Checkpoint 156-585 Exam Questions
Check Point Certified Troubleshooting Expert (Page 11 )

Updated On: 19-Feb-2026

When running a debug with fw monitor, which parameter will create a more verbose output?

  1. -i
  2. -i
  3. -0
  4. -d

Answer(s): D



What is connect about the Resource Advisor (RAD) service on the Security Gateways?

  1. RAD has a kernel module that looks up the kernel cache, notifies client about hits and misses and forwards a-sync requests to RAD user space module which is responsible for online categorization
  2. RAD is completely loaded as a kernel module that looks up URL in cache and if not found connects online for categorization There is no user space involvement in this process
  3. RAD functions completely in user space The Pattern Matter (PM) module of the CMI looks up for URLs in the cache and if not found, contact the RAD process in user space to do online categorization
  4. RAD is not a separate module, it is an integrated function of the 'fw1 kernel module and does all operations in the kernel space

Answer(s): C



What are some measures you can take to prevent IPS false positives?

  1. Exclude problematic services from being protected by IPS (sip, H 323, etc )
  2. Use IPS only in Detect mode
  3. Use Recommended IPS profile
  4. Capture packets. Update the IPS database, and Back up custom IPS files

Answer(s): A



RAD is initiated when Application Control and URL Filtering blades are active on the Security Gateway What is the purpose of the following RAD configuration file SFWDIR/conf/rad_settings.C?

  1. This file contains the location information tor Application Control and/or URL Filtering entitlements
  2. This file contains the information on how the Security Gateway reaches the Security Managers RAD service for Application Control and URL Filtering
  3. This file contains RAD proxy settings
  4. This file contains all the host name settings for the online application detection engine

Answer(s): B



What is the main SecureXL database for tracking the acceleration status of traffic?

  1. cphwd_db
  2. cphwd_tmp1
  3. cphwd_dev_conn_table
  4. cphwd_dev_identity_table

Answer(s): D






Post your Comments and Discuss Checkpoint 156-585 exam dumps with other Community members:

Join the 156-585 Discussion