Free CheckPoint 156-587 R81.20 Actual Exam Questions - Question 9 Discussion
Identity Collector?
D imo, adlog is usually for authentication logs but doesn’t directly show communication status between Security Gateway and Identity Collector. A might be better since fw ctl debug -m IDAPI seems focused on ID API modules, which fits the question. Also, B pdp connections idc could be version-dependent, so I'd skip that without version info. C mixes fw and nac debug, which feels too broad for this specific verification.
Option A works because it specifically targets IDAPI traffic for debugging.
Eliminating D since adlog is more for log review, not live comm check.
B, since it directly shows IDC connections without extra noise.
A/D? A is a common debug command for IDAPI, and D (adlog) shows authentication logs, which could help verify communication indirectly. C seems too broad for this specific check.
B imo since pdp connections idc specifically shows Identity Collector connections, making it a more direct way to verify communication.
Gotta be C on this one.