156-315.81.20 ClusterXL and VRRP High Availability Practice Question
What is the result of a 'cphastop' command on a cluster member?
⚠ Common exam trap
Candidates often think 'cphastop' is a safe way to pause traffic. They fail to realize it forces the node to 'Down' and immediately shifts all load.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It forces the member to a DOWN state and stops cluster traffic processing.
The 'cphastop' command disables the ClusterXL kernel module on that specific member. This effectively removes the node from the cluster, causing all traffic to fail over to the remaining node(s). This command is useful during maintenance, but administrators must exercise caution as it immediately interrupts local traffic processing and forces the peer to assume the full load.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It initiates a graceful reboot of the cluster member.
Why it's wrong here
This command does not reboot the system. It only stops the ClusterXL kernel module's participation in the cluster. The operating system continues to run, and the node remains powered on, but it will no longer process traffic as a member of the high-availability cluster configuration.
- ✓
It forces the member to a DOWN state and stops cluster traffic processing.
Why this is correct
The command instructs the kernel to cease cluster-related activities, effectively taking the node offline for the cluster. The peer node will detect this state change through the heartbeat mechanism and immediately take over all traffic, ensuring that the service remains available despite the local node being effectively disabled.
- ✗
It enables the standby mode for the member indefinitely.
Why it's wrong here
Standby mode is a dynamic state managed by the cluster. 'cphastop' completely removes the member from the cluster's operational logic. It does not put the member into a 'standby' state; rather, it makes the member entirely unavailable to the cluster until the kernel module is restarted with 'cphastart'.
- ✗
It clears the connection table and restarts the firewall service.
Why it's wrong here
While stopping the module may result in the loss of current connection state, the command itself is not a firewall service restart or a connection table clear command. It is specific to the cluster module, and the firewall service behavior is separate from the cluster-level status changes.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.