Courseiva

CCSM Advanced Firewall Troubleshooting Practice Question

A Security Gateway is dropping packets due to a policy rule, but the administrator cannot find any matching rule in the rule base. Which action should be taken to identify the rule number causing the drop?

⚠ Common exam trap

The trap here is assuming that all drops are logged or that packet capture tools can reveal rule numbers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'fw ctl zdebug drop' to see the drop reason and rule number.

When a rule drops packets without logging, fw ctl zdebug drop provides real-time debug output including the rule number. This allows the administrator to identify the exact rule, even if it is not configured to log. It is the most direct method for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check the SmartLog for drop logs with the action 'Drop'.

    Why it's wrong here

    If the rule is not set to log, there will be no drop logs in SmartLog. The administrator already cannot find matching rule, implying logging might be disabled. So checking SmartLog would not help identify the rule number.

  • ✗

    Enable 'Log Implied Rules' in the Global Properties and reinstall the policy.

    Why it's wrong here

    Enabling 'Log Implied Rules' will log traffic matched by implied rules, but it does not help identify drops caused by explicit rules that are not matching. The issue is that a rule is dropping packets but not being logged, so this setting would not reveal the rule number.

  • ✗

    Use 'fw monitor' to capture the packets and analyze the inspection points.

    Why it's wrong here

    fw monitor shows packets at various inspection points but does not indicate which rule dropped them. It can show that packets are dropped, but not the rule number. It is not the right tool for identifying the specific rule causing drops.

  • ✓

    Run 'fw ctl zdebug drop' to see the drop reason and rule number.

    Why this is correct

    fw ctl zdebug drop prints kernel debug messages for dropped packets, including the rule number that caused the drop. This directly identifies the rule even if it is not logged, making it the correct action to find the missing rule.

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.