What is correct about the Resource Advisor (RAD) service on the Security Gateways?
Answer(s): D
The Resource Advisor (RAD) service on the Security Gateways is responsible for online categorization of URLs and resources for Application Control and Threat Prevention blades. RAD has two components: a kernel module and a user space module. The kernel module looks up the kernel cache for URLs and resources, notifies the client about hits and misses, and forwards asynchronous requests to the user space module. The user space module handles the communication with the Check Point online web service and updates the kernel cache with the results. RAD can operate in three modes: hold, background, and custom, depending on the configuration of the blades and the policy.
Check Point Processes and Daemons - Section: Security Gateway Software Blades and Features - Subsection: URL Filtering BladeSolved: Re: RAD's high utilization - Post by @PhoneBoyCheck Point Certified Troubleshooting Expert (CCTE) - Exam Topics - Module 5: Advanced Access Control
What file contains the RAD proxy settings?
Which Daemon should be debugged for HTTPS inspection related issues?
Answer(s): B
The WSTLSD daemon is responsible for handling HTTPS Inspection related issues on the Security Gateway. It performs SSL/TLS termination and re-encryption, certificate validation and generation,and URL categorization for HTTPS traffic1. The WSTLSD daemon can be debugged using the command wstlsd debug on TDERROR_ALL_ALL=52. The debug file is located in $FWDIR/log/wstlsd.elg2. The other daemons, such as FWD, HTTPD, and VPND, are not directly related to HTTPS Inspection, but rather to policy installation, web server, and VPN, respectively.
1: sk65144: HTTPS Inspection Architecture 2: sk83520: How to debug the WSTLSD daemon
When URL category is not found in the kernel cache, what action will GW do?
Answer(s): A
Post your Comments and Discuss Checkpoint 156-587 exam with other Community members:
hab Commented on June 25, 2025 question 40: The Content Awareness kernel process, specifically dlpda, is responsible for analyzing file content and identifying data types within Check Point's Content Awareness (CTNT) software blade Anonymous
hab Commented on June 25, 2025 question 36 - answer is D Anonymous
hab Commented on June 25, 2025 question 29 answer is B Anonymous
hab Commented on June 25, 2025 question 21 - only fw ctl zdebug automatically enables 1MB buffer - answer is B Anonymous
To protect our content from bots for real learners like you, we ask you to register for free. Sign in or sign up now to continue with the 156-587 material!