CCSM Advanced Firewall Troubleshooting Practice Question
A network engineer is investigating why a VoIP call is experiencing one-way audio. The engineer suspects that the firewall is not correctly handling the SIP signaling or RTP traffic. Which Check Point command would allow the engineer to inspect the SIP and RTP packets in real time, showing the inspection points they traverse?
⚠ Common exam trap
The trap here is relying on interface-level packet capture tools like tcpdump, which do not show the firewall's internal inspection points where modifications or drops occur.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
fw monitor -e "accept udp port(5060) or udp port(10000-20000);"
fw monitor is the primary tool for capturing packets at various inspection points within the firewall kernel. By filtering for SIP and RTP ports, the engineer can observe whether the signaling and media streams are passing through correctly, and at which point they might be dropped or altered. This real-time visibility is crucial for diagnosing one-way audio, which often results from asymmetric routing or incorrect handling of SIP/SDP information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
fw monitor -e "accept udp port(5060) or udp port(10000-20000);"
Why this is correct
fw monitor captures packets at multiple inspection points in the kernel, including pre-inbound, post-inbound, pre-outbound, and post-outbound. By filtering on SIP (UDP 5060) and RTP (UDP 10000-20000), the engineer can see if packets are being dropped or modified at specific points, which is essential for diagnosing one-way audio issues related to SIP signaling or RTP media flow.
- ✗
fw ctl zdebug drop
Why it's wrong here
fw ctl zdebug drop displays debug messages for packets that are dropped by the firewall, including the reason and the rule that caused the drop. While it can indicate if SIP or RTP packets are being dropped, it does not show the full path or the content of packets at different inspection points. It is more of a drop log than a real-time packet inspection tool, so it may not provide the detailed visibility needed to diagnose one-way audio.
- ✗
tcpdump -i any -n udp port 5060
Why it's wrong here
tcpdump captures packets at the interface level, but it does not show the internal inspection points of the firewall kernel. It can confirm if packets are arriving at or leaving the interface, but it cannot reveal if the firewall is modifying or dropping packets at specific inspection stages. Therefore, it is insufficient for troubleshooting one-way audio that may be caused by firewall inspection.
- ✗
cpstat fw -f blades
Why it's wrong here
cpstat fw -f blades shows the status and statistics of enabled software blades, such as VoIP, but it does not provide per-packet inspection details. It would indicate if the VoIP blade is active and processing traffic, but not why a specific call has one-way audio. Thus, it lacks the granularity needed for this troubleshooting scenario.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.