Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

A Check Point administrator needs to verify whether IPsec traffic from a specific remote peer is being decrypted and passed to the internal network. The administrator has access to the gateway's command line. Which command provides a real-time capture of packets on the gateway's external interface, showing both encrypted and decrypted traffic?

⚠ Common exam trap

Watch out — candidates often confuse packet capture tools: tcpdump sees only encrypted packets, while fw monitor provides visibility into decrypted traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fw monitor -e 'accept host 203.0.113.5;'

fw monitor is a Check Point diagnostic tool that captures packets at several inspection points, including before encryption and after decryption. It can filter by host, showing both the encrypted and decrypted versions of the traffic. This makes it ideal for verifying that packets from a remote peer are decrypted and forwarded internally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    fw monitor -e 'accept host 203.0.113.5;'

    Why this is correct

    fw monitor captures packets at multiple points in the kernel, including before encryption (inbound) and after decryption (outbound). It shows both encrypted and decrypted traffic for the specified host, allowing the administrator to verify that packets are being decrypted and forwarded. The '-e' flag specifies a filter for the capture.

  • ✗

    tcpdump -i eth0 host 203.0.113.5

    Why it's wrong here

    tcpdump captures raw packets on the interface, but it only sees the encrypted ESP packets, not the decrypted payload. It cannot show whether decryption succeeded or what internal traffic looks like. While tcpdump is useful for seeing if packets arrive, it does not provide visibility into the decryption process.

  • ✗

    cpstat vpn

    Why it's wrong here

    cpstat vpn displays statistics about VPN tunnels, such as number of active tunnels and bytes encrypted/decrypted. It does not provide packet-level capture or show individual packets. While useful for monitoring, it cannot confirm that specific traffic from a peer is being decrypted and passed.

  • ✗

    vpn debug ikeon

    Why it's wrong here

    vpn debug ikeon enables IKE debugging, which logs Phase 1 and Phase 2 negotiations. It does not capture data packets or show decrypted traffic. This command is used for troubleshooting tunnel establishment, not for verifying data flow through an established tunnel.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.