Courseiva

CCSM Advanced Firewall Troubleshooting Practice Question

A network engineer is investigating why a VoIP call is experiencing one-way audio. The engineer suspects that the firewall is not correctly handling the SIP signaling or RTP traffic. Which Check Point command would allow the engineer to inspect the SIP and RTP packets in real time, showing the inspection points they traverse?

⚠ Common exam trap

The trap here is relying on interface-level packet capture tools like tcpdump, which do not show the firewall's internal inspection points where modifications or drops occur.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fw monitor -e "accept udp port(5060) or udp port(10000-20000);"

fw monitor is the primary tool for capturing packets at various inspection points within the firewall kernel. By filtering for SIP and RTP ports, the engineer can observe whether the signaling and media streams are passing through correctly, and at which point they might be dropped or altered. This real-time visibility is crucial for diagnosing one-way audio, which often results from asymmetric routing or incorrect handling of SIP/SDP information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    fw monitor -e "accept udp port(5060) or udp port(10000-20000);"

    Why this is correct

    fw monitor captures packets at multiple inspection points in the kernel, including pre-inbound, post-inbound, pre-outbound, and post-outbound. By filtering on SIP (UDP 5060) and RTP (UDP 10000-20000), the engineer can see if packets are being dropped or modified at specific points, which is essential for diagnosing one-way audio issues related to SIP signaling or RTP media flow.

  • ✗

    fw ctl zdebug drop

    Why it's wrong here

    fw ctl zdebug drop displays debug messages for packets that are dropped by the firewall, including the reason and the rule that caused the drop. While it can indicate if SIP or RTP packets are being dropped, it does not show the full path or the content of packets at different inspection points. It is more of a drop log than a real-time packet inspection tool, so it may not provide the detailed visibility needed to diagnose one-way audio.

  • ✗

    tcpdump -i any -n udp port 5060

    Why it's wrong here

    tcpdump captures packets at the interface level, but it does not show the internal inspection points of the firewall kernel. It can confirm if packets are arriving at or leaving the interface, but it cannot reveal if the firewall is modifying or dropping packets at specific inspection stages. Therefore, it is insufficient for troubleshooting one-way audio that may be caused by firewall inspection.

  • ✗

    cpstat fw -f blades

    Why it's wrong here

    cpstat fw -f blades shows the status and statistics of enabled software blades, such as VoIP, but it does not provide per-packet inspection details. It would indicate if the VoIP blade is active and processing traffic, but not why a specific call has one-way audio. Thus, it lacks the granularity needed for this troubleshooting scenario.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.