CCSM Advanced VPN Troubleshooting Practice Question
A Check Point administrator needs to verify whether IPsec traffic from a specific remote peer is being decrypted and passed to the internal network. The administrator has access to the gateway's command line. Which command provides a real-time capture of packets on the gateway's external interface, showing both encrypted and decrypted traffic?
⚠ Common exam trap
Watch out — candidates often confuse packet capture tools: tcpdump sees only encrypted packets, while fw monitor provides visibility into decrypted traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
fw monitor -e 'accept host 203.0.113.5;'
fw monitor is a Check Point diagnostic tool that captures packets at several inspection points, including before encryption and after decryption. It can filter by host, showing both the encrypted and decrypted versions of the traffic. This makes it ideal for verifying that packets from a remote peer are decrypted and forwarded internally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
fw monitor -e 'accept host 203.0.113.5;'
Why this is correct
fw monitor captures packets at multiple points in the kernel, including before encryption (inbound) and after decryption (outbound). It shows both encrypted and decrypted traffic for the specified host, allowing the administrator to verify that packets are being decrypted and forwarded. The '-e' flag specifies a filter for the capture.
- ✗
tcpdump -i eth0 host 203.0.113.5
Why it's wrong here
tcpdump captures raw packets on the interface, but it only sees the encrypted ESP packets, not the decrypted payload. It cannot show whether decryption succeeded or what internal traffic looks like. While tcpdump is useful for seeing if packets arrive, it does not provide visibility into the decryption process.
- ✗
cpstat vpn
Why it's wrong here
cpstat vpn displays statistics about VPN tunnels, such as number of active tunnels and bytes encrypted/decrypted. It does not provide packet-level capture or show individual packets. While useful for monitoring, it cannot confirm that specific traffic from a peer is being decrypted and passed.
- ✗
vpn debug ikeon
Why it's wrong here
vpn debug ikeon enables IKE debugging, which logs Phase 1 and Phase 2 negotiations. It does not capture data packets or show decrypted traffic. This command is used for troubleshooting tunnel establishment, not for verifying data flow through an established tunnel.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.