Courseiva
Advanced Threat Prevention →mediumMultiple Choice

CCSM Advanced Threat Prevention Practice Question

A security administrator is troubleshooting an issue where Anti-Bot is failing to block communications to a known malicious Command and Control (C&C) server. The traffic traverses the firewall via an encrypted HTTPS tunnel. Which configuration ensures that Anti-Bot can inspect and block this encrypted traffic?

⚠ Common exam trap

Candidates often suggest enabling 'URL Filtering' alone. They forget that without SSL/TLS decryption, the security gateway cannot see inside the encrypted tunnel to identify the malicious botnet traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable HTTPS Inspection on the Security Gateway and configure outbound decryption rules.

Enabling HTTPS Inspection on the Security Gateway allows the system to decrypt TLS traffic, inspect the application layer using Anti-Bot and URL Filtering blades, and block malicious C&C communication. Without decryption, encrypted payloads remain opaque, preventing security blades from reading HTTP headers or identifying specific botnet signatures embedded within SSL streams.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable HTTPS Inspection on the Security Gateway and configure outbound decryption rules.

    Why this is correct

    HTTPS Inspection decrypts outbound TLS traffic at the Security Gateway, allowing Anti-Bot to inspect the plaintext payload and block the C&C communication. Without outbound decryption rules, the encrypted tunnel hides the malicious traffic from inspection.

  • ✗

    Upgrade the Security Gateway firmware to the latest Jumbo Hotfix Accumulator release.

    Why it's wrong here

    A Jumbo Hotfix Accumulator delivers bug fixes and stability patches; it does not enable HTTPS inspection, so the encrypted C&C tunnel stays uninspected. It is tempting because firmware updates genuinely resolve known defects, which would be correct when the failure stems from a documented software bug rather than missing decryption.

  • ✗

    Configure Anti-Bot to operate in MTA mail relay mode for all outbound traffic.

    Why it's wrong here

    Anti-Bot's MTA mail relay mode inspects SMTP email content, so it cannot decrypt HTTPS tunnels carrying C&C traffic. It is tempting because mail relay scanning genuinely blocks malicious payloads in email flows, which would be the right choice for an SMTP-based threat rather than encrypted web traffic.

  • ✗

    Configure Anti-Spoofing on the internal interface to drop unverified encrypted packets.

    Why it's wrong here

    Anti-Spoofing validates source IP addresses against topology on an interface; it does not decrypt or inspect HTTPS payloads, so the encrypted C&C channel remains opaque. It is tempting because anti-spoofing genuinely drops forged-packet traffic, which would be correct when defending against IP spoofing rather than encrypted command-and-control.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.