Courseiva

CCSM Advanced Security Management Practice Question

A company runs a Check Point Security Management Server with several gateways. Auditors require that every administrative login and configuration change be attributable to an individual, and that shared accounts be eliminated. The administrator must implement this while preserving existing automation that uses the Management API. Which approach best satisfies the auditors?

⚠ Common exam trap

The trap here is believing that richer logging can compensate for shared credentials when the requirement is per-person attribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create individual administrator accounts for each person, keep the existing API service account for automation, and enable auditing of administrator actions.

Accountability requires that each human action map to a unique identity, so individual administrator accounts are essential, and a separate service account for automation keeps programmatic access controlled without sharing human credentials. Enabling auditing on top of that produces a traceable record of who changed what, which is what the auditors are asking for.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace all administrator accounts with SmartConsole API keys and distribute one key per team to simplify authentication.

    Why it's wrong here

    Distributing a single API key per team recreates the shared-credential problem in a different form and weakens attribution. API keys are intended for programmatic access with defined roles, not as substitutes for individual human accounts. This does not satisfy the requirement that each administrative action be tied to a named individual.

  • ✗

    Enable SmartEvent correlation for administrator logins and generate daily reports from the Log Server instead of changing accounts.

    Why it's wrong here

    SmartEvent correlation and reporting can surface login patterns, but reporting alone does not create individual identities or remove shared accounts. The underlying actions would still be performed under shared credentials, so attribution remains impossible. This addresses visibility of events, not the accountability requirement the auditors specified.

  • ✓

    Create individual administrator accounts for each person, keep the existing API service account for automation, and enable auditing of administrator actions.

    Why this is correct

    Individual accounts make every human action attributable, while a dedicated API service account preserves automation without sharing a human credential. Auditing records the actions performed, satisfying the requirement that changes be traceable. This combination separates human and machine identities, which is exactly what an auditor expects when shared accounts must be removed.

  • ✗

    Keep one shared administrator account for the team but enable detailed audit logging so every change is recorded with a timestamp.

    Why it's wrong here

    Audit logging records what changed and when, but a shared account cannot tie an action to a specific person. The auditor requirement is attribution to an individual, which a shared credential inherently prevents. Detailed logs on a shared account still leave the identity ambiguous, so this approach fails the stated objective.

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.