CCSM Advanced Threat Prevention Practice Question
A security administrator is analyzing a Check Point Threat Emulation report for a suspicious PDF file that was emulated. The report indicates that the file attempted to connect to a remote server and download additional content. The administrator wants to identify the specific Indicators of Compromise (IOCs) from the report to block future attacks. Which TWO pieces of information should the administrator extract from the Threat Emulation report to create effective threat prevention rules? (Choose two.)
⚠ Common exam trap
The trap here is selecting static file attributes like size or author instead of dynamic, actionable indicators like hashes and network addresses that can be enforced in security policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The URL or IP address of the remote server contacted by the PDF.
The two most valuable IOCs from the Threat Emulation report are the SHA-256 hash of the malicious file and the URL or IP address of the remote server it contacted. These can be directly used to create blocking rules in Check Point Threat Prevention, preventing similar attacks. Other details like file size or author are not reliable for detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The date and time the PDF was created.
Why it's wrong here
Creation timestamps are not unique IOCs and can be manipulated. They do not help in identifying or blocking the threat across different instances. Effective threat prevention relies on indicators like hashes or network addresses that are consistent across attacks.
- ✓
The URL or IP address of the remote server contacted by the PDF.
Why this is correct
The remote server URL or IP is a critical IOC because it represents the command and control or payload delivery point. Blocking this address prevents the PDF from downloading further malicious content. This information is typically found in the 'Network Activity' section of the Threat Emulation report and can be used to create a custom threat prevention rule or add to a blocklist.
- ✗
The file size of the PDF.
Why it's wrong here
File size alone is not a reliable IOC. Many benign PDFs have similar sizes, and blocking based on size would cause false positives. The administrator needs actionable indicators like network connections or file hashes, not static attributes that do not indicate malicious intent.
- ✗
The name of the PDF author from the document properties.
Why it's wrong here
Author names can be easily spoofed and are not reliable indicators of malicious activity. They do not provide a robust basis for blocking future attacks. The administrator should focus on technical indicators that are directly tied to the malicious behavior, such as network connections or file hashes.
- ✓
The SHA-256 hash of the PDF file.
Why this is correct
The SHA-256 hash uniquely identifies the malicious PDF and can be used to block it across the organization. Check Point's Threat Prevention can block files by hash, ensuring that even if the file is renamed or delivered via a different method, it is still detected. This is a standard IOC extracted from Threat Emulation reports.
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.