During firewall kernel debug with fw ctl zdebug you received less information that expected. You noticed that a lot of messages were lost since the time the debug was started. What should you do to resolve this issue?
A. Redirect debug output to file; Use fw ctl debug -o ./debug.elg
B. Redirect debug output to file; Use fw ctl zdebug -o ./debug.elg
C. Increase debug buffer; Use fw ctl zdebug -buf 32768
D. Increase debug buffer; Use fw ctl debug -buf 32768
正解:D
質問 2:
What is correct about the Resource Advisor (RAD) service on the Security Gateways?
A. RAD has a kernel module that looks up the kernel cache, notifies client about hits and misses and forwards a-sync requests to RAD user space module which is responsible for online categorization
B. RAD functions completely in user space. The Pattern Matter (PM) module of the CMI looks up for URLs in the cache and if not found, contact the RAD process in user space to do online categorization
C. RAD is not a separate module, it is an integrated function of the W kernel module and does all operations in the kernel space
D. RAD is completely loaded as a kernel module that looks up URL in cache and if not found connects online for categorization. There is no user space involvement in this process
正解:A
質問 3:
What is the correct syntax to set all debug flags for Unified Policy related issues?
A. fw ctl debug -m fw all
B. fw ctl debug -m up all
C. fw ctl kdebug -m UP all
D. fw ctl debug -m UP all
正解:D
質問 4:
The Check Point Firewall Kernel is the core component of the Gaia operating system and an integral part of traffic inspection process. There are two procedures available for debugging the firewall kernel. Which procedure/command is used for detailed troubleshooting and needs more resources?
A. fw debug/kdebug
B. fw ctl debug/kdebug
C. fw ctl zdebug
D. fw debug/kdebug ctl
正解:B
質問 5:
What is the kernel process for Content Awareness that collects the data from the contexts received from the CMI and decides if the file is matched by a data type?
A. dlpda
B. dlpu
C. cntawmod
D. cntmgr
正解:C
質問 6:
If SmartLog is not active or failed to parse results from server, what commands can be run to re-enable the service?
A. smartlogstart and smartlogstop
B. smartlogstart and smartlogsetup
C. smartloginit and smartlogstop
D. smartlogrestart and smartlogstart
正解:A
質問 7:
An administrator receives reports about issues with log indexing and text searching regarding an existing Management Server. In trying to find a solution she wants to check if the process responsible for this feature is running correctly. What is true about the related process?
A. fwssd crashes can affect therefore not show in the list
B. fwm manaqes this database after initialization of the 1CA
C. solr is a child process of cpm
D. cpd needs to be restarted manual to show in the list
正解:C
Sakai -
前評判通り、丁寧な解説で読み進めやすかったです。
CheckPointの問題集156-586、12日間の学習で合格できました。