.20 Security Gateway using the Gaia First Time Configuration Wizard. The organization requires the gateway to obtain its IP address dynamically from the corporate DHCP server, but the administrator also needs to ensure the gateway can be reached at a predictable address for management. Which configuration should the administrator select during the wizard?
Medium7Which action should you perform if a gateway fails to reach the management server after an upgrade?
Medium8A security administrator is upgrading a Security Gateway from R80.40 to R81.20. After the upgrade, the administrator notices that the gateway's management connection is lost, and the gateway is not responding to pings. The administrator can access the gateway via the console. What is the most likely cause of this issue?
Medium9An administrator is deploying a new R81.20 Security Gateway cluster. The cluster will use ClusterXL in High Availability mode. The administrator wants to ensure that the cluster members can communicate with each other for synchronization and failover. Which network configuration is required for the synchronization interface?
Medium10An administrator is preparing to upgrade a Security Gateway from R80.40 to R81.20 using CPUSE. Before starting the upgrade, the administrator wants to ensure that the gateway meets all prerequisites. Which two actions should the administrator perform? (Choose two.)
Medium11When upgrading a cluster, why is it recommended to upgrade the standby member first?
Medium12An administrator is upgrading a Security Gateway using CPUSE. The pre-upgrade verification fails with the error 'Unsupported configuration: IPv6 is enabled on interface eth0'. What is the most appropriate action to resolve this?
Hard13An administrator needs to revert a Security Gateway to its exact state before a failed Jumbo Hotfix installation. Which recovery method is most appropriate if a 'Snapshot' was taken immediately before the update?
Hard14When upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE 'Upgrade' option rather than a 'Clean Install', which of the following remains preserved through the process?
Hard15What is the primary benefit of using CPUSE for gateway upgrades in a production environment?
Easy16A junior administrator needs to install the latest Jumbo Hotfix Accumulator on a standalone R81.20 Security Gateway. The gateway has outbound internet access. Which CPUSE component should be used to find and download the hotfix directly from Check Point's servers?
Easy17Which tool would an administrator use to deploy a pre-configured Gaia image that includes a specific Jumbo Hotfix to multiple new appliances simultaneously?
Medium18You are preparing to upgrade a Security Gateway from R80.40 to R81.20 using CPUSE. Before initiating the upgrade, you want to ensure a smooth process. Which TWO actions are recommended best practices? (Choose two.)
Medium19An administrator is deploying a new R81.20 Security Gateway using the Gaia First Time Configuration Wizard. During the wizard, the administrator is prompted to select the 'Security Gateway' role. Which additional configuration is required to complete the deployment?
Easy20What is the primary benefit of using CPUSE (Check Point Upgrade Service Engine) for gateway upgrades compared to manual 'upgrade_export' and re-installation methods?
Easy21You are upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE Web UI. After selecting the upgrade package, you are prompted to choose between 'Upgrade' and 'Clean Install'. You want to preserve the existing configuration and installed hotfixes. Which option should you select?
Medium22You are preparing an R81.20 Security Gateway for an in-place upgrade using CPUSE. Corporate policy requires that you can roll back to the previous version if the upgrade fails. Which two actions must you take before starting the upgrade? (Choose two.)
Hard23Which TWO requirements must be met before a Security Gateway can be successfully provisioned using the Zero Touch Provisioning (ZTP) service?
Medium24When deploying a new Security Gateway, what is the role of the 'First Time Wizard'?
Medium25When deploying a Security Gateway in a public cloud environment like AWS or Azure, which method is typically used to handle the initial Gaia configuration?
Medium26A Security Gateway is being upgraded from R80.40 to R81.20 using CPUSE. The administrator wants to ensure that the upgrade can be rolled back if it fails. Which statement about CPUSE rollback is correct?
Hard27An administrator is deploying a new R81.20 Security Gateway and wants to reduce the attack surface by ensuring only required services are reachable on the management interface. After completing the First Time Configuration Wizard, which Gaia action best accomplishes this?
Medium28Refer to the exhibit. You are performing a cluster upgrade. You have successfully upgraded Member 2. What is the next logical step?
MediumOther domains
All 156-315.81.20 exam domains
Frequently asked questions
- What does the Gateway Deployment and Upgrades domain cover on the 156-315.81.20 exam?
- Be able to select and run a CPUSE in-place upgrade or upgrade_export path, verify SIC and gateway-to-Management-Server communication afterward, and confirm ZTP prerequisites. The single most important thing: validate connectivity and SIC status after any upgrade before declaring success.
- How many questions are in this domain?
- This page lists all 28 Gateway Deployment and Upgrades questions in the 156-315.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Gateway Deployment and Upgrades questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.