Courseiva

CCSM Advanced Content Inspection Practice Question

A Check Point security gateway is configured with HTTPS Inspection to decrypt outbound traffic for inspection by the Anti-Bot and Antivirus blades. The administrator notices that some users are receiving certificate warnings when accessing certain websites, while others are not. The administrator has installed the gateway's CA certificate in the trusted root store of all managed endpoints via GPO. Which of the following is the most likely reason for the certificate warnings on specific sites?

⚠ Common exam trap

The trap here is assuming that a trusted CA certificate resolves all HTTPS Inspection warnings, overlooking application-level pinning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The websites use certificate pinning, which causes the browser to reject the gateway's re-signed certificate.

Certificate pinning causes browsers or applications to expect a specific certificate or public key for a site. When HTTPS Inspection intercepts and re-signs the connection with the gateway's CA, the pinned certificate does not match, resulting in a warning or connection failure. This is a common challenge with HTTPS Inspection and explains why only certain sites are affected. The other options either contradict the scenario or are not typical causes of selective warnings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The websites use certificate pinning, which causes the browser to reject the gateway's re-signed certificate.

    Why this is correct

    Certificate pinning is a security mechanism where the application or browser expects a specific certificate or public key for a site. When HTTPS Inspection re-signs the certificate with the gateway's CA, the pinned certificate no longer matches, triggering a warning or blocking access. This is a common issue with sites like banking or high-security services, and it explains why only certain sites are affected despite the CA being trusted.

  • ✗

    The websites use Extended Validation (EV) certificates, and the gateway cannot re-sign EV certificates, leading to warnings.

    Why it's wrong here

    HTTPS Inspection can re-sign any certificate, but EV certificates have specific indicators in browsers. However, when re-signed, the EV status is lost, but this typically does not cause a certificate warning if the CA is trusted. The browser may show a regular padlock instead of an EV indicator, but not a warning. Thus, EV certificates alone do not explain the warnings.

  • ✗

    The gateway is configured to bypass HTTPS Inspection for certain categories, and those sites present their original certificates, which are untrusted.

    Why it's wrong here

    If HTTPS Inspection is bypassed, the original certificate is presented. Since the CA is trusted, the original certificate should also be trusted if it is from a public CA. Bypass would not cause warnings unless the site's certificate is invalid or self-signed. The scenario does not suggest bypass configuration, and warnings on specific sites are more consistent with pinning. This option is less likely.

  • ✗

    The gateway's CA certificate is not installed on the users' machines, causing warnings for all HTTPS sites.

    Why it's wrong here

    The scenario explicitly states that the administrator has installed the CA certificate in the trusted root store of all managed endpoints via GPO. If the CA were missing, all HTTPS sites would generate warnings, not just specific ones. Therefore, this cannot be the cause of the selective warnings. The issue is likely site-specific behavior.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.