Course Catalog
Check Point Certified Security Expert (CCSE)
Code: Check Point CCSE
Duration: 3 Day
$3000 USD

OVERVIEW

In this course, you will learn the advanced concepts and skills necessary to configure Check Point Next Generation Firewalls. During this course, you will gain with the advanced knowledge, skills, and hands-on experience needed to deploy, manage, and monitor existing Quantum Security Environments. Delegates will learn how to deploy Management High Availability, provide advanced policy management, configure Site-to-Site VPN, provide advanced security monitoring, upgrade a Security Gateway, use Central Deployment tool to install hotfixes, perform an import of a Primary Security Management Server, and Deploy ElasticXL Cluster.

 

Note: Supported version R82

DELIVERY FORMAT

This course is available in the following formats:

Virtual Classroom

Duration: 3 Day
Classroom

Duration: 3 Day

CLASS SCHEDULE

Delivery Format: Virtual Classroom
Date: Sep 02 2026 - Sep 04 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Sep 16 2026 - Sep 18 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Sep 30 2026 - Oct 02 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Oct 14 2026 - Oct 16 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Nov 04 2026 - Nov 06 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Nov 18 2026 - Nov 20 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Dec 02 2026 - Dec 04 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

Delivery Format: Virtual Classroom
Date: Dec 16 2026 - Dec 18 2026 | 10:00 - 18:00 EST
Location: Online
Course Length: 3 Day

$ 3000

GOALS

When you complete this course, you will be able to:

  • Deploy Management High Availability
  • Provide advanced policy management
  • Configure Site-to-Site VPN
  • Provide advanced security monitoring
  • Upgrade a Security Gateway
  • Use Central Deployment tool to install hotfixes
  • Perform an import of a Primary Security Management Server
  • Deploy ElasticXL Cluster
OUTLINE

Module 1: Management High Availability

  • Explain the purpose of Management High Availability
  • Identify the essential elements of Management High Availability

Module 2: Advanced Policy Management

  • Identify ways to enhance the Security Policy with more object types
  • Create dynamic objects to make policy updatable from the Gateway
  • Manually define NAT rules
  • Configure Security Management behind NAT

Module 3: Site-to-Site VPN

  • Discuss site-to-site VPN basics, deployment, and communities
  • Describe how to analyze and interpret VPN tunnel traffic
  • Articulate how pre-shared keys and certificates can be configured to authenticate with third-party and externally managed VPN Gateways
  • Explain Link Selection and ISP Redundancy options
  • Explain tunnel management features

Module 4: Advanced Security Monitoring

  • Describe the SmartEvent and Compliance Blade solutions, including their purpose and use

Module 5: Upgrades

  • Identify supported upgrade options

Module 6: Advanced Upgrades and Migrations

  • Export/import a Management Database
  • Upgrade a Security Management Server by freshly deploying the new release or using a new appliance

Module 7: ElasticXL Cluster

  • Describe the ElasticXL Cluster solution, including its purpose and use

Module 1: Management High Availability

  • Explain the purpose of Management High Availability
  • Identify the essential elements of Management High Availability

Module 2: Advanced Policy Management

  • Identify ways to enhance the Security Policy with more object types
  • Create dynamic objects to make policy updatable from the Gateway
  • Manually define NAT rules
  • Configure Security Management behind NAT

Module 3: Site-to-Site VPN

  • Discuss site-to-site VPN basics, deployment, and communities
  • Describe how to analyze and interpret VPN tunnel traffic
  • Articulate how pre-shared keys and certificates can be configured to authenticate with third-party and externally managed VPN Gateways
  • Explain Link Selection and ISP Redundancy options
  • Explain tunnel management features

Module 4: Advanced Security Monitoring

  • Describe the SmartEvent and Compliance Blade solutions, including their purpose and use

Module 5: Upgrades

  • Identify supported upgrade options

Module 6: Advanced Upgrades and Migrations

  • Export/import a Management Database
  • Upgrade a Security Management Server by freshly deploying the new release or using a new appliance

Module 7: ElasticXL Cluster

  • Describe the ElasticXL Cluster solution, including its purpose and use
LABS

Lab 1:

  • Deploy and configure Management High Availability
  • Ensure the failover process functions as expected

Lab 2:

  • Use Updatable Objects
  • Configure Network Address Translation for server and network objects
  • Configure Management behind NAT for Branch Office connections

Lab 3:

  • Configure Site-to-Site VPN with internally managed Security Gateways

Lab 4:

  • Configure a SmartEvent Server to monitor relevant patterns and events
  • Demonstrate how to configure Events and Alerts in SmartEvent
  • Demonstrate how to run specific SmartEvent reports
  • Activate the Compliance Blade
  • Demonstrate Security Best Practice settings and alerts
  • Demonstrate Regulatory Requirements Compliance Scores

Lab 5:

  • Upgrade a Security Gateway
  • Use Central Deployment tool to install Hotfixes

Lab 6:

  • Prepare to perform an Advanced Upgrade with Database Migration on the Primary Security Management Server in a distributed environment
  • Perform an import of a Primary Security Management Server in a distributed Check Point environment

Lab 7:

  • Deploy an ElasticXL Security Gateway Cluster

Lab 1:

  • Deploy and configure Management High Availability
  • Ensure the failover process functions as expected

Lab 2:

  • Use Updatable Objects
  • Configure Network Address Translation for server and network objects
  • Configure Management behind NAT for Branch Office connections

Lab 3:

  • Configure Site-to-Site VPN with internally managed Security Gateways

Lab 4:

  • Configure a SmartEvent Server to monitor relevant patterns and events
  • Demonstrate how to configure Events and Alerts in SmartEvent
  • Demonstrate how to run specific SmartEvent reports
  • Activate the Compliance Blade
  • Demonstrate Security Best Practice settings and alerts
  • Demonstrate Regulatory Requirements Compliance Scores

Lab 5:

  • Upgrade a Security Gateway
  • Use Central Deployment tool to install Hotfixes

Lab 6:

  • Prepare to perform an Advanced Upgrade with Database Migration on the Primary Security Management Server in a distributed environment
  • Perform an import of a Primary Security Management Server in a distributed Check Point environment

Lab 7:

  • Deploy an ElasticXL Security Gateway Cluster
WHO SHOULD ATTEND

Technical persons who support, install, deploy, or administer Check Point Software Blades should attend this course. This could include the following:

  • Security Engineers
  • Security Analysts
  • Security Consultants
  • Security Architects
  • Anyone seeking CCSE certification
PREREQUISITES

  • Unix-like and/or Windows OS
  • Internet Fundamentals
  • Networking Fundamentals
  • Networking Security
  • TCP/IP Networking
  • Minimum of 6-months of practical experience with the management of a Quantum Security Environment