CCSM Advanced Threat Prevention Practice Question
A security administrator is troubleshooting an issue where Anti-Bot is failing to block communications to a known malicious Command and Control (C&C) server. The traffic traverses the firewall via an encrypted HTTPS tunnel. Which configuration ensures that Anti-Bot can inspect and block this encrypted traffic?
⚠ Common exam trap
Candidates often suggest enabling 'URL Filtering' alone. They forget that without SSL/TLS decryption, the security gateway cannot see inside the encrypted tunnel to identify the malicious botnet traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable HTTPS Inspection on the Security Gateway and configure outbound decryption rules.
Enabling HTTPS Inspection on the Security Gateway allows the system to decrypt TLS traffic, inspect the application layer using Anti-Bot and URL Filtering blades, and block malicious C&C communication. Without decryption, encrypted payloads remain opaque, preventing security blades from reading HTTP headers or identifying specific botnet signatures embedded within SSL streams.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable HTTPS Inspection on the Security Gateway and configure outbound decryption rules.
Why this is correct
HTTPS Inspection decrypts outbound TLS traffic at the Security Gateway, allowing Anti-Bot to inspect the plaintext payload and block the C&C communication. Without outbound decryption rules, the encrypted tunnel hides the malicious traffic from inspection.
- ✗
Upgrade the Security Gateway firmware to the latest Jumbo Hotfix Accumulator release.
Why it's wrong here
A Jumbo Hotfix Accumulator delivers bug fixes and stability patches; it does not enable HTTPS inspection, so the encrypted C&C tunnel stays uninspected. It is tempting because firmware updates genuinely resolve known defects, which would be correct when the failure stems from a documented software bug rather than missing decryption.
- ✗
Configure Anti-Bot to operate in MTA mail relay mode for all outbound traffic.
Why it's wrong here
Anti-Bot's MTA mail relay mode inspects SMTP email content, so it cannot decrypt HTTPS tunnels carrying C&C traffic. It is tempting because mail relay scanning genuinely blocks malicious payloads in email flows, which would be the right choice for an SMTP-based threat rather than encrypted web traffic.
- ✗
Configure Anti-Spoofing on the internal interface to drop unverified encrypted packets.
Why it's wrong here
Anti-Spoofing validates source IP addresses against topology on an interface; it does not decrypt or inspect HTTPS payloads, so the encrypted C&C channel remains opaque. It is tempting because anti-spoofing genuinely drops forged-packet traffic, which would be correct when defending against IP spoofing rather than encrypted command-and-control.
Visual reference
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.