156-585 Sample Questions

156-585 Sample Questions & Answers

Kernel debugging and chain-module issues take the largest share, backed by CPInfo-based diagnostics, log and event analysis, CPView gateway monitoring, access-control debugging, identity-source problems, and site-to-site plus client VPN troubleshooting.

Launch the full 156-585 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Introduction to Advanced Troubleshooting · CPInfo and System Diagnostics

    To collect comprehensive diagnostic data from a Security Gateway, including configuration, process status, log files, and OS information, for submission to Check Point Support, which command should be executed in Expert mode?

    Show answer & explanation

    Correct answer: C

    The cpinfo utility is the standard Check Point tool for collecting a wide range of diagnostic information. The -z flag compresses the output into a .tgz file, and the -o flag specifies the output filename. This is the required format for submitting data to Check Point Support for analysis.

  2. Question 2Advanced

    Advanced Identity Awareness Troubleshooting · Identity Source Issues

    Case Study:

    A retail company uses an R81 cluster with the Identity Awareness blade enabled, using AD Query as the identity source. Recently, the IT department deployed a new fleet of Point-of-Sale (POS) terminals that run a custom Linux OS. The security team created an Access Role for these terminals based on their static IP addresses. However, store managers, who use Windows laptops and are part of the 'Store_Managers' AD group, report that they can no longer access the inventory server, which they could access before the POS deployment.

    Troubleshooting shows that the managers' traffic is being dropped by a rule that denies access from the POS terminals' Access Role to the inventory server. Logs indicate that when a manager logs in, their IP address is incorrectly being associated with the POS Access Role instead of their AD-based user identity. The POS terminals are on the same subnet as the managers' laptops.

    What is the most likely reason for this identity misidentification?

    Show answer & explanation

    Correct answer: C

    Check Point's Identity Awareness blade uses a priority order to resolve conflicts when multiple identity sources can claim the same IP address. In this scenario, because the POS terminals have a static IP-based Access Role, that identity source is likely prioritized higher than AD Query. When a manager's laptop gets an IP on that subnet, the gateway first matches it to the IP-based Access Role and stops processing further identity sources. To fix this, the priority of 'AD Query' must be moved above 'Access Roles' so that user-based identities are checked before network-based ones.

  3. Question 3Intermediate

    Advanced Management Server Troubleshooting · Log System Architecture

    You are debugging a slow database issue on a Security Management Server. You suspect the solr process, which handles log indexing, is consuming excessive resources. Which command would you use to safely restart ONLY the solr process without impacting other critical management services like cpm?

    Show answer & explanation

    Correct answer: D

    The solr process is a child process managed by cpm. The correct and safe way to restart it is by using the cpm_control.sh script with the -n solr flag. This ensures a graceful shutdown and restart of the indexing service without affecting the main cpm process or other services. Using cpstop; cpstart would restart all Check Point services, which is too disruptive. evstop; evstart controls the SmartEvent processes, not Solr. A kill -9 is an unsafe termination and should be avoided as cpm might not restart it correctly.

  4. Question 4AdvancedSelect 2

    Advanced Gateway Troubleshooting · Performance Tuning

    An administrator is troubleshooting an issue where traffic that should be accelerated by SecureXL is being processed by the Firewall (FW) path instead, causing high CPU. They check fwaccel stats -s and see that 'Accelerated conns' is very low. They suspect a specific NAT rule is causing traffic to be de-accelerated. Which of the following NAT configurations are known to prevent SecureXL acceleration? (Select TWO).

    Show answer & explanation

    Correct answers: B, D

    Certain complex NAT configurations cannot be handled by the SecureXL acceleration path and must be sent to the FW path (F2F - Fast to Firewall). Using a port range for Port Address Translation (PAT) is one such case. Another is a NAT rule where the translated destination port is 'Any' or a service group containing 'Any', as SecureXL cannot determine a specific port for the connection template. Standard Static NAT and Hide NAT behind the gateway are fully accelerable.

  5. Question 5Intermediate

    Advanced Firewall Kernel Debugging · Kernel Debug Procedures

    A kernel debug is being performed on a production gateway to trace a complex packet flow issue. The administrator needs to ensure the debug buffer is large enough to capture all relevant data without wrapping too quickly, but also wants to avoid consuming excessive kernel memory. What is the command to set the kernel debug buffer to 16384 KB?

    Show answer & explanation

    Correct answer: C

    The correct command to allocate kernel memory for the debug buffer is fw ctl debug -buf . The other options use incorrect syntax. fw ctl kdebug is used to read the buffer, not set its size. fw ctl debug --buf is not a valid flag, and fw ctl debug -s is not used for setting the buffer size.

  6. Question 6Advanced

    Advanced Management Server Troubleshooting · Database Management

    Case Study:

    A large enterprise has a multi-site deployment with a central R81 Security Management Server and numerous remote gateways. An administrator pushes a large policy package to all gateways. Most installations succeed, but one specific remote cluster reports 'Installation failed. Reason: Verification failed.' The administrator reviews the fwm.elg log file on the Management Server and finds messages indicating a 'syntax error' related to a newly added network object, but the object's configuration appears correct in SmartConsole.

    The administrator suspects a database inconsistency between what is shown in the GUI and what is stored in the PostgreSQL database. They decide to use the api status command on the management server, and the output shows that the 'API server' process is running, but the 'FWM' process is in a 'starting' state and repeatedly restarting. This confirms a problem with the management database preventing the FWM process from initializing correctly.

    What is the most appropriate next step to resolve this issue?

    Show answer & explanation

    Correct answer: C

    The evidence points to a recent change (the new network object) corrupting the database or causing an inconsistency that prevents the FWM process from starting. The most targeted and least disruptive solution is to use the Database Revision Control feature to revert the management database to the state it was in before the problematic object was added. This undoes the specific change causing the issue without requiring a full system restore, which is a much more drastic measure. Troubleshooting the remote cluster is pointless as the problem is on the Management Server.

  7. Question 7Intermediate

    Advanced Gateway Troubleshooting · fw monitor

    When using fw monitor to inspect traffic, the output shows a packet being dropped with the reason chain_fn_0: drop, rule 23. What does this message indicate?

    Show answer & explanation

    Correct answer: B

    The output chain_fn_0: drop, rule 23 from fw monitor indicates that the packet was explicitly dropped by the Access Control policy. The rule 23 part directly corresponds to the rule number in the security policy that caused the drop. chain_fn_0 is one of the functions in the firewall chain responsible for policy enforcement. Anti-Spoofing drops and kernel route drops would be indicated with different messages.

  8. Question 8Beginner

    Advanced Gateway Troubleshooting · Clustering

    True or False: The cphaprob stat command provides detailed statistics about the state of all configured cluster members, including their roles (e.g., Active, Standby), synchronization status, and the state of monitored pnotes (problem notifications).

    Show answer & explanation

    Correct answer: A

    True. The cphaprob stat command is the primary tool for viewing the real-time status of a ClusterXL cluster. It displays crucial information about each member's state, role, priority, and the status of critical devices (pnotes) that are monitored to determine the health of the cluster member.

  9. Question 9Intermediate

    Introduction to Advanced Troubleshooting · User Mode Debugging

    You need to debug an issue related to the Check Point daemon (cpd) on a Security Gateway, but you only want to see debug messages specifically related to SIC (Secure Internal Communication). Which command would accomplish this?

    Show answer & explanation

    Correct answer: D

    User-mode process debugging is typically done using the fw debug on syntax. For the cpd daemon, SIC-related debugging is controlled by the OPSEC_DEBUG_LEVEL flag. A level of 3 provides a high level of detail for SIC operations. TDERROR_ALL_ALL is a generic, high-level flag, while cpd_admin is not the correct utility for setting debug flags.

  10. Question 10Beginner

    Introduction to Advanced Troubleshooting · Linux-based Commands

    A hospital's R81 gateway is dropping HTTPS traffic to a critical patient records system. A kernel debug using fw ctl debug -m fw + conn drop was performed. The administrator needs to analyze the output file, kdebug.out, to find entries related to a specific source IP address, 10.100.50.15. Which grep command is the most efficient for finding all debug entries containing this IP address?

    Show answer & explanation

    Correct answer: A

    The standard grep command is used to search for patterns in text files. To find all lines containing the IP address '10.100.50.15' within the file 'kdebug.out', the simplest and most direct command is grep . The other options use incorrect syntax (fgrep is an alias but the -f flag expects a file of patterns) or are overly complex for this task.

Ready for the real thing?

The full 156-585 simulator has every exam-style question, timed mode, and instant scoring.