156-836 Sample Questions

156-836 Sample Questions & Answers

Maestro security groups and the single management object get top billing, alongside hyperscale basics, initial admin operations, traffic-flow distribution, diagnostics and troubleshooting tools, dual-orchestrator or dual-site setups, and upgrade procedures.

Launch the full 156-836 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Administrator Operations · File Distribution

    A new Security Group has been created in a Maestro R81.10 environment. An administrator needs to push a custom script to all SGMs in this new group to gather specific performance metrics. The script should not be sent to any other Security Groups. Which action is the most appropriate for this task?

    Show answer & explanation

    Correct answer: A

    There is no asg_file or asg_cp2all command in Quantum Maestro. The documented tool is asg_cp2blades [-b ] [-r] [-s] [ ], run in Gaia gClish or Expert mode on a Security Group Member. It copies a file from the current SGM to the other SGMs; with no -b (or -b all) it targets all SGMs of that Security Group on all Maestro Sites. Each Security Group is a separate gateway, so running it on Security Group the new group copies the file only to that group's SGMs. The command does not run on the Orchestrator, update_conf_file only edits parameters in configuration files such as fwkern.conf, and asg_config save only saves the gClish configuration.

  2. Question 2Beginner

    Administrator Operations · Initial Implementation

    A systems engineer is provisioning a new Maestro MHO-170 Orchestrator running R81.10. After connecting the management interface and assigning an IP address to Mgmt1 in Gaia Clish, the engineer is unable to access the WebUI (Gaia Portal). What is the most likely reason?

    Show answer & explanation

    Correct answer: B

    On Maestro Orchestrators R80.20SP - R81.20 there is no Gaia First Time Configuration Wizard, and Orchestrators do not need a license. The Getting Started Guide procedure is: connect to the MGMT port (default 192.168.1.1, admin/admin) or the console, activate the Orchestrator (enter "y"; this enables the Downlink and Uplink ports), then in Gaia Clish run set interface Mgmt1 ipv4-address mask-length , set interface Mgmt1 state on, set static-route default nexthop gateway address on and save config. Only then is Gaia Portal reachable at https:// . If the port is not set to state on (or no route/save), the WebUI is unreachable even though an IP was assigned.

  3. Question 3IntermediateSelect 3

    Dual Orchestrator Environment · Benefits of Dual Orchestrator

    Which of the following are key benefits of connecting two Orchestrators on the same site in a Check Point Maestro R81.10 environment? (Select THREE)

    Show answer & explanation

    Correct answers: B, D, E

    Two Orchestrators on the same site work together Active/Active: each Security Appliance is cabled to both Orchestrators, and Uplink and Management interfaces are configured as Bond interfaces across both, so the failure of one Orchestrator or one downlink cable does not stop traffic distribution. Orchestrators are upgraded or patched one at a time (a Jumbo Hotfix stops traffic processing only on the Orchestrator being updated). A second Orchestrator does not change SGM licensing (Orchestrators need no license), and Security Group management tasks run on the SMO, not on the Orchestrators.

    Two Orchestrators on the same site work together Active/Active: each Security Appliance is cabled to both Orchestrators, and Uplink and Management interfaces are configured as Bond interfaces across both, so the failure of one Orchestrator or one downlink cable does not stop traffic distribution. Orchestrators are upgraded or patched one at a time (a Jumbo Hotfix stops traffic processing only on the Orchestrator being updated). A second Orchestrator does not change SGM licensing (Orchestrators need no license), and Security Group management tasks run on the SMO, not on the Orchestrators.

    Two Orchestrators on the same site work together Active/Active: each Security Appliance is cabled to both Orchestrators, and Uplink and Management interfaces are configured as Bond interfaces across both, so the failure of one Orchestrator or one downlink cable does not stop traffic distribution. Orchestrators are upgraded or patched one at a time (a Jumbo Hotfix stops traffic processing only on the Orchestrator being updated). A second Orchestrator does not change SGM licensing (Orchestrators need no license), and Security Group management tasks run on the SMO, not on the Orchestrators.

  4. Question 4Intermediate

    System Diagnostics and Tracking Changes · Running Diagnostics on a Specific SGM

    An administrator sees in the asg stat -v output that SGM 1_3 of a Quantum Maestro R81.10 Security Group is DOWN while all other SGMs are ACTIVE. Before opening a support case, the administrator wants to run the built-in Maestro diagnostic test suite (System Health, Resources, SSD Health, Policy, Licenses, networking tests and more) and see a Passed/Failed summary with the failure reasons. Which Gaia gClish command should be used?

    Show answer & explanation

    Correct answer: A

    In Quantum Maestro R81.10, the built-in diagnostic tests are run with the "smo verifiers" commands in Gaia gClish on the Security Group. show smo verifiers report runs all tests (for example System Health = asg stat -v, Resources = asg resource, SSD Health = asg resource --ssd, Policy = asg policy verify -a, Licenses = asg_license_verifier -v, Bond, ARP Consistency, Core Dumps) and shows a Passed/Failed summary with a Reason column and the output file. show smo verifiers print shows the full output, and report name / report id run specific tests. There is no asg diag --chassis/--blades, g_asg_diag or asg test command.

  5. Question 5Advanced

    Troubleshooting · Using asg monitor

    An administrator runs asg monitor -v on a Maestro Security Group. What does the output show?

    Show answer & explanation

    Correct answer: A

    "asg monitor" continuously shows the same information as "asg stat", refreshed at an interval. The "-v" parameter shows only the System component status, and "-all" shows both the Security Group Member and System component status. The command does not trace packets, show distribution hashes, or capture traffic. To find which member handles a connection, use "asg search". To capture traffic, use "tcpdump -mcap".

  6. Question 6Intermediate

    System Diagnostics and Tracking Changes · Audit Trails

    A retail company has deployed a Maestro R81.10 Security Group to handle its e-commerce traffic. To comply with PCI DSS, they must record every successful Gaia configuration change that administrators make on the Security Group and send these records to their Check Point Management Server. Which feature provides this information?

    Show answer & explanation

    Correct answer: C

    The R81.10 Gaia System Logging settings "Send audit logs to management server upon successful configuration" (set syslog mgmtauditlogs on) and "Send audit logs to syslog upon successful configuration" (set syslog auditlog permanent) record every Gaia configuration change that authorized users make. With Remote System Logging you can also forward them to a syslog/SIEM server. On Scalable Platforms (Maestro), you configure this on the applicable Security Group. There is no show audit-trail command. cpstat shows status counters, the Expert mode shell history is per-user and not an audit record, and Threat Prevention logs record traffic, not administrator changes.

  7. Question 7Beginner

    Maestro Security Groups and the Single Management Object · Purpose of Multiple Security Groups

    What is the primary purpose of defining multiple Security Groups in a single Maestro deployment?

    Show answer & explanation

    Correct answer: D

    Multiple Security Groups allow for logical separation of the security gateways within the same Maestro chassis. Each Security Group acts as an independent firewall cluster, managed as its own Single Management Object (SMO). This is ideal for scenarios like multi-tenancy, separating perimeter and internal firewalls, or testing new policies on a dedicated group of SGMs without affecting production traffic on another group.

  8. Question 8Intermediate

    Upgrades · CPUSE Upgrade Process

    True or False: When performing a CPUSE upgrade on a Maestro Security Group, the upgrade package must be manually copied to each SGM before running the installer.

    Show answer & explanation

    Correct answer: B

    False. For a Security Group upgrade, the administrator transfers the CPUSE Offline package to the Security Group once, for example into /var/log/. In Gaia gClish, "installer import local " imports it; gClish commands apply to all Security Group Members. "installer verify member_ids all" checks all members. "installer upgrade member_ids " then upgrades one logical group of members at a time. The package does not have to be copied to each member manually.

  9. Question 9IntermediateSelect 2

    Dual Orchestrator Environment · Dual Orchestrator Configuration Requirements

    A Maestro R81.10 setup consists of two MHO-170 orchestrators on the same site and ten SGMs. The lead architect wants traffic to continue with minimal disruption if one orchestrator fails. Which of the following must be in place for this to work correctly? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Two Orchestrators on the same site work together Active/Active (there is no 'standby' Orchestrator). The Getting Started Guide states that only two Orchestrators of the same model can be connected (MBS-5038), and that to prevent traffic outage in an environment with two Orchestrators on a single site, each Uplink interface and each Management interface must be configured as a Bond interface spanning both Orchestrators. The Orchestrators need no license, and there is no floating SMO address to configure for Orchestrator redundancy.

    Two Orchestrators on the same site work together Active/Active (there is no 'standby' Orchestrator). The Getting Started Guide states that only two Orchestrators of the same model can be connected (MBS-5038), and that to prevent traffic outage in an environment with two Orchestrators on a single site, each Uplink interface and each Management interface must be configured as a Bond interface spanning both Orchestrators. The Orchestrators need no license, and there is no floating SMO address to configure for Orchestrator redundancy.

  10. Question 10Intermediate

    Traffic Flow · Layer 4 Distribution

    The output of show distribution l4-mode on a Maestro R81.10 Security Group shows 'L4 Distribution: Enabled'. In which scenario is keeping this setting most appropriate?

    Show answer & explanation

    Correct answer: D

    With Layer 4 distribution enabled (the default, together with Auto-Topology), the Orchestrator adds ports to the distribution decision: User mode uses Source Port + Destination IP, Network mode uses Source IP + Destination Port, and General mode uses Source IP, Source Port, Destination IP and Destination Port. Without it, User mode uses only the Destination IP, Network mode only the Source IP, and General mode Source + Destination IP. So all connections from many users hidden behind one NAT source IP would land on the same SGM. Keeping Layer 4 distribution enabled uses the varying source ports to spread those connections across SGMs, and each connection still stays on one SGM.

Ready for the real thing?

The full 156-836 simulator has every exam-style question, timed mode, and instant scoring.