Courseiva

156-315.81.20 · domain

troubleshooting

Practise Check Point Certified Security Expert troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

210 questions38 easy104 medium68 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (210)

Click any question to see the full explanation, or start a practice session above.

1

An administrator is configuring a VPN community and needs to ensure that only specific subnets are encrypted. Which setting should be configured to restrict the traffic that enters the tunnel?

Medium
2

Before performing an R81.20 upgrade on a gateway, what is the best practice to verify that the current configuration is compatible?

Medium
3

An administrator is configuring Threat Extraction on a R81.20 Security Gateway. They want to ensure that files are sanitized and delivered quickly while maintaining security. Which TWO actions should they take? (Choose two.)

Hard
4

An administrator is troubleshooting a Check Point Security Gateway that is experiencing performance degradation. The administrator runs 'fwaccel stats -s' and notices a high number of 'Non-accelerated conns' with the reason 'P' (Policy). Which of the following is the most likely cause for this?

Medium
5

What is the consequence of having mismatched 'Cluster Mode' settings on two gateways intended to form a cluster?

Medium
6

An administrator is troubleshooting a performance issue and identifies that packet drops are occurring in the SecureXL layer. Which command should they use to troubleshoot packet drops specifically related to the acceleration layer?

Hard
7

How can an administrator monitor the effectiveness of the Threat Prevention blades over time?

Medium
8

A security administrator is deploying a new R81.20 Security Gateway in a high-traffic data center. The gateway has four physical interfaces: eth0 (management), eth1, eth2, and eth3 (all 10 Gbps). To optimize throughput and CPU utilization, the administrator wants to combine eth1, eth2, and eth3 into a single logical interface using 802.3ad Link Aggregation (LACP). After configuring the bond interface in Gaia, the administrator notices that traffic is not being distributed evenly across the member interfaces and overall throughput is lower than expected. Which of the following is the most likely cause?

Hard
9

Refer to the exhibit. A Security Administrator notices that the cluster is failing over unexpectedly. What is the most likely cause based on the output provided?

Hard
10

Which of the following is the most efficient way to debug SecureXL traffic drops?

Hard
11

Refer to the exhibit. An administrator is analyzing SecureXL performance and sees a high number of F2F (Firewall-to-Fastpath) packets. What is the most likely reason for this performance pattern?

Hard
12

A security engineer is asked to verify whether SecureXL is currently enabled on a Check Point R81 Security Gateway. Which command should the engineer use?

Easy
13

Refer to the exhibit. Why was 'invoice.pdf' blocked?

Hard
14

Which phase of the IKE negotiation establishes the secure, encrypted channel used for subsequent management and Phase 2 negotiation?

Medium
15

A security administrator manages a two-member ClusterXL High Availability cluster. The administrator wants to run a failover test during a maintenance window without unplugging any cables or stopping the cluster. Which action will cause the currently active member to relinquish its Active state and force the standby member to take over?

Medium
16

Which component of the Check Point Threat Prevention architecture is responsible for providing real-time, global threat intelligence updates to the security gateway?

Easy
17

A security administrator is troubleshooting a performance issue on an R81 Security Gateway. The administrator runs 'fwaccel stats -s' and observes that a large number of connections are being handled by the Firewall path instead of being accelerated. The administrator wants to identify which specific connections are not being accelerated. Which command should be used to view the acceleration status of active connections?

Medium
18

What is the primary difference between ClusterXL High Availability (HA) mode and Load Sharing (LS) mode?

Easy
19

A security administrator is configuring Threat Prevention profiles on a Check Point R81.20 Security Gateway. The administrator wants to ensure that the organization benefits from Check Point's recommended settings for Threat Emulation and Threat Extraction. Which two of the following are characteristics of the 'Recommended' Threat Prevention profile? (Choose two.)

Medium
20

A security administrator is configuring a Remote Access VPN with Endpoint Security VPN clients. The requirement is that all client traffic, including Internet-bound traffic, must be inspected by the gateway's Threat Prevention blades before reaching its destination. Which client configuration setting should the administrator enable?

Medium
21

An administrator is troubleshooting an Identity Awareness deployment where AD Query fails to resolve user identities for workstations located in a newly added branch office subnet. The Security Gateway can successfully ping the Domain Controllers in the branch office. What is the most likely cause of this communication failure?

Medium
22

A network engineer is reviewing the performance of a Check Point Security Gateway. The engineer runs the command 'fwaccel stats' and sees the following output: Accelerated: 100000, F2F: 5000, Total: 105000. The engineer wants to understand what the 'F2F' counter represents. Which of the following best describes the meaning of 'F2F' in this context?

Easy
23

An administrator wants to verify if SecureXL is handling the packet processing for a specific interface. Which command is best suited for this?

Medium
24

A remote access VPN client is failing to connect to the Security Gateway. The logs show 'IKE Phase 1 Main Mode failed to match proposal'. Which configuration component is the most likely culprit?

Medium
25

When would an administrator consider disabling SecureXL on a gateway?

Medium
26

An administrator is analyzing the performance of a Security Gateway with CoreXL and SecureXL enabled. The administrator notices that certain types of traffic, such as VoIP and streaming media, are not being accelerated by SecureXL. Which of the following is the most likely reason for this behavior?

Medium
27

Refer to the exhibit. What will happen to the ClusterXL HA member if 'eth2' is a monitored interface?

Hard
28

A company's Security Management Server manages 12 gateways. The administrator has created a Star VPN community named 'StarCommunity' and a Mesh VPN community named 'MeshCommunity'. Gateway A belongs to both communities. In the community properties, 'StarCommunity' is configured to use IKEv1 only, while 'MeshCommunity' is configured to use IKEv2 only. A new site-to-site tunnel is attempted between Gateway A and Gateway B, where Gateway B belongs only to 'MeshCommunity'. Which statement describes the IKE version negotiation for this tunnel?

Hard
29

A Security Gateway is configured with Identity Awareness using AD Query, and users authenticate to the domain normally. An administrator notices that identities for users who log on to workstations on a remote subnet are not appearing in the Identity Awareness database, while local subnet users are identified correctly. The domain controllers are reachable and audit logging is enabled. Which configuration item should the administrator verify first?

Hard
30

An administrator wants to ensure that a specific cluster member always takes priority during a failover. Which setting should be adjusted?

Medium
31

You are upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE 'In-Place Upgrade' method. After the upgrade, you notice the gateway is not communicating with the Management Server. Which file should you check first to identify potential SIC-related errors during the boot process?

Medium
32

An administrator needs to implement Identity Awareness in a large environment with multiple Active Directory domains. Which method ensures the most efficient identity retrieval without requiring client-side agent installations on every workstation?

Medium
33

When using the Identity Agent, what is the 'Shared User' feature used for?

Medium
34

A Check Point Security Gateway is experiencing high CPU utilization on a single core, while other cores are underutilized. CoreXL is enabled, and the administrator suspects that the traffic is not being distributed evenly across the CoreXL firewall instances. Which command should the administrator use to verify the distribution of connections across CoreXL instances?

Easy
35

Which component acts as the centralized repository for global threat intelligence in a Check Point deployment?

Easy
36

A security administrator is configuring a ClusterXL High Availability cluster and wants to verify that the cluster is in the correct mode. Which command should the administrator use to display the current ClusterXL mode and status?

Easy
37

During a Connectivity Upgrade of a cluster, what happens to the traffic when the first member (Member A) is being upgraded and is currently down?

Medium
38

An organization is deploying a large-scale Remote Access VPN. To optimize performance and reduce gateway load, what is the recommended approach for distributing traffic?

Medium
39

A security administrator configures a two-member ClusterXL High Availability cluster. The cluster works correctly, but during a maintenance window the administrator administratively detaches Member 1 by running 'clusterXL_admin down' on it. Shortly afterward, Member 2 becomes Active as expected. The administrator then runs 'clusterXL_admin up' on Member 1 to return it to service. Which statement describes the resulting state of the cluster?

Hard
40

Which THREE factors can cause a ClusterXL member to transition to a 'Down' state?

Hard
41

What is the primary benefit of using CoreXL on a Check Point Security Gateway?

Easy
42

An administrator wants to prioritize specific high-bandwidth traffic for acceleration. Which command can influence SecureXL to favor these flows?

Hard
43

An administrator is preparing to upgrade a Security Gateway from R80.40 to R81.20 using the CPUSE Web UI. Before initiating the upgrade, the administrator wants to ensure that all required packages are available and that the repository is up to date. Which action should the administrator take first?

Medium
44

An administrator is troubleshooting an Identity Awareness deployment where users authenticated through a Captive Portal are shown as unidentified on a different Security Gateway in the same distributed environment. The portal gateway correctly identifies the users, but the second gateway does not. Which action should the administrator take to allow the identity information to reach the second gateway?

Medium
45

A security administrator is deploying a new ClusterXL High Availability cluster with two members. The administrator needs to ensure that the cluster can properly synchronize state and perform failover. Which two actions are required to configure the synchronization network? (Choose two.)

Medium
46

A security administrator manages a two-member ClusterXL High Availability cluster running R81.10. The primary member fails and the secondary takes over. After the primary is repaired and rejoins, the administrator wants to verify which member is currently active and which is standby, and confirm that the failover completed cleanly. Which command should be run on either member to display the current cluster state and member roles?

Medium
47

An administrator is troubleshooting a performance degradation on a Check Point Security Gateway. The administrator suspects that SecureXL is not accelerating traffic as expected. Which two actions should the administrator take to verify and potentially resolve the issue? (Choose two.)

Hard
48

A security administrator is configuring Threat Prevention on a R81.20 Security Gateway. They enable Threat Emulation for incoming files and want to reduce the gateway's CPU load by having emulation performed by a dedicated appliance rather than the gateway itself. Which Check Point component should they deploy and configure to achieve this?

Medium
49

An administrator is deploying a new R81.20 Security Gateway using the Gaia First Time Configuration Wizard. The organization requires the gateway to obtain its IP address dynamically from the corporate DHCP server, but the administrator also needs to ensure the gateway can be reached at a predictable address for management. Which configuration should the administrator select during the wizard?

Medium
50

Which of the following describes the 'Threat Emulation' process correctly?

Easy
51

Which THREE parameters must be correctly configured when setting up an Active Directory Query identity source in SmartConsole? (Choose THREE)

Hard
52

A Check Point administrator is troubleshooting a Threat Emulation issue where a specific PDF file was not emulated, despite the Threat Prevention policy being configured to inspect PDFs. The log shows the file was allowed with the action 'Bypass' under Threat Emulation. The administrator verifies that the file is not password-protected and is under the maximum file size limit. What is the most likely reason for the bypass?

Hard
53

An administrator is configuring a VPN between a Check Point R81 Security Gateway and a third-party vendor's gateway. The third-party gateway uses a single IP address for both IKE and IPsec traffic, but the Check Point gateway is behind a NAT device that translates its public IP. The administrator wants to ensure the VPN tunnel establishes successfully. Which Check Point feature should be enabled on the Check Point gateway?

Hard
54

An administrator is deploying a Route-Based VPN between two Check Point R81 Security Gateways to support dynamic routing over the tunnel. After configuring the VPN community as a Route-Based VPN type, the administrator notices that traffic is not being encrypted. What is the most likely reason?

Medium
55

When configuring VRRP in a Check Point environment, what is the primary purpose of the Virtual Router ID (VRID)?

Medium
56

A Check Point administrator is configuring a Site-to-Site VPN between a Security Gateway and a third-party device using IKEv2. The third-party device requires a specific non-standard IKEv2 proposal. Where should the administrator define this custom proposal in SmartConsole?

Medium
57

When configuring a VPN Star Community, what is the primary role of the Center Gateway?

Medium
58

Which command is used to manually verify the synchronization status of the kernel tables between ClusterXL members?

Medium
59

A Check Point administrator is designing a hub-and-spoke VPN community where all branch offices must communicate through the central gateway. The administrator wants to ensure that traffic between spokes is routed via the hub without requiring direct tunnels. Which Check Point VPN community configuration achieves this?

Medium
60

An administrator configures a Threat Emulation profile to use 'Hold until scanned' mode for email traffic. Users report that inbound emails with PDF attachments are delayed by several minutes. What is the operational impact and architectural reason for this delay?

Medium
61

A security administrator is configuring a ClusterXL High Availability cluster. The administrator wants to verify that the cluster is using the correct synchronization interface and that the synchronization status is healthy. Which command should be used to display the synchronization status of the cluster members?

Medium
62

A firewall engineer is troubleshooting a CoreXL-enabled R81.20 gateway where a single firewall instance appears saturated while others are lightly loaded, even though SecureXL is active and the interface is configured for multi-queue. After reviewing fw ctl multik stat output, the engineer suspects that the distribution of connections across instances is uneven. Which factor most directly explains why CoreXL instance distribution can become skewed on this gateway?

Hard
63

A security administrator is setting up a VPN community between two Check Point Security Gateways using IKEv2. The administrator wants to ensure that the gateways authenticate each other using certificates. What must be configured on both gateways to enable certificate-based authentication?

Easy
64

Which action should you perform if a gateway fails to reach the management server after an upgrade?

Medium
65

Which THREE of the following are prerequisites for successful IKEv2 VPN establishment between a Check Point gateway and a third-party peer?

Medium
66

A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway. The environment uses a Windows Server 2019 domain controller, and the administrator wants the gateway to learn user identities by querying Windows Security Event Logs on the domain controller. The administrator has already configured the Identity Awareness blade and enabled AD Query in SmartConsole. Which additional configuration is required on the domain controller for AD Query to function?

Medium
67

An administrator has deployed Identity Awareness on a Security Gateway in AD Query mode. Users authenticate to the domain and their identities are learned successfully. However, a security policy rule that should permit access to an internal web server for the group 'Sales' is not matching. The administrator verifies that user 'jsmith' is a member of 'Sales' in Active Directory. The gateway's PDP shows the user identity, but the group is missing. What is the most likely cause?

Medium
68

A Security Administrator is configuring a new ClusterXL High Availability cluster with two members. The administrator wants to ensure that if the active member fails, the standby member takes over within the shortest possible time. Which ClusterXL mechanism is responsible for detecting a failure of the active member and triggering the failover?

Easy
69

A security administrator needs to ensure that the primary firewall node always regains the master role after a failover once it recovers. Which setting must be enabled?

Hard
70

Refer to the exhibit. What is the impact of having templates disabled on this gateway?

Hard
71

An administrator is tuning a Security Gateway with CoreXL enabled. The administrator notices that the 'fw_worker' processes are evenly distributed across cores, but overall throughput is lower than expected. After checking SecureXL, the administrator finds that a significant portion of traffic is not being accelerated. Which of the following is the most likely cause for this performance bottleneck?

Hard
72

What is the primary advantage of deploying Threat Emulation on a Security Gateway rather than just using endpoint-based protection?

Medium
73

A Check Point R81 gateway is using Threat Emulation. An administrator observes that a PDF file was emulated, and the log shows the verdict as 'Malicious'. However, the user was able to open the file without any warning. What is the most likely cause of this behavior?

Hard
74

A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway using the Identity Agents method. The organization wants to avoid installing additional client software on user workstations. Which Check Point component must be deployed to collect identities from the Active Directory domain controllers without requiring a full Identity Agent on each endpoint?

Medium
75

A security administrator is upgrading a Security Gateway from R80.40 to R81.20. After the upgrade, the administrator notices that the gateway's management connection is lost, and the gateway is not responding to pings. The administrator can access the gateway via the console. What is the most likely cause of this issue?

Medium
76

An administrator is deploying a new R81.20 Security Gateway cluster. The cluster will use ClusterXL in High Availability mode. The administrator wants to ensure that the cluster members can communicate with each other for synchronization and failover. Which network configuration is required for the synchronization interface?

Medium
77

Which of the following is a primary benefit of using a ClusterXL High Availability cluster?

Easy
78

Which TWO of the following are primary components of the Check Point SandBlast Threat Extraction solution?

Medium
79

Why should an administrator use a 'VPN Community' instead of manual IKE settings for site-to-site tunnels?

Medium
80

If an administrator executes 'fwaccel stats -s' and notes a low 'Accelerated conns' value relative to 'Total conns', what is the most likely cause?

Medium
81

A Check Point administrator is troubleshooting a Site-to-Site VPN where the tunnel is up, but traffic is not passing. The administrator runs 'vpn tu tlist' and sees the tunnel is established. However, 'fw monitor' shows packets being dropped with the error 'Encryption failure: no SA'. What is the most likely cause?

Hard
82

Which mechanism does Check Point use to allow VPN users to access resources using a single virtual IP address while hidden behind a gateway?

Hard
83

A security administrator is deploying a ClusterXL High Availability cluster and needs to ensure that the cluster will successfully synchronize kernel tables between members. Which two conditions are required for successful synchronization? (Choose two.)

Hard
84

An administrator is configuring a VPN community in a Check Point R81 environment to support multiple remote access clients using Office Mode. The administrator needs to ensure that Office Mode IP addresses are assigned correctly. Which two statements about Office Mode are true? (Choose two.)

Hard
85

A security engineer is configuring a ClusterXL High Availability cluster with two members. The cluster is operational, but the engineer wants to ensure that the Active member can detect a failure of the Standby member's synchronization path. Which interface should be configured as the synchronization network?

Hard
86

In which scenario should a security administrator choose to use 'Threat Extraction' over 'Threat Emulation'?

Medium
87

An administrator notices that users connecting through a Citrix XenApp published application server are all appearing as a single user in Identity Awareness access logs. What is the appropriate solution to resolve this limitation?

Medium
88

An administrator needs to allow VPN traffic to pass through a NAT device. Which feature must be enabled in the VPN community settings?

Medium
89

Which VPN feature should be used to protect a gateway from being overwhelmed by a flood of VPN connection attempts?

Medium
90

A security administrator notices that a user downloaded a file that was flagged as malicious by Threat Emulation, but the file was not blocked. The Threat Prevention policy shows that the Threat Emulation blade is set to 'Detect' mode for that user group. What is the most likely reason the file was not blocked?

Medium
91

An administrator is troubleshooting why Threat Emulation is not inspecting files downloaded over HTTPS. The gateway is configured with HTTPS Inspection, but files are still bypassing emulation. What is the most likely cause?

Hard
92

A security analyst is reviewing logs and sees multiple entries indicating that files were sent to Threat Emulation but the verdict was 'Malicious'. However, the files were not blocked. What is the most likely cause?

Easy
93

An administrator is preparing to upgrade a Security Gateway from R80.40 to R81.20 using CPUSE. Before starting the upgrade, the administrator wants to ensure that the gateway meets all prerequisites. Which two actions should the administrator perform? (Choose two.)

Medium
94

Refer to the exhibit. Which critical devices are being monitored by the cluster according to the output provided?

Medium
95

A Check Point administrator is analyzing logs and notices that a file was marked as 'Emulation Failed' in the Threat Emulation logs. The file was downloaded from a reputable website and is a common document format. The administrator wants to understand why this status occurred. Which of the following is the most likely cause for an 'Emulation Failed' status?

Hard
96

When upgrading a cluster, why is it recommended to upgrade the standby member first?

Medium
97

An administrator observes that the 'fw multik' process is consuming significantly more CPU than other processes. What is the most likely cause, and which feature configuration should be checked?

Medium
98

What is the result of a 'cphastop' command on a cluster member?

Medium
99

An organization requires that all incoming files be sanitized immediately to ensure business continuity. Which configuration setting is most appropriate?

Hard
100

When troubleshooting SecureXL, what does the 'fwaccel stats -t' command provide?

Medium
101

A Check Point Security Gateway uses Identity Awareness with AD Query. An administrator notices that user identities are not being recognized in firewall rules that reference Active Directory groups. The gateway can identify individual users, but group-based rules do not match. What is the most likely cause?

Hard
102

An administrator manages a three-member ClusterXL High Availability cluster on R81.10. During a maintenance window, the administrator needs to upgrade the standby member without causing a failover of the active member. The administrator plans to use the ClusterXL command-line tools. Which sequence of actions will allow the upgrade while preserving the active member's role?

Hard
103

Refer to the exhibit. What is the most common reason for an 'Authentication failed' error in an IKE Phase 1 negotiation?

Hard
104

An administrator is upgrading a Security Gateway using CPUSE. The pre-upgrade verification fails with the error 'Unsupported configuration: IPv6 is enabled on interface eth0'. What is the most appropriate action to resolve this?

Hard
105

An administrator is configuring Threat Emulation on a Check Point R81.20 Security Gateway. The administrator wants to ensure that files downloaded from the internet are inspected in a sandbox environment. Which of the following best describes the function of the Threat Emulation blade?

Easy
106

Refer to the exhibit. What is the most immediate risk to this cluster configuration?

Medium
107

A Check Point R81 gateway is configured with Threat Emulation. An administrator notices that a suspicious executable file downloaded via HTTP was not emulated. The log shows the action as 'Bypassed'. Which of the following is the most likely reason for this bypass?

Hard
108

What is the primary function of the 'fwaccel' module in the context of Check Point performance tuning?

Medium
109

An administrator needs to revert a Security Gateway to its exact state before a failed Jumbo Hotfix installation. Which recovery method is most appropriate if a 'Snapshot' was taken immediately before the update?

Hard
110

A Check Point Security Gateway is configured with CoreXL and SecureXL. The administrator notices that the 'fwaccel conns' command shows a large number of connections in the 'TEMPLATE' state. What is the most likely impact of this observation on the gateway's performance?

Hard
111

When upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE 'Upgrade' option rather than a 'Clean Install', which of the following remains preserved through the process?

Hard
112

A security administrator is setting up a VPN tunnel between two Check Point Security Gateways. The administrator wants to ensure that only specific services are allowed through the tunnel, while all other traffic is blocked. Which Check Point feature should be used to enforce this?

Easy
113

Which file type is most commonly targeted by Threat Extraction for active content removal?

Medium
114

An administrator is configuring a VPN tunnel between a Check Point Security Gateway and a third-party gateway. The third-party gateway uses a certificate signed by an internal CA. The administrator wants to use certificate-based authentication. Which step is required on the Check Point gateway to trust the third-party certificate?

Medium
115

Which mechanism ensures that a VPN tunnel remains active even if there is no traffic traversing it?

Medium
116

A Check Point administrator is configuring a VPN community and wants to ensure that only specific services are allowed through the VPN tunnel. The administrator wants to enforce this at the community level, affecting all gateways in the community. Which Check Point feature should be used?

Easy
117

Refer to the exhibit. An administrator is troubleshooting a file download issue. The CLI output confirms the file is blocked by Threat Emulation. What is the next logical step to investigate why this specific file was classified as malicious?

Hard
118

A security engineer configures a Threat Prevention profile with Threat Emulation enabled for PDF files. Users report that some PDF files are not being emulated, and the logs show the action 'Bypass' with the reason 'File size exceeds limit'. The engineer wants to ensure all PDFs are inspected without overloading the gateway. What is the most appropriate action?

Hard
119

Which Identity Awareness source is best suited for identifying users connecting from non-Windows devices like mobile phones or tablets?

Easy
120

When configuring CoreXL in a virtualized environment, what is a primary consideration for optimal performance?

Hard
121

An administrator is deploying Identity Awareness on a Security Gateway and wants to ensure that user identities are shared with other gateways in the same domain. The administrator configures the gateway as a PDP and enables Identity Sharing. Which statement describes the primary benefit of this configuration?

Easy
122

An administrator is configuring a ClusterXL High Availability cluster. Which requirement is mandatory for the synchronization network to ensure stateful failover?

Medium
123

An administrator is configuring a VPN community and observes that traffic is being dropped because the gateway doesn't recognize it as part of the VPN domain. How can this be resolved?

Hard
124

An administrator is configuring Identity Awareness on a Check Point Security Gateway. The organization wants to identify users based on their login to the Windows domain without installing any software on user computers. Which Identity Awareness method should be used?

Easy
125

A security administrator has enabled the Threat Extraction blade on a gateway and set it to extract and sanitize all PDF files delivered to users. A user reports that a PDF file now contains only text and images, but all interactive form fields are gone. The administrator checks the Threat Extraction log and sees the action 'Extract'. Which statement explains this behavior?

Hard
126

A security administrator has a two-member ClusterXL High Availability cluster running R81.20. After a power failure at the primary site, the secondary member becomes active. When the primary member reboots, the administrator wants it to automatically resume the active role. Which ClusterXL setting should be configured to achieve this behavior?

Medium
127

What is the primary benefit of using CPUSE for gateway upgrades in a production environment?

Easy
128

Refer to the exhibit. An administrator runs a CLI command to test policy evaluation for a specific client IP address. What does the output indicate about the gateway's evaluation process?

Hard
129

A security administrator notices that Threat Emulation is bypassing all files from a specific internal server. They want to ensure that files from this server are emulated. What is the most likely reason for the bypass, and how can it be resolved?

Medium
130

When designing a VPN for a mobile workforce using Check Point Endpoint Security VPN, an administrator wants to ensure that users are automatically assigned internal IP addresses from a specific pool. Which feature should be configured on the Security Gateway to provide this functionality?

Easy
131

An administrator is tuning a Check Point Security Gateway with CoreXL enabled. The administrator observes that the 'fwaccel stat' output shows that SecureXL is enabled, but the 'fwaccel stats' command indicates a high number of packets being handled by the 'PXL' path. Which of the following is the most likely reason for this behavior?

Medium
132

When utilizing Identity Awareness, what is the primary purpose of the 'Identity Logging' feature in the context of compliance and auditing?

Hard
133

A junior administrator needs to install the latest Jumbo Hotfix Accumulator on a standalone R81.20 Security Gateway. The gateway has outbound internet access. Which CPUSE component should be used to find and download the hotfix directly from Check Point's servers?

Easy
134

A network administrator is configuring Identity Awareness on a Security Gateway using AD Query. The administrator wants to ensure that user identities are correctly associated with IP addresses and that the gateway can resolve user group memberships for policy enforcement. Which component must be installed and configured on the Security Gateway to enable AD Query?

Easy
135

Which tool would an administrator use to deploy a pre-configured Gaia image that includes a specific Jumbo Hotfix to multiple new appliances simultaneously?

Medium
136

Why might a file be marked as 'Emulation Failed' in the logs?

Medium
137

An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Captive Portal method. The organization wants to ensure that users who authenticate via the portal are correctly identified and that their identities are used in security policies. Which two actions are necessary to enable this? (Choose two.)

Medium
138

A company wants to enforce identity-based rules for remote users who connect through a VPN. The administrator needs the Security Gateway to learn the user identity during the VPN authentication process without deploying additional agents. Which Identity Awareness feature should the administrator use?

Easy
139

An administrator configures Identity Awareness in a Check Point environment using Active Directory Query as the primary identity source. Users suddenly report that access policies based on user groups are randomly failing. What is the most likely root cause of this behavior?

Medium
140

An administrator notices that the Threat Emulation blade is not inspecting files downloaded over HTTP from a specific internal web server. The administrator confirms that the Threat Prevention policy includes the internal network as a protected scope. What is the most likely reason?

Easy
141

Refer to the exhibit. An administrator is trying to refresh group membership for a user manually using the CLI. What is the most likely cause of this error?

Hard
142

Which TWO of the following are required to implement Check Point VPN with third-party interoperability using generic IKE settings?

Hard
143

Which mechanism does ClusterXL use to prevent the 'split-brain' scenario in a High Availability deployment?

Medium
144

Refer to the exhibit. Why are both members showing as 'Active' in this Load Sharing configuration?

Medium
145

An administrator has a ClusterXL High Availability cluster with two members. The primary member fails, and the secondary member becomes active. After the primary member is repaired and rebooted, it does not become active again, even though it has a higher priority. The administrator checks and finds that the cluster is in High Availability mode and priorities are correctly set. What is the most likely reason for this behavior?

Hard
146

A company wants users on managed Windows laptops to be identified by the Security Gateway without deploying any additional endpoint software and without prompting for credentials. Users already authenticate to the Active Directory domain at logon. Which Identity Awareness component is required on the Security Gateway to achieve this?

Easy
147

You are preparing to upgrade a Security Gateway from R80.40 to R81.20 using CPUSE. Before initiating the upgrade, you want to ensure a smooth process. Which TWO actions are recommended best practices? (Choose two.)

Medium
148

Which command is used to verify the current status of SecureXL on a Check Point Security Gateway?

Easy
149

Refer to the exhibit. What is the cause of the 'Proxy ID mismatch' error in the VPN debug output?

Hard
150

A security administrator is troubleshooting a performance bottleneck on a Check Point Security Gateway. The administrator suspects that SecureXL is not accelerating a large portion of traffic. Which command should the administrator use to identify which traffic is being accelerated and which is not?

Hard
151

A Check Point administrator is deploying a ClusterXL High Availability cluster with two members. The administrator wants to ensure that the cluster can properly synchronize connection tables and maintain state during failover. Which two conditions must be met for successful synchronization? (Choose two.)

Hard
152

Which TWO of the following are benefits of using the Threat Prevention 'Recommended' profile over a custom profile?

Medium
153

A network engineer is reviewing the performance of a Check Point Security Gateway. The engineer wants to verify whether SecureXL is currently enabled and functioning. Which command provides a quick summary of SecureXL status, including whether it is enabled or disabled?

Easy
154

An administrator is troubleshooting Identity Awareness on a Security Gateway. Users authenticated previously, but now the gateway shows them as unidentified and all traffic falls to the default rule. The administrator confirms the gateway can reach the domain controllers and that the Identity Awareness blade is enabled. Which action should the administrator take first to verify whether the gateway is receiving identity information from the PDP?

Hard
155

An administrator is validating performance tuning on an R81.20 Security Gateway and wants to confirm that the CoreXL firewall instance count matches the planned design of one instance per firewall core. Which command provides the current number of CoreXL firewall instances and the cores assigned to them?

Medium
156

An administrator has configured Identity Awareness with AD Query. Users are identified correctly during the day, but every morning many users appear unidentified until they generate new domain logon events. The administrator wants to reduce this morning gap without switching acquisition methods. Which configuration should the administrator adjust?

Hard
157

An enterprise environment utilizes Identity Awareness with both AD Query and Browser-Based Authentication. Security administrators notice that contractor devices, which are not joined to the Active Directory domain, fail to acquire identity roles and are blocked by internal firewall rules. Which TWO methods can be implemented to correctly identify and authenticate these non-domain-joined contractor machines? (Choose TWO)

Hard
158

What is the primary benefit of using CoreXL on a multi-core Security Gateway?

Medium
159

A large enterprise is transitioning from a static Hub-and-Spoke VPN topology to a design that supports dynamic routing protocols to simplify management. They require the ability to run OSPF over their VPN tunnels to ensure automatic failover between multiple data centers. Which VPN design component is required to support this implementation on Check Point Gateways?

Medium
160

A security administrator is troubleshooting a Security Gateway that shows low throughput despite low CPU utilization. The administrator runs 'fwaccel stats -s' and observes that the 'Accelerated' packet count is extremely low, while 'F2F' (Forward to Firewall) packets are high. The administrator wants to understand why traffic is being sent to the Firewall path instead of being accelerated. Which of the following is the most likely reason for this behavior?

Medium
161

Refer to the exhibit. An administrator is troubleshooting a VPN tunnel that fails to initialize. Based on the debug output, what is the most likely cause?

Medium
162

What is the primary benefit of using High Availability (HA) mode over Load Sharing in a Check Point ClusterXL deployment?

Easy
163

Refer to the exhibit. An administrator notices that the cluster state is Active/Standby, but the sync status shows 'Problem'. What is the most likely consequence for the network traffic?

Hard
164

Which TWO authentication methods are natively supported by Check Point Identity Awareness for acquiring user identities without requiring a client-side agent installation? (Choose TWO)

Hard
165

An administrator is deploying a new R81.20 Security Gateway using the Gaia First Time Configuration Wizard. During the wizard, the administrator is prompted to select the 'Security Gateway' role. Which additional configuration is required to complete the deployment?

Easy
166

When configuring Threat Prevention, what is the significance of the 'Hold' vs. 'Background' emulation mode?

Medium
167

What is the primary benefit of using CPUSE (Check Point Upgrade Service Engine) for gateway upgrades compared to manual 'upgrade_export' and re-installation methods?

Easy
168

Which feature must be enabled on the network interface to allow SecureXL to distribute the processing load across multiple CPU cores effectively?

Medium
169

A Check Point security administrator is designing a route-based VPN between two R81.10 Security Gateways. The administrator wants to route dynamic routing protocols (OSPF) and multicast traffic through the VPN tunnel without defining encryption domains for each network. Which VPN community type should be used?

Medium
170

Which core software blade must be enabled on a Check Point Security Gateway to allow the creation of access control rules based on Active Directory user groups and computer objects?

Easy
171

A security administrator is troubleshooting an Identity Awareness issue where users are not being identified on a Security Gateway. The gateway is configured to use AD Query. The administrator runs the command 'pdp monitor all' and sees that no users are listed. Which of the following is the most likely cause?

Medium
172

What is the primary function of the 'VPN Domain' in a Check Point VPN community?

Medium
173

A junior administrator is learning how Check Point performance acceleration works on an R81.20 Security Gateway. The administrator wants to understand the role of SecureXL in the packet processing pipeline. Which statement best describes what SecureXL provides?

Easy
174

Refer to the exhibit. An administrator is troubleshooting a failed IKEv2 tunnel. What is the cause of the failure?

Hard
175

An administrator is reviewing Threat Prevention logs and notices that a file was marked as 'Benign' by Threat Emulation. The file was downloaded from a known malicious site but did not exhibit malicious behavior during emulation. What is the most likely reason for this verdict?

Easy
176

A Check Point administrator wants to ensure that files downloaded from the internet are inspected by Threat Emulation before reaching the user. Which blade must be enabled in the Threat Prevention policy to achieve this?

Easy
177

You are upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE Web UI. After selecting the upgrade package, you are prompted to choose between 'Upgrade' and 'Clean Install'. You want to preserve the existing configuration and installed hotfixes. Which option should you select?

Medium
178

What is the primary function of the 'ThreatCloud' service in the context of SandBlast Threat Prevention?

Medium
179

A Check Point administrator is configuring a Remote Access VPN using Endpoint Security VPN clients. The administrator wants to ensure that all client traffic, including Internet-bound traffic, is routed through the Security Gateway for inspection. Which option must be enabled in the VPN community or client configuration?

Easy
180

When configuring a VPN with multiple encryption domains, what is the most effective way to ensure traffic is correctly routed through the tunnel without complex policy rules?

Hard
181

You are preparing an R81.20 Security Gateway for an in-place upgrade using CPUSE. Corporate policy requires that you can roll back to the previous version if the upgrade fails. Which two actions must you take before starting the upgrade? (Choose two.)

Hard
182

Which TWO of the following are primary functions of the Threat Extraction blade in Check Point SandBlast? (Choose two)

Medium
183

Refer to the exhibit. An administrator is troubleshooting a site-to-site VPN tunnel. What is the most effective next step to resolve the 'No proposal found' error?

Medium
184

In ClusterXL High Availability mode, how many cluster members can be active for a specific virtual IP at any given time?

Easy
185

Which TWO requirements must be met before a Security Gateway can be successfully provisioned using the Zero Touch Provisioning (ZTP) service?

Medium
186

A security administrator is troubleshooting an Identity Awareness deployment that uses Identity Agents. Users report that they can access resources based on their identity, but sometimes they are prompted to authenticate again even though they are already logged in. The administrator checks the gateway and sees that the Identity Agent is running on the users' computers. What is a possible cause for the re-authentication prompts?

Medium
187

When deploying a new Security Gateway, what is the role of the 'First Time Wizard'?

Medium
188

An administrator notices that the Threat Extraction blade is converting incoming Microsoft Word documents into static PDF files, but users complain that embedded dynamic macros are completely missing from the converted documents. What is the cause of this behavior?

Medium
189

A security administrator needs to ensure that all encrypted traffic is inspected by the Threat Prevention blades. What is the mandatory requirement for this?

Medium
190

When deploying a Security Gateway in a public cloud environment like AWS or Azure, which method is typically used to handle the initial Gaia configuration?

Medium
191

A security administrator is configuring a Check Point R81 gateway running Threat Emulation and Threat Extraction blades. They want to ensure that files downloaded by users are inspected and, when necessary, sanitized before delivery. Which two of the following statements correctly describe the behavior of Threat Extraction? (Choose two.)

Medium
192

A security administrator notices that a Check Point Security Gateway with SecureXL enabled is still forwarding a portion of traffic through the Firewall Kernel path. The administrator runs 'fwaccel stats -s' and observes a high number of 'Accelerated conns' but also a substantial number of 'Non-accelerated conns'. The administrator wants to identify which traffic is not being accelerated. Which command should be used to view detailed information about non-accelerated connections?

Medium
193

Refer to the exhibit. Rule 5 allows the group 'Admins'. Why is the user 'admin' being blocked?

Hard
194

A security administrator is deploying a new ClusterXL High Availability cluster with two members. The administrator wants to ensure that if the standby member takes over as Active, it will automatically return to Standby once the original active member recovers. Which ClusterXL feature must be enabled?

Easy
195

Refer to the exhibit. An administrator sees this CPU distribution on a gateway. What is the most appropriate action?

Medium
196

When should an administrator consider changing the 'CoreXL instance' count?

Medium
197

A security administrator is troubleshooting a ClusterXL High Availability cluster where the standby member repeatedly fails to synchronize its kernel tables. The administrator suspects that the synchronization network is being blocked. Which interface type must be allowed to pass ClusterXL synchronization traffic for the cluster to function correctly?

Hard
198

An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Terminal Server Agent. The environment has multiple users logging into a Citrix terminal server. The administrator wants to ensure that each user's identity is correctly associated with their individual session, not just the terminal server's IP address. Which statement describes how the Terminal Server Agent accomplishes this?

Medium
199

Which TWO of the following scenarios would typically prevent a connection from being accelerated by SecureXL?

Hard
200

Which THREE of the following are valid methods for deploying the SandBlast Threat Emulation service?

Hard
201

A Security Gateway is being upgraded from R80.40 to R81.20 using CPUSE. The administrator wants to ensure that the upgrade can be rolled back if it fails. Which statement about CPUSE rollback is correct?

Hard
202

An administrator is implementing Identity Awareness using AD Query on a Security Gateway. Before identities can be learned from Active Directory, which two actions must be performed? (Choose two.)

Hard
203

An administrator notices that files are being successfully blocked by Threat Emulation, but the user is not seeing the block notification page. Which configuration must be verified to ensure the user receives the notification?

Medium
204

An administrator is deploying a new R81.20 Security Gateway and wants to reduce the attack surface by ensuring only required services are reachable on the management interface. After completing the First Time Configuration Wizard, which Gaia action best accomplishes this?

Medium
205

Which cryptographic function is primary in verifying the integrity of IKE packets during the negotiation?

Hard
206

A security administrator is troubleshooting a performance issue on an R81 Security Gateway (156-315.81.20) with SecureXL enabled. The administrator runs 'fwaccel stats' and observes a high number of packets in the 'P' (pass) path but also a significant number in the 'F' (forward) path. Which action should the administrator take to improve performance?

Medium
207

Refer to the exhibit. You are performing a cluster upgrade. You have successfully upgraded Member 2. What is the next logical step?

Medium
208

What happens if a user tries to download a file, and the Threat Emulation service is temporarily unreachable?

Hard
209

An administrator is configuring a ClusterXL High Availability (HA) solution. Which mechanism does the cluster use to ensure that the standby member can take over traffic seamlessly if the active member fails?

Medium
210

A security engineer configures Threat Emulation to inspect incoming archive files containing nested compressed directories. During testing, an archive containing six nested levels of ZIP files bypasses deep emulation inspection. What is the most likely configuration cause?

Hard

Frequently asked questions

What does the troubleshooting domain cover on the 156-315.81.20 exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 210 troubleshooting questions in the 156-315.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.