CCSM Advanced Threat Prevention Practice Question
A Check Point administrator is tuning a Threat Prevention profile for a site that repeatedly generates 'Protected Scope' violations with the 'Prevent' action on the 'Suspicious Executable Download' protection. The administrator wants to stop blocking these downloads while still logging them, but must not weaken any other protections in the profile. What is the most precise way to accomplish this?
⚠ Common exam trap
The trap here is assuming that the only way to stop a block is to change the profile-wide action or disable the protection, rather than using a per-protection exception that preserves logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an exception in the Threat Prevention profile for the specific protection and set its action to 'Detect'.
The precise fix is a per-protection exception that changes only that protection's action to Detect. This stops the unwanted blocking while keeping the event logged and leaving every other protection at its configured Prevent action. Broad profile-wide changes or whitelisting sources would unnecessarily weaken other protections and fail the requirement to avoid collateral impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an exception in the Threat Prevention profile for the specific protection and set its action to 'Detect'.
Why this is correct
This is correct because Check Point Threat Prevention profiles allow per-protection exceptions. By overriding the action for only the 'Suspicious Executable Download' protection to 'Detect', the administrator stops blocking while preserving logging and leaving all other protections at their configured actions. This is the most precise, least-disruptive change.
- ✗
Add the affected source IP addresses to a global whitelist in the Threat Prevention policy.
Why it's wrong here
Whitelisting source IPs would bypass all Threat Prevention protections for those hosts, not just the executable-download protection. That weakens the security posture far more than necessary. It also does not scale well if the blocks come from many internal users, and it fails to preserve the same granular logging intent.
- ✗
Change the profile's overall action from 'Prevent' to 'Detect' for the entire profile.
Why it's wrong here
This fails because changing the profile-wide action weakens every protection in the profile, not just the one causing the blocks. The requirement is to stop blocking only the specific protection while keeping all others in 'Prevent'. A global action change is too broad and violates the constraint of not weakening other protections.
- ✗
Disable the 'Suspicious Executable Download' protection entirely in the profile.
Why it's wrong here
Disabling the protection removes both blocking and logging. The administrator explicitly wants to keep logging the event, so this does not meet the requirement. It also removes visibility that could be needed for later tuning or investigation, making it inferior to an action override that preserves logs.
About these practice questions
Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.