The ticket
You have a CCSA PDF. The interviewer asks: “Policy install says not trusted. Walk me through it.” If you cannot do lessons 3 and 15 out loud, the certificate is wallpaper.
CCSA = configure objects, policy, NAT, logs, basic gateway on Gaia. CCSE = ClusterXL, VPN, HTTPS Inspection, acceleration, hard installs. I prove with fw stat, cphaprob, vpn tu, fw monitor letters, and SmartLog blade — not with product slogans.
SMS sms-lab 10.10.10.5 · cluster VIP 10.10.10.1 (cp-gw-01 10.10.10.2 / cp-gw-02 10.10.10.3) · external 203.0.113.25 · internal LAN 10.20.30.0/24 · HR PC 10.20.30.80 TECHCLICK\priya.hr · HR app 10.20.30.41 hr.techclick-lab.in. Not a live customer.
CCSA vs CCSE
| CCSA | CCSE | |
|---|---|---|
| Focus | Administrator | Expert / troubleshoot |
| Exam flavour (current trains) | 156-215.81 / .81.20 / .82 | 156-315.x matching train |
| This series | Lessons 1–6, 10, 15 | 7–9, 11–14, 16 |
| Lab bar | Install, SIC, rule, Hide NAT, log | Cluster failover, VPN P2, fw monitor, TP exception |
Confirm the exact exam code on Check Point’s training site before you book. Trains move (R81.20, R82).
What to lab
- Distributed SMS + two-member cluster (even if nested VMs).
- One Hide LAN + one Static server.
- One Access Role (even a fake mapping).
- One HTTPS Inspection warn you fix with bypass or CA.
- One TP exception.
- One Community with a second gateway (or strongswan peer).
- Break SIC and recover. Break a session lock and recover.
20 questions
Q1 · Architecture
Traffic still flows, SmartConsole is down. What do you do?
Weak
Reboot the cluster.
Q2 · Gaia
IPs vanish after reboot. Why?
save config in clish.Q3 · SIC
Install: Not Trusted. Steps?
Q4 · First match
Rule 40 never logs. Rule 8 Any-Any Accept does. What happened?
Q5 · Layers
Network Accept, user still fails.
Q6 · NAT
Outbound works, inbound VIP dead.
Q7 · IA
Access Role, empty Source User.
Q8 · HTTPS
One site warns.
Q9 · TP
Access Accept, EXE dies.
Q10 · Logs
Three theories, no evidence.
Q11 · fw monitor
tcpdump yes, monitor no.
Q12 · SecureXL
Empty policy log, packet on wire.
Q13 · ClusterXL
Both members Active.
Q14 · VPN
P1 up, P2 down.
Q15 · Lock
Install locked.
Q16 · vs PA
What is User-ID on Check Point?
Q17 · Implied rules
Is row 1 the first check?
Q18 · Standalone
Why not Standalone in production?
Q19 · Cleanup
Why log cleanup?
Q20 · Prove install
How do you know the gateway has today’s policy?
fw stat date/time and name — not the SmartConsole editor.Weak vs strong
| Weak | Strong |
|---|---|
| “I would restart the firewall.” | “Which of the three boxes, and here is the command.” |
| “Turn off IPS.” | “Name the protection, exception, install TP.” |
| “fw monitor shows nothing so it never arrived.” | “Wrong letter / -e / SecureXL.” |
How to practice
Pick three tickets from Q1–Q20. Speak 90 seconds each with a dummy IP from this lab. If you cannot name a command, re-open that lesson.
Traps
Do not memorize dump sites. Do not invent menu names. Confirm current exam codes on the official training catalog.
Knowledge check
Judgment items. One best answer. Reasons send you back to the matching section.
Check Point class series: Architecture · Gaia first day · SIC reset · Objects + first match · Policy layers · Hide vs Static NAT · Identity Awareness · HTTPS Inspection · Threat Prevention · Find the drop · fw monitor · SecureXL · ClusterXL · VPN Community · Policy install lock · vs PA vs Forti · CCSA / CCSE interview
Sources
- CCSA Exam Prep Guide (PDF) — confirm current train.
- Check Point training catalog — CCSA / CCSE / CCTE exam codes (R81.20, R82).
- This Techclick series lessons 1–16 — the lab proofs behind each question.
Related: Check Point evidence desk · session factory · next lesson in the series above.