
[Jun-2026] Get 100% Real Free CCME 156-836 Sample Questions
Accurate 156-836 Questions with Free and Fast Updates
To be eligible for the CCME certification exam, candidates must have a minimum of two years of experience in network security and must have completed the Check Point Certified Security Administrator (CCSA) and Check Point Certified Security Expert (CCSE) certifications. 156-836 exam consists of 90 multiple-choice questions and has a time limit of 90 minutes. The passing score for the exam is 70%. Upon passing the exam, candidates will be awarded the CCME certification, which is valid for two years. Check Point Certified Maestro Expert - R81 (CCME) certification can be renewed by passing a renewal exam or by completing continuing education requirements.
NEW QUESTION # 14
What is a downlink interface used for?
- A. To connect appliances to Orchestrators
- B. To connect in between Orchestrators
- C. To connect appliances to customer's infrastructure
- D. To connect Orchestrators to customer's infrastructure
Answer: A
Explanation:
A downlink interface is a physical or virtual interface that connects a security gateway to an orchestrator. It allows the security gateway to send and receive configuration updates, policy changes, and other data from the orchestrator.
References = [Check Point R81.10 for Scalable Platforms - Check Point Software], [Scalable Platforms (Maestro and Chassis) comparison between versions - Check Point Software], [Check Point R81.10 AI & ML Driven Threat Prevention and Security Management - Check Point Blog].
NEW QUESTION # 15
In a Maestro Dual Site environment, what is the definition of the term Active Site.
- A. The Active Site is the site that is not handling any traffic for the specific SG, but itsconnections are synced to its SGMs from the MHOs to be ready in the event of a failover.
- B. The Active Site is the site currently handling the enforcement on traffic passing for a specific SG.Connections are synced within the SGMs in the Active Site.
- C. The Active Site is the site where the SMO Master exists.
- D. There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.
Answer: B
Explanation:
Explanation
In a Maestro Dual Site environment, there are two sites that can host Security Group Members (SGMs) for each Security Group (SG). The Active Site is the one that is currently processing the traffic for a specific SG, while the Standby Site is the one that is ready to take over in case of a failover. The Active Site and the Standby Site can be different for different SGs, depending on the load balancing and failover policies. The Active Site and the Standby Site are synchronized by the Maestro Orchestrators (MHOs) using the Site-Sync port and VLANs.
References =
*Solved: Maestro dual site failover - Check Point CheckMates
*Maestro Dual Site configuration with a direct connection through L2 switches
NEW QUESTION # 16
What can be learned from the output of sx_api_ports_dump.py command?
- A. Information about Security Groups
- B. Orchestrator port status
- C. Information about backplane bonds
- D. Information about downlink ports only
Answer: C
Explanation:
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3
NEW QUESTION # 17
What is the maximum number of Appliances within Security group in Dual-Site configuration?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 18
Which command do you use to find bottlenecks in the system that are affecting performance, even functionality in some cases?
- A. asg monitor
- B. asg stat -v
- C. asg perf -v
- D. asg diag verify
Answer: C
Explanation:
The asg perf -v command is used to find bottlenecks in the system that are affecting performance, even functionality in some cases. The asg perf -v command displays the performance statistics of the Security Group Modules (SGMs) in the Security Group, such as throughput, packet rate, CPU utilization, memory usage, and more. The asg perf -v command also shows the distribution mode and the correction rate of each SGM, which can indicate potential issues with asymmetric routing or load balancing. The asg perf -v command can help identify which SGMs are overloaded, underutilized, or misconfigured, and provide insights for troubleshooting and optimization.
References =
*Check Point Maestro R81.X Administration Guide, page 67, section "asg perf" 1
*Check Point Maestro R81.X Getting Started Guide, page 29, section "asg perf" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 26
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.
checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm
2: https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%
20Maestro%20under%20the%20hood%202022.pptx
NEW QUESTION # 19
To display processes that are consuming excessive system resources, users should use the_____ command.
- A. asg_perf_hogs
- B. asg stat -v
- C. asg perf -v
- D. top
Answer: A
Explanation:
Explanation
The asg_perf_hogs command is a script that displays the processes that are consuming excessive system resources, such as CPU, memory, disk, and network, on the orchestrator and the appliances. It can help identify performance issues and bottlenecks in the Maestro environment.
References
*Software Provision and Performance hogs failed - Check Point CheckMates1
*CHECK POINT MAESTRO EXPERT, page 33
NEW QUESTION # 20
There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?
- A. All 10
- B. 0
- C. 1
- D. Between 2 and 4
Answer: D
Explanation:
Explanation
References =
*Check Point Maestro R81.X Administration Guide, page 64, section "Correction Layer" 1
*Check Point Maestro R81.X Getting Started Guide, page 26, section "Correction Layer" 2
*Check Point Maestro Under the Hood presentation by Lari Luoma, slide 23
*Check Point Maestro Frequently Asked Questions (FAQ), question 9
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frame
:
https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/maestro/1191/1/Check%20Mates%20M
:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=
NEW QUESTION # 21
When a VPN tunnel is formed with a Maestro SGM,
- A. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connectionand tunnel owner.
- B. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer.
- C. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets.
- D. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic.
Answer: B
Explanation:
Explanation
In scalable security environments, initial IKE (Internet Key Exchange) handling by a central orchestrator before distributing traffic for encryption is a common approach to maintain efficiency and security.
NEW QUESTION # 22
What command will be used for updating fwkern.conf file on all Appliances within Security Group?
- A. g_update_conf_file
- B. g_all update_conf_file
- C. vi
- D. g_update_kernel
Answer: A
NEW QUESTION # 23
What type of cluster can a Security Group can be compared to?
- A. Load Sharing Active / Active
- B. VSLS
- C. Active / Standby
- D. Active / Backup
Answer: A
Explanation:
Explanation
A Security Group can be compared to a Load Sharing Active / Active cluster because it consists of multiple Security Group Members that share the traffic load and provide high availability and scalability. Each Security Group Member is an active firewall that processes traffic according to the Security Group policy and synchronizes its state with other members. The Maestro Orchestrator acts as a load balancer that distributes the traffic among the Security Group Members based on their capacity and availability.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3
NEW QUESTION # 24
What will happen in case of NAT of the traffic passing through Management network?
- A. This traffic will pass with no inspection
- B. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances
- C. This traffic will not pass correction, since it will be dropped
- D. Orchestrator will disable NAT and traffic will pass with no issue
Answer: D
Explanation:
Explanation
According to the Check Point MAESTRO R80.20SP Administration Manual1, NAT is not supported on the management network. If you configure NAT on the management network, the Orchestrator will disable NAT and allow the traffic to pass without translation. This is to ensure that the management traffic can reach the Security Group members and the SmartConsole without any issues.
References
*Check Point MAESTRO R80.20SP Administration Manual, page 291
NEW QUESTION # 25
When security policy is installed
- A. All SGMs receive the security policy and simultaneous policy installation occurs.
- B. All SGMs receive the security policy and one by one performs an independent policy verification.
Then, all SGMs simultaneously install the policy. - C. The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.
- D. The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.
Answer: C
Explanation:
This is the correct answer because it describes the security policy installation flow for a Maestro Security Group. The SMO Master is the Security Group Member that acts as the leader and the single point of contact for the Management Server. The SMO Master verifies the policy and installs it first, then notifies the other SGMs that a new policy is available. The other SGMs fetch the policy from the SMO Master and install it in parallel.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.3: Security Policy Installation, page 2-15
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Policy Installation, page 2-13
*Policy installation flow - Check Point Software
NEW QUESTION # 26
The ______________ command will allow users to update the specified file on all SGMs.
- A. g_all"
- B. sed
- C. g_update_conf_file
- D. g_cat
Answer: C
Explanation:
The g_update_conf_file command is a global command that allows users to update the specified file on all Security Group Members of the current Security Group. The command takes the file name and the parameter- value pair as arguments and updates the file accordingly. For example, g_update_conf_file fwkern.conf fwha_enable_arp=1 will add or modify the fwha_enable_arp parameter in the fwkern.conf file on all SGMs.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-12
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-10
*Maestro Commands for Security Groups - Check Point CheckMates
NEW QUESTION # 27
What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?
- A. Out-of-band interfaces for access to Orchestrator itself
- B. 1Gbps connectivity for Security Groups
- C. Reserved for internal purposes. Not in use.
- D. Additional ports used as uplinks
Answer: A
Explanation:
The Management ports located on the Rear Panel of the Orchestrator MHO-140 are out-of-band interfaces that provide access to the Orchestrator itself for configuration and management purposes. They are not used for traffic distribution or connectivity to the Security Groups or the external networks. They are 1Gbps RJ-45 ports that can be connected to a switch or a router.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates2, page 4
NEW QUESTION # 28
What is HealthCheck Point?
- A. Performs a system health check and is meant to replace both a CPInfo and the health check script.
- B. Can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.
- C. Is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.
- D. Is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.
Answer: A
Explanation:
HealthCheck Point (HCP) is a tool designed to perform a comprehensive system health check for the Maestro environment. It is intended to replace both the CPInfo tool and traditional health check scripts by providing a streamlined way to assess the health of Maestro Orchestrators (MHOs) and Security Group Members (SGMs).
HCP evaluates system status, configuration, and potential issues, generating detailed reports for troubleshooting and maintenance.
Exact Extract:
"HealthCheck Point (HCP) performs a system health check and is meant to replace both a CPInfo and the health check script. It assesses the health of the Maestro environment, including MHOs and SGMs, by checking system status, configuration settings, and potential issues. HCP provides detailed reports to aid in troubleshooting and maintenance."
-Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using theCommand Line Interface and WebUI, Lesson 4.4: System Diagnostics, page 4-15
-Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: HealthCheck Point, page 4-12 Explanation of Options:
* A. Is a self-updatable suite of tools for MHOs...: Incorrect, as HCP is not limited to MHOs and does not focus on visualizing topology or event timelines. It is a general health check tool for the entire Maestro environment.
* B. Performs a system health check and is meant to replace both a CPInfo and the health check script:
Correct, as HCP's primary function is to perform system health checks, replacing CPInfo and health check scripts, as per the documentation.
* C. Can be used to let you visualize the Firewall topology...: Incorrect, as HCP does not provide visualization of firewall topology or live statistics like throughput and CPU utilization.
* D. Is a self-updatable suite of tools for SGMs...: Incorrect, as HCP is not exclusive to SGMs and does not include topology visualization or event timeline features.
References:
Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.4: System Diagnostics, page 4-15 Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: HealthCheck Point, page 4-12
NEW QUESTION # 29
What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?
- A. 1Gbps connectivity for Security Groups
- B. Two Out-of-band interfaces for access to Orchestrator itself
- C. Reserved for internal purposes. Not in use
- D. Out-of-band interface for access to Orchestrator itself and Serial Console connector
Answer: D
Explanation:
Explanation
The RJ-45 connectors located at the front panel of the Orchestrator MHO-170 are used for out-of-band management and serial console access. One of them is a 1Gbps RJ-45 port that provides an out-of-band interface for accessing the Orchestrator itself for configuration and management purposes. The other one is a RJ-45 serial console port that provides a command-line interface for initial setup and troubleshooting.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates, page 4
NEW QUESTION # 30
Do all MHOs need to be upgraded before starting the SGM upgrades?
- A. A minimum of one of the MHOs should be upgraded before starting the SGM upgrades. However, there is no requirement to upgrade all the SGMs during the same maintenancewindow as the MHO
- B. All MHOs must first be upgraded before starting the SGM upgrades However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHOs.
- C. During the upgrade process all SGMs should be upgraded before upgrading all of the MHOs.
- D. MHOs do not need to be upgraded at all because Maestro supports the use of different versions between the MHOs and SGMs.
Answer: B
Explanation:
This is the correct answer because it follows the upgrade order and procedure specified in the R81.10 and R81.
20 Administration Guides for Maestro environments. The MHOs are responsible for managing and synchronizing the SGMs, so they must be upgraded to the target version before the SGMs. However, the SGMs can be upgraded one by one or in batches, as long as they arecompatible with the MHOs. The upgrade process also supports Multi-Version Clustering, which allows different versions of SGMs to operate in the same Security Group with zero downtime.
References =
*Check Point R81.10 for Scalable Platforms - Check Point Software
*Check Point R81.20 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT
NEW QUESTION # 31
What is the Orchestrator?
- A. Manager of compute and network resources, load balancer and network switch
- B. Load balancer
- C. None of above
- D. Network Switch
Answer: A
Explanation:
Explanation
The Orchestrator is a Maestro component that manages the compute and network resources of the Security Group Modules (SGMs) in a Security Group. It also acts as a load balancer and a network switch, distributing traffic among the SGMs and connecting them to the customer's network infrastructure.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline
NEW QUESTION # 32
What command can be run to show which SGM is selected to receive traffic?
- A. asg monitor
- B. asg calc
- C. dxl calc
- D. g_tcpdump
Answer: B
Explanation:
The asg calc command is a tool to show which SGM is selected to receive traffic based on the distribution mode and the packet parameters. It takes the port number, the source IP, the destination IP, and optionally the source port and the destination port as arguments and returns the SGM ID and the hash value. For example, asg calc 1 10.0.0.1 20.0.0.2 1234 80 will show which SGM will receive the traffic from 10.0.0.1:1234 to
20.0.0.2:80 on port 1.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.1: asg calc, page 4-5
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: asg calc, page 4-5
*asg calc - Check Point Software
NEW QUESTION # 33
When working with Maestro, what is the difference between using Clish and gClish?
- A. Clish commands are for testing purposes only and cannot be saved, gClish commands apply to all SG members, by default.
- B. Clish commands apply to all UP SG members, by default. gClish commands apply to all SG members, by default.
- C. Clish commands apply only to a specific SG member. gClish commands apply to all UP SG members, by default.
- D. Clish commands are run on the SG members. gClish commands are run on the MHO and applied to all connected SG members in a specified group.
Answer: C
Explanation:
Explanation
This is the correct answer because it describes the difference between using Clish and gClish when working with Maestro. Clish is the Check Point command line shell that allows users to configure and manage the SG members individually. gClish is the global Clish that allows users to run commands on all UP SG members of the current Security Group at once. UP SG members are theones that are in the UP state and have the same policy installed as the SMO Master.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-11
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-9
*Global Expert Mode Commands - Check Point CheckMates
NEW QUESTION # 34
What can be learned from the output of sx_api_ports_dump.py command?
- A. Information about Security Groups
- B. Orchestrator port status
- C. Information about backplane bonds
- D. Information about downlink ports only
Answer: C
Explanation:
Explanation
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3
NEW QUESTION # 35
There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?
- A. 66%/33%
- B. 50%/50%
- C. 100%/0%
- D. 33%/66%
Answer: B
Explanation:
Explanation
The proportion of traffic distribution done by Orchestrator depends on the traffic distribution mode that is configured for the Security Group. There are three modes: Round Robin, Load Sharing, andActive/Standby1.
*Round Robin mode distributes the traffic equally among all the appliances in the Security Group, regardless of the number of downlinks they have. This mode is suitable for scenarios where all the appliances have similar performance and capacity. In this mode, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
*Load Sharing mode distributes the traffic proportionally to the number of downlinks each appliance has. This mode is suitable for scenarios where the appliances have different performance and capacity. In this mode, the proportion of traffic distribution would be 33%/66% for two appliances with one and two downlinks respectively.
*Active/Standby mode distributes the traffic to only one appliance at a time, while the other appliances are in standby mode. This mode is suitable for scenarios where high availability is required. In this mode, the proportion of traffic distribution would be 100%/0% or 0%/100% for two appliances with one and two downlinks respectively, depending on which appliance is active.
Since the question does not specify the traffic distribution mode, the default mode is Round Robin2.
Therefore, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
NEW QUESTION # 36
What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?
- A. 1Gbps connectivity for Security Groups
- B. Two Out-of-band interfaces for access to Orchestrator itself
- C. Reserved for internal purposes. Not in use
- D. Out-of-band interface for access to Orchestrator itself and Serial Console connector
Answer: D
Explanation:
The RJ-45 connectors located at the front panel of the Orchestrator MHO-170 are used for out-of-band management and serial console access. One of them is a 1Gbps RJ-45 port that provides an out-of-band interface for accessing the Orchestrator itself for configuration and management purposes. The other one is a RJ-45 serial console port that provides a command-line interface for initial setup and troubleshooting.
References
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
*Quantum Maestro Getting Started Guide - Check Point CheckMates, page 4
NEW QUESTION # 37
What is the max amount of Orchestrators in Dual-site setup?
- A. 2 per Security Group
- B. 0
- C. 4 per Security Group
- D. 1
Answer: C
Explanation:
Explanation
A Dual Site setup can have either two or four orchestrators, depending on the scenario. However, the maximum number of orchestrators per Security Group is four, regardless of the number of sites. This is because each Security Group can have up to two orchestrators on each site, and each site can have up to two orchestrators. Therefore, the maximum number of orchestrators in a Dual Site setup is four per Security Group.
References =
*Maestro Frequently Asked Questions (FAQ)
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)
NEW QUESTION # 38
......
CheckPoint 156-836 (Check Point Certified Maestro Expert - R81 (CCME)) Certification Exam is designed to test the knowledge and skills of IT professionals who work with Check Point technologies. Check Point Certified Maestro Expert - R81 (CCME) certification exam is intended for those who have already completed the Check Point Certified Maestro Architect (CCMA) certification exam and have gained a deeper understanding of advanced networking concepts, as well as troubleshooting and optimization techniques. The CCME exam is a comprehensive exam that covers a wide range of topics related to Check Point's Maestro technology, including deployment, configuration, and management.
The Check Point Certified Maestro Expert - R81 (CCME) exam covers a wide range of topics related to Maestro solution. This includes configuring and managing Maestro orchestrator and gateways, understanding Maestro architecture, deployment, and scaling, troubleshooting Maestro solutions, and managing Maestro security policies. 156-836 exam is designed to assess the candidate's understanding of the Maestro solution and their ability to implement various features and functionalities.
156-836 Study Guide Realistic Verified Dumps: https://2cram.actualtestsit.com/CheckPoint/156-836-exam-prep-dumps.html