What is the purpose of interface bonding?
A bond interface can be configured for high availability redundancy.
A bond interface is used for passing synchronization traffic between the SGMs.
For load sharing which increases connection throughput above that which is possible using one physical interface.
A bond interface can be configured for high availability redundancy or for load sharing which increases connection throughput above that which is possible using one physical interface.
After you import the R81.10 software package, what do you use to verify that it is possible to upgrade an MHO or SG?
Run HCP. One of the tests will list upgrade eligibility status for the MHO or SG.
Run the Pre-Upgrade Verifier to make sure it is possible to upgrade
Nothing. CPUSE will run a verification during the upgrade process to ensure the package is compatible.
The package is verified during the import process and a warning or error will be displayed at that time.
The Pre-Upgrade Verifier is a tool that checks the compatibility and readiness of the Maestro environment for the upgrade process. It verifies the current version, the target version, the hardware requirements, the configuration settings, and the license validity of the Maestro Orchestrators and the Security Groups. It also identifies any potential issues or risks that might affect the upgrade and provides recommendations on how to resolve them. The Pre-Upgrade Verifier should be run before importing the R81.10 software package and before performing the actual upgrade.
References =
•Check Point R81.10 for Scalable Platforms - Check Point Software
•CHECK POINT MAESTRO EXPERT
What will happen in case of NAT of the traffic passing through Management network?
This traffic will not pass correction, since it will be dropped
Orchestrator will disable NAT and traffic will pass with no issue
Since Management traffic is always going to SMO, it will take a care for Correction Layer and will re-distribute traffic to other Appliances
This traffic will pass with no inspection
According to the Check Point MAESTRO R80.20SP Administration Manual1, NAT is not supported on the management network. If you configure NAT on the management network, the Orchestrator will disable NAT and allow the traffic to pass without translation. This is to ensure that the management traffic can reach the Security Group members and the SmartConsole without any issues.
References
•Check Point MAESTRO R80.20SP Administration Manual, page 291
What kinds of transceivers are supported on Orchestrator MHO-140?
SFP, QSFP, QSFP28
SFP+, SFP28, QSFP
SFP, SFP+, SFP28
SFP, SFP+, QSFP, QSFP28
The Maestro Hyperscale Orchestrator MHO-140 supports a variety of transceivers to provide high-speed and high-density connectivity. Specifically, it supports SFP, SFP+, QSFP, and QSFP28 transceivers, which cater to different port speeds and connectivity requirements in the Maestro environment.
Exact Extract:
“The Orchestrator MHO-140 supports SFP, SFP+, QSFP, and QSFP28 transceivers on its ports. SFP stands for Small Form-factor Pluggable, SFP+ supports up to 10 Gbps, QSFP (Quad Small Form-factor Pluggable) supports up to 40 Gbps, and QSFP28 supports up to 100 Gbps per port.”
—Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 1: Introduction to Check Point Maestro, Lesson 1.2: Maestro Licensing and Hardware, page 1-8
—Check Point R81 Maestro Administration Guide, Chapter 1: Introduction to Check Point Maestro, Section: Maestro Licensing, page 1-6
—Check Point Quantum Maestro Orchestrator Datasheet, page 3
Explanation of Options:
A. SFP, QSFP, QSFP28: Incorrect, as it omits SFP+, which is supported by the MHO-140.
B. SFP+, SFP28, QSFP: Incorrect, as SFP28 is not explicitly listed as supported on the MHO-140, and SFP is missing.
C. SFP, SFP+, SFP28: Incorrect, as SFP28 is not supported, and QSFP and QSFP28 are omitted.
D. SFP, SFP+, QSFP, QSFP28: Correct, as this option includes all transceivers supported by the MHO-140, as per the official documentation.
In what mode do MHOs process traffic?
MHOs process traffic in load sharing mode
MHOs process traffic in Active-Standby mode
MHOs process traffic in Active-Active mode
MHOs process traffic in VSLS mode
MHOs process traffic in Active-Active mode, which means that both MHOs are active and share theload of the traffic that is sent to and from the SGMs. Active-Active mode provides better performance and scalability than Active-Standby mode, which only uses one MHO at a time and keeps the other as a backup. Active-Active mode also allows for faster failover and recovery in case of an MHO failure, as the surviving MHO can take over the traffic without interruption.
References
•Maestro Expert (CCME) Course - Check Point Software, page 25
•CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 2
•Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 2
Which command should be used to restart Orchestrator service only?
orchd restart
reboot
service orchestrator restart
cpstop; cpstart
Page 313 from the training manual:
- Restart the service:
orchd restart
- Restart the service without confirmation
service orchd restart
What is one benefit of a Dual MHO environment?
Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent.
Dual MHOs allow better synchronization to occur between SGMs.
Dual MHOs allow additional SGMs to be added to the SG.
Dual MHOs can be used to achieve increased scalability and redundancy..
One of the benefits of a Dual MHO environment is that it can provide both scalability and redundancy to the Maestro system. Scalability means that the system can handle more traffic and SGMs as the demand grows, and redundancy means that the system can survive the failure of one or more components without losing functionality or performance. Dual MHOs can achieve these benefits by distributing the load and the management tasks among two orchestrators, and by providing backup and failover mechanisms for each other.
References
•Maestro Expert (CCME) Course - Check Point Software, page 251
•CheckPoint Certified Maestro Expert (CCME) - Skillzcafe, page 22
•Check Point Certified Maestro Expert (CCME) R81.X, page 23
What is HealthCheck Point?
Is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system.
Performs a system health check and is meant to replace both a CPInfo and the health check script.
Can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization.
Is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system.
HealthCheck Point (HCP) is a tool designed to perform a comprehensive system health check for the Maestro environment. It is intended to replace both the CPInfo tool and traditional health check scripts by providing a streamlined way to assess the health of Maestro Orchestrators (MHOs) and Security Group Members (SGMs). HCP evaluates system status, configuration, and potential issues, generating detailed reports for troubleshooting and maintenance.
Exact Extract:
“HealthCheck Point (HCP) performs a system health check and is meant to replace both a CPInfo and the health check script. It assesses the health of the Maestro environment, including MHOs and SGMs, by checking system status, configuration settings, and potential issues. HCP provides detailed reports to aid in troubleshooting and maintenance.”
—Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using theCommand Line Interface and WebUI, Lesson 4.4: System Diagnostics, page 4-15
—Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: HealthCheck Point, page 4-12
Explanation of Options:
A. Is a self-updatable suite of tools for MHOs…: Incorrect, as HCP is not limited to MHOs and does not focus on visualizing topology or event timelines. It is a general health check tool for the entire Maestro environment.
B. Performs a system health check and is meant to replace both a CPInfo and the health check script: Correct, as HCP’s primary function is to perform system health checks, replacing CPInfo and health check scripts, as per the documentation.
C. Can be used to let you visualize the Firewall topology…: Incorrect, as HCP does not provide visualization of firewall topology or live statistics like throughput and CPU utilization.
D. Is a self-updatable suite of tools for SGMs…: Incorrect, as HCP is not exclusive to SGMs and does not include topology visualization or event timeline features.
There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?
100%/0%
33%/66%
50%/50%
66%/33%
What Maestro component is automatically designated the SMO Master?
The SGM with the lowest member ID (the first one added to the security group.)
The MDS that pushes policy to the SMO is considered the SMO Master.
The first MHO configured is considered the SMO Master.
The SGM with the highest member ID (the last one added to the security group.)
The SMO Master is the SGM that is responsible for synchronizing the configuration and policy with the other SGMs in the security group. The SMO Master is automatically designated as the SGM with the lowest member ID, which is usually the first one added to the security group. The SMO Master can be changed manually if needed.
Is it possible to define distribution mode per interface?
Yes, only for downlink interfaces
No, only for the Security Group
Yes, only for uplink interfaces
Yes, for both uplink and downlink interfaces
Maestro allows you to define the distribution mode per interface, which determines how traffic is distributed among the Security Group Modules (SGMs) in a Security Group. You can configure the distribution mode for each interface individually, or use the default mode for all interfaces. The distribution mode can be set for both uplink and downlink interfaces.
References =
•Check Point Maestro R81.X Administration Guide, page 62, section “Distribution Mode” 1
•Check Point Maestro R81.X Getting Started Guide, page 25, section “Distribution Mode” 2
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm
During an upgrade, Is Multi-Version Clustering (MVC) supported?
No. Maestro does not support MVC because ClusterXL is disabled during an upgrade.
No, Maestro does not support MVC.
Maestro supports MVC or full connectivity upgrade as of R80.40.
Yes, MVC is supported as of R81 for Maestro.
What command should be used for collecting diagnostic information about the orchestrator?
cpinfo
asg perf -v
cpview
orch_info
The cpinfo command is a tool that collects diagnostic information about the orchestrator, such as hardware, software, network, configuration, and logs. The cpinfo command generates a file that can be sent to Check Point Support for analysis and troubleshooting. The cpinfo command can be run on the orchestrator’s CLI or WebUI.
References =
•Check Point Maestro R81.X Administration Guide, page 68, section “cpinfo” 1
•Check Point Maestro R81.X Getting Started Guide, page 30, section “cpinfo” 2
•Maestro Hyperscale Orchestrator Datasheet - Check Point Software 3
1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm 3: https://www.checkpoint.com/downloads/products/maestro-hyperscale-orchestrator-datasheet.pdf
Which command can be used during an upgrade to verify that the upgraded SGMs have returned to UP status before upgrading other SGMs?
asg monitor
cpview
asg perf -v
asg stat -v
The asg stat -v command is used to verify the status of Security Group Members (SGMs) during an upgrade in a Maestro environment. This command provides detailed status information, including whether SGMs are in the UP state, which is critical before proceeding with upgrades to other SGMs to ensure system stability and continuity.
Exact Extract:
“The command ‘asg stat -v’ can be used during an upgrade to verify that the upgraded Security Group Members (SGMs) have returned to UP status before upgrading other SGMs. This command provides a detailed view of the status of all SGMs in the Security Group, ensuring that the upgraded members are operational.”
—Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 4: Using the Command Line Interface and WebUI, Lesson 4.4: System Diagnostics, page 4-16
—Check Point R81 Maestro Administration Guide, Chapter 4: Using the Command Line Interface and WebUI, Section: System Diagnostics, page 4-13
Explanation of Options:
A. asg monitor: Incorrect, as asg monitor is used for real-time monitoring but does not provide detailed status verification for SGMs during upgrades.
B. cpview: Incorrect, as cpview provides performance and system statistics but is not specific to verifying SGM status post-upgrade.
C. asg perf -v: Incorrect, as asg perf -v focuses on performance metrics, not SGM status verification.
D. asg stat -v: Correct, as this command is explicitly used to check the UP status of SGMs during upgrades, as per the documentation.
The core four manual diagnostic tools include:
asg diag verify, asg perf -v, orch_stat -all, and
asg diag verify
cpinfo
hcp -r all
asg stat -v
"Asg stat -v" could be a part of the core diagnostic tools, providing valuable statistics and information for manual diagnostics.
References =
•Maestro Expert (CCME) Course - Check Point Software 3
•Check Point Maestro R81.X Administration Guide 1
•Check Point Maestro R81.X Getting Started Guide 2
3: https://www.checkpoint.com/downloads/training/ccme-maestro-expert-r81.10-course.pdf 1: https://www.manualslib.com/manual/2031661/Check-Point-Maestro-R80-20sp.html 2: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_GettingStarted/html_frameset.htm
What type of license is required for an MHO?
The MHO requires a NGTP license.
The MHO requires a VSX license.
The MHO does not require a license.
A license is needed for each attached SGM.
The MHO (Maestro Hyperscale Orchestrator) does not require a license by itself, but each SGM (Security Group Module) that is attached to the MHO needs a license. The license type depends on the features and blades that are enabled on the SGM. For example, if the SGM is running VSX, it needs a VSX license.
In a Maestro Dual Site environment, what is the definition of the term Standby Site?
The Standby Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover.
There is no such thing as an active site. In a Dual Site environment, traffic is load balanced.
The Standby Site is the second site to have been defined in the process of configuring the Dual Site environment.
The Standby Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site.
In a Maestro Dual Site environment, the Standby Site is defined as the site that is not currently handling traffic for a specific Security Group (SG). Instead, it maintains synchronized connections with its Security Group Members (SGMs) via the Maestro Hyperscale Orchestrators (MHOs), ensuring it is ready to take over in the event of a failover. This setup enhances high availability and disaster recovery.
Exact Extract:
“In a Maestro Dual Site environment, the Standby Site is the site that is not handling any traffic for the specific Security Group, but its connections are synced to its Security Group Members (SGMs) from the Maestro Hyperscale Orchestrators (MHOs) to be ready in the event of a failover. This ensures high availability and seamless failover capabilities.”
—Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 3: Dual Orchestrator Environment, Lesson 3.1: Introduction to Dual Orchestrator Environment, page 3-7
—Check Point R81 Maestro Administration Guide, Chapter 3: Working with Security Group Modules, Section: Dual Site Configuration, page 3-9
Explanation of Options:
A. The Standby Site is the site that is not handling any traffic…: Correct, as this accurately describes the role of the Standby Site in a Dual Site environment, per the documentation.
B. There is no such thing as an active site…: Incorrect, as Maestro Dual Site environments explicitly define Active and Standby Sites, not load-balanced traffic across both sites.
C. The Standby Site is the second site to have been defined…: Incorrect, as the Standby Site is defined by its role (not handling traffic), not the order of configuration.
D. The Standby Site is the site currently handling the enforcement…: Incorrect, as this describes the Active Site, not the Standby Site.
What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?
Two Out-of-band interfaces for access to Orchestrator itself
1Gbps connectivity for Security Groups
Out-of-band interface for access to Orchestrator itself and Serial Console connector
Reserved for internal purposes. Not in use
The RJ-45 connectors located at the front panel of the Orchestrator MHO-170 are used for out-of-band management and serial console access. One of them is a 1Gbps RJ-45 port that provides an out-of-band interface for accessing the Orchestrator itself for configuration and management purposes. The other one is a RJ-45 serial console port that provides a command-line interface for initial setup and troubleshooting.
References
•Maestro Hyperscale Orchestrator Datasheet - Check Point Software1, page 2
•Quantum Maestro Getting Started Guide - Check Point CheckMates, page 4
Where should sx_api_ports_dump.py command be ran?
Management server
Security Group
Orchestrator
SMO Appliance
The sx_api_ports_dump.py command should be run on the Orchestrator, which is the device that manages the communication and the configuration of the Security Groups and the SGMs. The command shows the port mapping and the traffic distribution for each Security Group, as well as the backplane bonds and the Orchestrator ports. The command does not work on the Management server, the Security Group, or the SMO Appliance, as they do not have the same role and functionality as the Orchestrator.
References
•R81.20 Maestro Cheat Sheet version 7 - Check Point CheckMates, page 2
•Maestro Expert (CCME) Course - Check Point Software, page 31
•Check Point Certified Maestro Expert (CCME) R81.X - Global Knowledge, page 3
What is an uplink interface used for?
To connect in between appliances
To connect appliances to customer's infrastructure
To connect Orchestrators to customer’s infrastructure
To connect in between Orchestrators
An uplink interface in a Check Point Maestro environment is specifically used to connect Maestro Hyperscale Orchestrators (MHOs) to the customer’s network infrastructure, such as switches, routers, or firewalls. These interfaces facilitate the transmission and reception of management and control traffic between the MHOs and the customer’s network. They are critical for integrating the Maestro system with the external network environment.
Exact Extract:
“Uplink interfaces are used to connect Maestro Hyperscale Orchestrators (MHOs) to the customer’s network infrastructure, such as switches, routers, or firewalls. They are also used to send and receive management and control traffic from the customer’s network to the MHOs.”
—Check Point Certified Maestro Expert (CCME) R81.X Courseware, Module 1: Introduction to Check Point Maestro, Lesson 1.3: Maestro Interfaces, page 1-10
—Check Point R81 Maestro Administration Guide, Chapter 1: Introduction to Check Point Maestro, Section: Interfaces, page 1-8
Explanation of Options:
A. To connect in between appliances: Incorrect, as uplink interfaces are not used to connect appliances (Security Group Members) to each other. This is typically handled by downlink interfaces or internal backplane connections.
B. To connect appliances to customer's infrastructure: Incorrect, as appliances (SGMs) connect to the Orchestrators via downlink interfaces, not directly to the customer’s infrastructure.
C. To connect Orchestrators to customer’s infrastructure: Correct, as uplink interfaces are explicitly designed for this purpose, as stated in the courseware and administration guide.
D. To connect in between Orchestrators: Incorrect, as connections between Orchestrators (e.g., in a Dual-Site setup) are typically handled via site-sync ports, not uplink interfaces.
What is the Orchestrator?
Network Switch
Manager of compute and network resources, load balancer and network switch
Load balancer
None of above
The Orchestratoris a device that connects multiple security gateways into a unified system, called a security group. It manages the configuration, policy, software, and routing of the security group, and distributes the network traffic among the security gateways using a load-balancing algorithm. It also acts as a network switch for the internal and external networks.
References = Maestro Hyperscale Orchestrator Datasheet - Check Point Software, Check Point Maestro Hyperscale Network Security, 7 Reasons to Use Check Point Maestro and … - Check Point Software
What is the throughput penalty of Security Group?
Depends on the type of Appliance
1% per member
10% per Security Group with no relation to the number of members
5% per member
Check Point reduced throughput degradation to 1% per added SGMs. For example, the overall throughput degradation is 10% for 10 SGMs in a Security Group. Check Point aims to reduce this even further in the future. https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails= &solutionid=sk147853
What happens if you apply a hotfix using gClish?
If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time.
If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so.
Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A."
If you apply a hotfix using gclish, the operation will fail because an outage would occur.
According to the Installing and Uninstalling a Hotfix on Quantum Maestro Orchestrators, page 1, when you apply a hotfix using gclish, the MHO distributes the hotfix to all SGMs in the SecurityGroup. The SGMs install the hotfix and reboot one by one, in ascending order of their SGM IDs. The SGMs wait for the previous SGM to finish rebooting before starting their own reboot. This ensures that there is no outage for the entire Security Group.
References = Installing and Uninstalling a Hotfix on Quantum Maestro Orchestrators, page 1; Maestro R81.10 Jumbo Hotfix install - Check Point CheckMates, page 1.
TESTED 30 Aug 2026
