Courseiva
Advanced Threat Prevention →mediumMultiple Choice

CCSM Advanced Threat Prevention Practice Question

A Check Point administrator is investigating a security incident where a user's computer was infected with malware. The malware was downloaded via HTTP and executed. The administrator reviews the Threat Prevention logs and sees that the Anti-Bot blade detected communication with a known command and control server but did not block it. The logs show the action as 'Detect' instead of 'Prevent'. What is the most likely reason for this?

⚠ Common exam trap

The trap here is assuming that a licensed and active Anti-Bot blade automatically blocks threats, when in fact the action depends on the configured profile mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Anti-Bot blade is configured in 'Detect' mode in the Threat Prevention profile.

The Anti-Bot blade's action is determined by the Threat Prevention profile. If the profile is set to 'Detect' mode for Anti-Bot, it will only log malicious traffic without blocking it. The administrator should check the profile and switch to 'Prevent' mode to actively block command and control communications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Anti-Bot blade is configured in 'Detect' mode in the Threat Prevention profile.

    Why this is correct

    The Anti-Bot blade can be set to 'Detect' or 'Prevent' mode in the Threat Prevention profile. If set to 'Detect', it will log the malicious traffic but not block it. This is likely the cause of the observed behavior. The administrator should change the profile to 'Prevent' mode to block such traffic.

  • ✗

    The Anti-Bot blade requires a separate license to block traffic.

    Why it's wrong here

    Licensing enables the blade, but does not control the action (Detect vs Prevent). If the blade is licensed and active, the action is determined by the profile settings. Lack of license would typically disable the blade, not set it to Detect mode.

  • ✗

    The malware used an encrypted channel that Anti-Bot cannot block.

    Why it's wrong here

    Anti-Bot can block encrypted traffic if it can identify the C&C communication. The log indicates detection, so the blade did identify it. The action 'Detect' suggests the profile is set to monitor only, not that blocking is impossible.

  • ✗

    The command and control server is on the ThreatCloud whitelist.

    Why it's wrong here

    If the C&C server were whitelisted, the Anti-Bot blade would not generate a log entry at all, or it would log as 'Allowed'. Since it logged as 'Detect', whitelisting is not the cause. Whitelisting would bypass detection entirely.

About these practice questions

One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.