CCSM Advanced Threat Prevention Practice Question
A security analyst is investigating a malware outbreak and needs to identify the command and control (C&C) infrastructure used by the malware. The analyst has access to Check Point ThreatCloud and SmartLog. Which two actions should the analyst take to identify the C&C servers? (Choose two.)
⚠ Common exam trap
The trap here is focusing on host-based remediation instead of network-based threat intelligence to identify C&C servers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query ThreatCloud for the malware's hash to retrieve associated C&C IP addresses.
ThreatCloud provides a repository of malware indicators, including C&C IPs linked to file hashes, and Anti-Bot logs capture outbound C&C traffic. Together, these actions efficiently identify C&C infrastructure. The other options are either less direct or focus on host remediation rather than network indicators.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the Threat Emulation report for the malware sample to see if it lists C&C domains.
Why it's wrong here
Threat Emulation reports focus on behavior and may include network activity, but they do not always list C&C domains. While useful, it is not a reliable primary method to identify C&C servers. The question asks for actions to identify C&C, and this is less direct than ThreatCloud or Anti-Bot logs.
- ✗
Analyze firewall logs for inbound connections from known malicious IPs.
Why it's wrong here
Firewall logs show inbound connections, but C&C communication is typically outbound from the infected host. Analyzing inbound connections is less likely to reveal C&C servers. This action is not as effective as checking outbound Anti-Bot logs or ThreatCloud.
- ✓
Query ThreatCloud for the malware's hash to retrieve associated C&C IP addresses.
Why this is correct
ThreatCloud maintains a database of malware indicators, including C&C IPs associated with file hashes. Querying by hash can reveal known C&C infrastructure. This is a direct method to identify C&C servers using Check Point's threat intelligence.
- ✓
Review Anti-Bot logs in SmartLog for outbound connections to suspicious IPs.
Why this is correct
Anti-Bot logs record outbound connections that match botnet patterns, including C&C communication. Reviewing these logs can identify the C&C servers the malware is contacting. This is a key step in incident response within Check Point environments.
- ✗
Run a full system scan on the infected host using Anti-Virus.
Why it's wrong here
A full system scan detects malware on the host but does not directly identify C&C servers. While it may remove the malware, it does not provide network indicators. The goal is to identify C&C infrastructure, not just clean the host.
About these practice questions
One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.