[Sep-2025] 156-836 Certification with Actual Questions from PracticeTorrent [Q39-Q60]

Share

[Sep-2025] 156-836 Certification with Actual Questions from PracticeTorrent

Updated 156-836 Dumps PDF - 156-836 Real Valid Brain Dumps With 90 Questions!


The CCME exam is designed to evaluate the skills and knowledge of security professionals who work with the Check Point Maestro platform. 156-836 exam covers a wide range of topics, including Maestro architecture, deployment, management, troubleshooting, and optimization. Candidates who pass the exam will be recognized as experts in the Maestro platform and will have the skills and knowledge needed to design, implement, and manage complex security infrastructures using this platform.


CheckPoint 156-836 is a certification exam for Check Point Certified Maestro Experts that focuses on R81 version. Check Point Certified Maestro Expert - R81 (CCME) certification validates an individual's knowledge and skills in managing and operating the Check Point Maestro. 156-836 exam is designed for professionals who want to demonstrate their expertise in managing complex network infrastructures, security policies, and security solutions using Check Point Maestro.

 

NEW QUESTION # 39
What is the max amount of Orchestrators in Dual-site setup?

  • A. 0
  • B. 4 per Security Group
  • C. 2 per Security Group
  • D. 1

Answer: B

Explanation:
Explanation
A Dual Site setup can have either two or four orchestrators, depending on the scenario. However, the maximum number of orchestrators per Security Group is four, regardless of the number of sites. This is because each Security Group can have up to two orchestrators on each site, and each site can have up to two orchestrators. Therefore, the maximum number of orchestrators in a Dual Site setup is four per Security Group.
References =
*Maestro Frequently Asked Questions (FAQ)
*Maestro Dual Site configuration with a direct connection through L2 switches
*Dual Site Single Maestro Hyperscale Orchestrator Cluster (Dual Site Single MHO Redundancy)


NEW QUESTION # 40
Do all MHOs need to be upgraded before starting the SGM upgrades?

  • A. During the upgrade process all SGMs should be upgraded before upgrading all of the MHOs.
  • B. MHOs do not need to be upgraded at all because Maestro supports the use of different versions between the MHOs and SGMs.
  • C. All MHOs must first be upgraded before starting the SGM upgrades However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHOs.
  • D. A minimum of one of the MHOs should be upgraded before starting the SGM upgrades. However, there is no requirement to upgrade all the SGMs during the same maintenancewindow as the MHO

Answer: C

Explanation:
This is the correct answer because it follows the upgrade order and procedure specified in the R81.10 and R81.
20 Administration Guides for Maestro environments. The MHOs are responsible for managing and synchronizing the SGMs, so they must be upgraded to the target version before the SGMs. However, the SGMs can be upgraded one by one or in batches, as long as they arecompatible with the MHOs. The upgrade process also supports Multi-Version Clustering, which allows different versions of SGMs to operate in the same Security Group with zero downtime.
References =
*Check Point R81.10 for Scalable Platforms - Check Point Software
*Check Point R81.20 for Scalable Platforms - Check Point Software
*CHECK POINT MAESTRO EXPERT


NEW QUESTION # 41
What does the lldpctl command do?

  • A. Show all devices discovered by LLDP protocol on uplink ports
  • B. Show all devices discovered by LLDP protocol on all ports
  • C. Show all devices discovered by LLDP protocol on downlink ports
  • D. Discover orchestrators

Answer: B

Explanation:
The lldpctl command is a tool to display information about the devices discovered by the Link Layer Discovery Protocol (LLDP) on all ports of the Maestro Orchestrator and the Security Group Members. LLDP is a protocol that enables devices to exchange information about their identity, capabilities, and configuration.
LLDP can help to discover the topology and connectivity of the Maestro environment.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.2: LLDP, page 4-9
*Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section:
LLDP, page 3-9


NEW QUESTION # 42
Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?

  • A. When dynamic routing protocols, such as BGP or OSPF are used.
  • B. When there is a heavy imbalance of traffic between the SGMs that are members of the same SG.
  • C. When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS.
  • D. When the SG is NATing a very high percentage of traffic passing through it.

Answer: A

Explanation:
Explanation
This is the correct answer because Layer 4 distribution is not recommended when dynamic routing protocols are used in Maestro. Layer 4 distribution is a feature that adds the source and/or destination ports to the distribution equation, which can improve the load balancing among the SGMs. However, it can also cause issues with the correction layer, which is a mechanism that ensures the packets are processed by the correct SGM. Dynamic routing protocols, such as BGP or OSPF, use specific ports to exchange routing information and establish neighbor relationships. If Layer 4 distribution is enabled, it can interfere with the routing protocol packets and cause routing instability or failures.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.4: Traffic Flow, page 2-20
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Traffic Distribution, page 2-8
*Layer 4 Distribution - Yes or No? - Check Point CheckMates
*Support, Support Requests, Training ... - Check Point Software


NEW QUESTION # 43
What is the Orchestrator?

  • A. Load balancer
  • B. Network Switch
  • C. Manager of compute and network resources, load balancer and network switch
  • D. None of above

Answer: C

Explanation:
Explanation
The Orchestrator is a Maestro component that manages the compute and network resources of the Security Group Modules (SGMs) in a Security Group. It also acts as a load balancer and a network switch, distributing traffic among the SGMs and connecting them to the customer's network infrastructure.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 41
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline


NEW QUESTION # 44
The ______________ command will allow users to update the specified file on all SGMs.

  • A. g_all"
  • B. g_update_conf_file
  • C. g_cat
  • D. sed

Answer: B

Explanation:
The g_update_conf_file command is a global command that allows users to update the specified file on all Security Group Members of the current Security Group. The command takes the file name and the parameter- value pair as arguments and updates the file accordingly. For example, g_update_conf_file fwkern.conf fwha_enable_arp=1 will add or modify the fwha_enable_arp parameter in the fwkern.conf file on all SGMs.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-12
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-10
*Maestro Commands for Security Groups - Check Point CheckMates


NEW QUESTION # 45
In a Maestro Dual Site environment, what is the definition of the term Active Site.

  • A. There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.
  • B. The Active Site is the site where the SMO Master exists.
  • C. The Active Site is the site currently handling the enforcement on traffic passing for a specific SG.Connections are synced within the SGMs in the Active Site.
  • D. The Active Site is the site that is not handling any traffic for the specific SG, but itsconnections are synced to its SGMs from the MHOs to be ready in the event of a failover.

Answer: C

Explanation:
Explanation
In a Maestro Dual Site environment, there are two sites that can host Security Group Members (SGMs) for each Security Group (SG). The Active Site is the one that is currently processing the traffic for a specific SG, while the Standby Site is the one that is ready to take over in case of a failover. The Active Site and the Standby Site can be different for different SGs, depending on the load balancing and failover policies. The Active Site and the Standby Site are synchronized by the Maestro Orchestrators (MHOs) using the Site-Sync port and VLANs.
References =
*Solved: Maestro dual site failover - Check Point CheckMates
*Maestro Dual Site configuration with a direct connection through L2 switches


NEW QUESTION # 46
When security policy is installed

  • A. The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non-SMO Master SGMs install the policy.
  • B. All SGMs receive the security policy and simultaneous policy installation occurs.
  • C. All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy.
  • D. The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other membersretrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy.

Answer: D

Explanation:
Explanation
This is the correct answer because it describes the security policy installation flow for a Maestro Security Group. The SMO Master is the Security Group Member that acts as the leader and the single point of contact for the Management Server. The SMO Master verifies the policy and installs it first, then notifies the other SGMs that a new policy is available. The other SGMs fetch the policy from the SMO Master and install it in parallel.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.3: Security Policy Installation, page 2-15
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Policy Installation, page 2-13
*Policy installation flow - Check Point Software


NEW QUESTION # 47
Which licenses should be issued for the Orchestrator?

  • A. No licenses are required for Orchestrator
  • B. The Orchestrator is considered a Management server, hence it's licensed the same way
  • C. The Orchestrator requires NGTX license
  • D. Depends on Software Blades enabled on connected appliances

Answer: A

Explanation:
Explanation
Orchestrators in many network environments do not require separate licenses, as they primarily function to manage and distribute network traffic.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 1: Introduction to Check Point Maestro, Lesson 1.2: Maestro Licensing, page 1-8
*Check Point R81 Maestro Administration Guide, Chapter 1: Introduction to Check Point Maestro, Section:
Maestro Licensing, page 1-6
*Activation of a Quantum Maestro Orchestrator - Check Point Software


NEW QUESTION # 48
What kinds of transceivers are supported on Orchestrator MHO-140?

  • A. SFP+, SFP28, QSFP
  • B. SFP, SFP+, QSFP, QSFP28
  • C. SFP, QSFP, QSFP28
  • D. SFP, SFP+, SFP28

Answer: D

Explanation:
Explanation
According to the Maestro Hyperscale Orchestrator Datasheet1, the Orchestrator MHO-140 supports the following transceiver types: SFP, SFP+, SFP28. These transceivers can be used for the management, uplink, and downlink ports of the Orchestrator. The SFP transceivers support 1 GbE, the SFP+ transceivers support 10 GbE, and the SFP28 transceivers support 25 GbE.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Maestro Hyperscale Orchestrator Datasheet - Check Point Software, page 2


NEW QUESTION # 49
What is one benefit of a Dual MHO environment?

  • A. Dual MHOs allow additional SGMs to be added to the SG.
  • B. Dual MHOs allow better synchronization to occur between SGMs.
  • C. Dual MHOs can be used to achieve increased scalability and redundancy.
    .
  • D. Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.

Answer: C

Explanation:
Explanation
One of the benefits of a Dual MHO environment is that it can provide both scalability and redundancy to the Maestro system. Scalability means that the system can handle more traffic and SGMs as the demand grows, and redundancy means that the system can survive the failure of one or more components without losing functionality or performance. Dual MHOs can achieve these benefits by distributing the load and the management tasks among two orchestrators, and by providing backup and failover mechanisms for each other.
References
*Maestro Expert (CCME) Course - Check Point Software, page 251
*CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 22
*Check Point Certified Maestro Expert (CCME) R81.X, page 23


NEW QUESTION # 50
Maestro allows running commands globally in Expert mode by using global prefixes, such as:

  • A. all
  • B. g_all
  • C. global
  • D. asg all

Answer: B

Explanation:
Explanation
The g_all prefix is used to run commands globally in Expert mode on all Security Group Members of the current Security Group. For example, g_all cpstop will stop the Check Point services on all SGMs. The other prefixes are not valid for global commands in Expert mode.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.3: Global Commands, page 4-11
*Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: Global Commands, page 4-9
*Global Expert Mode Commands - Check Point CheckMates


NEW QUESTION # 51
There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?

  • A. 100%/0%
  • B. 50%/50%
  • C. 33%/66%
  • D. 66%/33%

Answer: B

Explanation:
Explanation
The proportion of traffic distribution done by Orchestrator depends on the traffic distribution mode that is configured for the Security Group. There are three modes: Round Robin, Load Sharing, andActive/Standby1.
*Round Robin mode distributes the traffic equally among all the appliances in the Security Group, regardless of the number of downlinks they have. This mode is suitable for scenarios where all the appliances have similar performance and capacity. In this mode, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.
*Load Sharing mode distributes the traffic proportionally to the number of downlinks each appliance has. This mode is suitable for scenarios where the appliances have different performance and capacity. In this mode, the proportion of traffic distribution would be 33%/66% for two appliances with one and two downlinks respectively.
*Active/Standby mode distributes the traffic to only one appliance at a time, while the other appliances are in standby mode. This mode is suitable for scenarios where high availability is required. In this mode, the proportion of traffic distribution would be 100%/0% or 0%/100% for two appliances with one and two downlinks respectively, depending on which appliance is active.
Since the question does not specify the traffic distribution mode, the default mode is Round Robin2.
Therefore, the proportion of traffic distribution would be 50%/50% for two appliances with one and two downlinks respectively.


NEW QUESTION # 52
Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?

  • A. Mobile Access configuration files.
  • B. fwkern.conf files.
  • C. VPN configuration files
  • D. IPS configuration files

Answer: D

Explanation:
Explanation
References
*Maestro R80.30SP Jumbo Hotfix Accumulator, Section: Important Notes
*Check Point Maestro R80.30SP with Gaia 3.10, Section: Known Limitations
*Check Point SNMP MIB files, Section: Revision History


NEW QUESTION # 53
Is it possible to define distribution mode per interface?

  • A. No, only for the Security Group
  • B. Yes, for both uplink and downlink interfaces
  • C. Yes, only for uplink interfaces
  • D. Yes, only for downlink interfaces

Answer: B

Explanation:
Maestro allows you to define the distribution mode per interface, which determines how traffic is distributed among the Security Group Modules (SGMs) in a Security Group. You can configure the distribution mode for each interface individually, or use the default mode for all interfaces. The distribution mode can be set for both uplink and downlink interfaces.
References =
*Check Point Maestro R81.X Administration Guide, page 62, section "Distribution Mode" 1
*Check Point Maestro R81.X Getting Started Guide, page 25, section "Distribution Mode" 2
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.
checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm


NEW QUESTION # 54
For the MHO-175, which ports are Management ports?

  • A. Ports 1 - 4 are Management ports.
  • B. Ports 5 - 26 are Management ports.
  • C. Ports 27 - 47 are Management ports.
  • D. Ports 49 - 55 are Management ports.

Answer: A

Explanation:
Explanation
According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 -
47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751


NEW QUESTION # 55
What can be learned from the output of sx_api_ports_dump.py command?

  • A. Orchestrator port status
  • B. Information about backplane bonds
  • C. Information about downlink ports only
  • D. Information about Security Groups

Answer: B

Explanation:
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*[Maestro Expert (CCME) Course - Check Point Software], page 31
*[Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge], page 3


NEW QUESTION # 56
What type of cluster can a Security Group can be compared to?

  • A. Active / Standby
  • B. Load Sharing Active / Active
  • C. VSLS
  • D. Active / Backup

Answer: B

Explanation:
A Security Group can be compared to a Load Sharing Active / Active cluster because it consists of multiple Security Group Members that share the traffic load and provide high availability and scalability. Each Security Group Member is an active firewall that processes traffic according to the Security Group policy and synchronizes its state with other members. The Maestro Orchestrator acts as a load balancer that distributes the traffic among the Security Group Members based on their capacity and availability.
References
*Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 2: Maestro Security Groups, Lesson 2.1: Introduction to Security Groups, page 2-4
*Check Point R81 Maestro Administration Guide, Chapter 2: Maestro Security Groups, Section: Security Group Overview, page 2-3


NEW QUESTION # 57
For the MHO-175, which ports are Management ports?

  • A. Ports 1 - 4 are Management ports.
  • B. Ports 5 - 26 are Management ports.
  • C. Ports 27 - 47 are Management ports.
  • D. Ports 49 - 55 are Management ports.

Answer: A

Explanation:
According to the Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-175 document1, ports 1 - 4 are Management ports that are used to connect the MHO to the customer's management infrastructure, such as SmartConsole or SmartDomain Manager. Ports 5 - 26 are Uplink ports that are used to connect the MHO to the customer's network infrastructure, such as switches, routers, or firewalls. Ports 27 -
47 are Downlink ports that are used to connect the MHO to the Security Group Modules (SGMs) in the Security Group. Ports 49 - 55 are Backplane ports that are used to connect the MHO to another MHO in a Dual Orchestrator environment.
References:
*Maestro Expert (CCME) Course - Check Point Software, page 42
*Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, course outline3
*Port Mapping for the Check Point Maestro HyperScale Orchestrator MHO-1751


NEW QUESTION # 58
During an upgrade, Is Multi-Version Clustering (MVC) supported?

  • A. Maestro supports MVC or full connectivity upgrade as of R80.40.
  • B. No, Maestro does not support MVC.
  • C. Yes, MVC is supported as of R81 for Maestro.
  • D. No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.

Answer: A


NEW QUESTION # 59
In a dual MHO environment, MHO1 and MHO2 are connected to the SGM line cards in which way?

  • A. MHO1 and MHO2 are connected to the line cards in any order administrators see fit.
  • B. MHO1 and MHO2 are connected to the SGMs using the Sync cable.
  • C. MHO 1 is connected to the odd-numbered ports, while MHO2 is connected to even-numbered ports.
  • D. MHO 1 is connected to the even-numbered ports, while MHO2 is connected to odd-numbered ports.

Answer: D

Explanation:
Explanation
The correct way to connect MHO1 and MHO2 to the SGM line cards in a dual MHO environment is to use the even-numbered ports for MHO1 and the odd-numbered ports for MHO2. This is to ensure that each SGM has two downlinks to each MHO, and that the downlinks are balanced across the different NICs and links. This provides redundancy and high availability for the traffic flow between the SGMs and the MHOs.
References
*R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
*Maestro Expert (CCME) Course - Check Point Software, page 18
*Maestro Technical Training, Module 2: Maestro Security Groups and the Single Management Object, slide 16


NEW QUESTION # 60
......


To be eligible for the CCME certification exam, candidates must have a minimum of two years of experience in network security and must have completed the Check Point Certified Security Administrator (CCSA) and Check Point Certified Security Expert (CCSE) certifications. 156-836 exam consists of 90 multiple-choice questions and has a time limit of 90 minutes. The passing score for the exam is 70%. Upon passing the exam, candidates will be awarded the CCME certification, which is valid for two years. Check Point Certified Maestro Expert - R81 (CCME) certification can be renewed by passing a renewal exam or by completing continuing education requirements.

 

Pass Your 156-836 Exam Easily With 100% Exam Passing Guarantee: https://actual4test.practicetorrent.com/156-836-practice-exam-torrent.html