Courseiva

156-315.81.20 Gateway Deployment and Upgrades Practice Question

You are upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE 'In-Place Upgrade' method. After the upgrade, you notice the gateway is not communicating with the Management Server. Which file should you check first to identify potential SIC-related errors during the boot process?

⚠ Common exam trap

Candidates frequently look at general system logs or firewall traffic logs instead of daemon-specific files like cpd.elg which handle secure internal communication processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$FWDIR/log/cpd.elg

Checking the cpd.elg file is critical because it captures the Check Point Daemon logs, which document the secure communication initialization process. During an upgrade, SIC certificates or trust relationships can occasionally fail to re-initialize due to connectivity issues or synchronization mismatches. By examining these logs, an administrator can quickly pinpoint whether the issue stems from a certificate expiration, an incorrect IP address resolution, or a failure in the initial handshake process between the gateway and management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    $FWDIR/log/fw.log

    Why it's wrong here

    This file contains logs related to packet inspection and firewall policy enforcement. While it tracks traffic, it does not log the low-level Secure Internal Communication handshakes that occur between the gateway and the management server, making it ineffective for debugging initial boot-time SIC establishment issues after a version upgrade.

  • ✓

    $FWDIR/log/cpd.elg

    Why this is correct

    The cpd daemon is responsible for managing internal communications and system processes. Examining this log file is the standard procedure for identifying SIC failures, as it records the detailed negotiation steps, certificate validation results, and connectivity attempts that occur specifically when the gateway attempts to re-establish trust with management.

  • ✗

    /var/log/messages

    Why it's wrong here

    This is a general Linux system log file used for kernel events and hardware-level reporting. While it might show hardware initialization errors, it lacks the specialized Check Point-specific context required to troubleshoot SIC communication, which is managed within the proprietary application layer of the gateway's software architecture.

  • ✗

    $FWDIR/log/fwm.log

    Why it's wrong here

    The fwm process runs exclusively on the Security Management Server and handles the policy server and GUI client requests. Since the gateway does not run the fwm process, this file does not exist on the gateway, and checking for it will yield no results for your connectivity troubleshooting efforts.

About these practice questions

This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.