Courseiva

CCSM Advanced Firewall Troubleshooting Practice Question

An administrator is investigating why a specific rule in the Security Policy is not logging any traffic, even though users report that connections to a critical server are being blocked. The rule is configured to log with 'Account' action. After checking the rulebase, the administrator confirms the rule is installed and active. Which command should be used to verify whether the rule is being matched and what action is being taken in the kernel?

⚠ Common exam trap

The trap here is relying on log viewers or packet captures to infer rule behavior, when only kernel-level rule debugging can definitively show which rule matched and what action was applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fw ctl zdebug + rule

To determine if a specific rule is being matched in the kernel, the 'fw ctl zdebug + rule' command is the appropriate diagnostic. It prints the rule number and action (accept, drop, reject) for each packet, directly showing whether the rule in question is evaluated and what happens. This is especially useful when logs are missing, as it can reveal that the rule is matched but logging is disabled or misconfigured, or that another rule is shadowing it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    cpstat fw -f blades

    Why it's wrong here

    cpstat with the blades filter reports on the status of software blades such as IPS, Application Control, and URL Filtering. It does not provide information about rule matching or logging behavior. While it can confirm that logging-related blades are active, it cannot tell whether a particular rule is being hit or why its log entries are absent. This makes it unsuitable for the troubleshooting task at hand.

  • ✗

    fw monitor -e 'accept;'

    Why it's wrong here

    fw monitor captures packets at multiple inspection points but does not show which rule matched or what action was taken. It can confirm that packets reach the firewall and are forwarded or dropped, but it cannot identify the specific rule responsible. Since the administrator needs to verify rule matching and action, this tool lacks the necessary granularity and would not explain the missing logs.

  • ✗

    fw log -f -t

    Why it's wrong here

    The fw log command displays existing log records in real time, but if the rule is not logging, there will be no entries to show. This command is reactive and only useful after logs are generated. It cannot reveal kernel-level rule matching decisions or explain the absence of logs. Therefore, it does not help determine whether the rule is being matched or what action is taken.

  • ✓

    fw ctl zdebug + rule

    Why this is correct

    This command activates kernel-level debugging for rule matching, printing the rule number and action for each packet that traverses the firewall. It is the definitive way to see if a specific rule is being evaluated and what verdict (accept, drop, reject) the kernel applies. In this scenario, where logging is absent, it can reveal whether the rule is matched but not logged due to a logging configuration issue, or whether a different rule is taking precedence.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.