Yuri Slobodyanyuk Blog on Information Security 2024年07月23日
Check Point Certified Troubleshooting Administrator (CCTA) 156-580 Exam Preparation Tips and Impressions
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文作者分享了其通过Check Point Certified Technical Administrator (CCTA) R80.30考试的经验,并提供了详细的备考建议。文章涵盖了考试的难度、考试内容、重点内容、备考材料和资源等方面,并提醒考生注意R80.30版本的新特性和变化,例如fw monitor、kernel debug、daemon ports等。

🎯 **考试内容和重点:** 考试包含75道选择题,涵盖了官方课程大纲中的所有主题,重点考察R80.30版本的新特性和变化,例如fw monitor、kernel debug、daemon ports等。 考试中涉及了UserCenter TAC网站流程的问题,需要考生了解不同类型工单的创建、提交和所需信息。 考试中fw monitor相关问题数量和深度有所增加,考生需要熟悉所有开关、选项和操作。 考试中还涉及到Security Blades的调试、daemon名称、文件、数据库位置等内容。 考生需要掌握kernel debug的通用步骤,并了解R80.30版本中新的debug命令和语法。

🎯 **备考材料和资源:** 作者建议考生首先参考官方课程大纲,并了解最新的考试内容。 作者还推荐了以下备考资源: - Heiko Ankenbrand的daemon和端口清单,包括R80.30版本的变化。 - Checkpoint网站上的Advanced Technical Reference Guides (ATRG)。 - Timothy Hall的《Checkpoint Firewall Optimization》一书,涵盖了R80.30版本及以后的内容。

🎯 **备考建议:** 作者建议考生在备考过程中,重点关注R80.30版本的新特性和变化,并熟悉相关的debug命令和语法。 考生还需要了解不同类型的工单、fw monitor的各种操作、Security Blades的调试方法、daemon名称和端口等。 作者还建议考生阅读相关的ATRG和书籍,以便更深入地理解考试内容。

🎯 **其他建议:** 作者建议考生在考试前进行PearsonVue在线考试流程的模拟演练,并运行PearsonVue的系统测试软件,以确保考试顺利进行。 作者还建议考生在备考过程中,与其他考生交流经验,并分享备考资源。

🎯 **总结:** 作者的备考经验分享对考生准备CCTA R80.30考试提供了宝贵的建议和指导。考生可以根据作者的建议,选择合适的备考材料和资源,制定合理的备考计划,并最终取得考试的成功。

The following, I hope, will help you to prepare better for the exam as there is no information I could find anywhere.

Note
Links to all the resources I mention in the text are at the end. Also, for obvious reasons this article does not contain actual questions from the exam.

First, the exam wasn’t easy by any means and I’ve been passing #Checkpoint exams starting with R60. Still, it is doable. There are all in all 75 questions. There were no long-winded questions as in the past spanning 4-5 lines. I didn’t need to actually type anything - only multiple answer types of questions. I took the exam via the PearsonVue online proctoring and had 0 issues with the technical side of it. If you plan on taking it online for the first time, make sure to see Youtube walk-throughs of the process to prevent any surprises and run System Test software from PearsonVue BEFORE actually ordering the exam. Now, to the exam preparation itself.

    Official materials. Start your preparation with the exam topics in the official preparation course syllabus. As I understand from bits of information found on the Checkpoint Community forum and elsewhere, the distinction between CCTA and Check Point Certified Troubleshooting Expert (CCTE) exam is not in the level of expertise, but rather in the topics. I haven’t taken CCTE yet. By this I want to say - don’t be fooled by "Administrator" versus "Expert" in the exam title. I didn’t take the official Checkpoint course, so can’t comment how it helps to pass the exam. In theory, you can buy just the official courseware from Checkpoint catalog website (about 650$ last time I checked). The catch, though, is that you can’t directly buy it from Checkpoint - when trying to pay for it, the website refers you to your Account Manager. And from, again, reports on the Checkpoint Community forum - they (AM) will refer you back to ATC center, which of course will have no incentive to sell you just courseware, without the instructor based course of their own (2000$-3000$ depending on location).

    CCSM R80 overlap. The exam, unfortunately, had very little questions from CCSM R80, my rough estimate would be about 15 out of 75. It means it is NOT possible to pass the exam on CCSM R80 knowledge/study materials/experience only.New: UserCenter TAC website procedures questions. That was a surprise. I answered one such question wrong just because lacking context, the question asked about specifics of the UserCenter website and I didn’t understand that they were actually testing on TAC website and not on technical issue of the firewall. To prepare for such questions, I would suggest dry run opening ALL types of tickets, stopping just before hitting "Submit" button. Know what types of tickets exist, how they differ, what information each one requires, etc.

    This is R80.20+ Based Exam. The official preparation course is titled "R80.30 …​", so it is expected. The point to remember , especially for those who have experience with pre-R80.30 versions and exams (like me), is when in doubt - think it is R80.30 specific exam only. Many features we’ve known for years in Checkpoint have changed in R80.30 and you may fall in the trap of answering the R77.30/R80.10-way. E.g. (not from real exam, but it could be) - fw monitor questions, which are always present in such exams. Before R80.20 Take xxx and R80.30, it was the Checkpoint recommendation to disable SecureXL before running fw monitor and exams followed the suite. Then, they changed it to NOT disable for version R80.20, only later to change it again to DO disable SecureXL. So, currently, the correct answer is to disable SecureXL until further notice. Kernel debug, which is always present as well, changed too. Refresh your knowledge even for the well known topics.

    More than usual questions on fw monitor. fw monitor questions were always on this exam (CCSE+, CCSM), but I felt this time they increased in number and depth. So, know all the switches/options and how to work with this sniffer well. And again - refresh your knowledge for R80.30 as new options such as filtering/insertion points appeared.

    Blades that are on the topics list - know their debug well. Obvious, but still - Security Blades listed on the official course syllabus make a large portion of the exam. Know their specific debug, daemon names, files they create/use, their databases locations.

    Kernel debug. No news here - you have to remember general steps in running kernel debug for at least popular modules like ClusterXL, NAT, IPSec VPN. Pay attention that usual ?? ??? ????? ?? +`…​ syntax is not enough in R80.30. That is - learn both ?????? and ??????.

    Daemons and their ports. This sort of questions is present in, seems like, all the Checkpoint exams. In the References section below I put Heiko Ankenbrand’s complete cheat sheet on what port which daemon works, including the changes in R80.30. Memorize this cheat sheet, you’ll thank me and Heiko later.

    Read ATRGs on relevant topics. Reading Advanced Technical Reference Guides (ATRG) is my way to prepare extra for the exam. I can’t say this is strictly necessary, but helps to feel more confident. If you do, read only ATRGs on the topics mentioned in the official course list.

    Timothy Hall book. I didn’t read it specifically for the exam, but for my work and recommend it not only for optimization but debug as well. The book is R80.30+ only so helps with exam topics as well.

That’s all for this exam. Make sure to share this with your friends who prepare for the exam. Thanks for reading, nice and peaceful weekend to everyone.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

CCTA Check Point R80.30 考试 备考 经验分享
相关文章