Courseiva

CCSM Advanced Threat Prevention Practice Question

A security analyst is investigating a malware outbreak and needs to identify the command and control (C&C) infrastructure used by the malware. The analyst has access to Check Point ThreatCloud and SmartLog. Which two actions should the analyst take to identify the C&C servers? (Choose two.)

⚠ Common exam trap

The trap here is focusing on host-based remediation instead of network-based threat intelligence to identify C&C servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query ThreatCloud for the malware's hash to retrieve associated C&C IP addresses.

ThreatCloud provides a repository of malware indicators, including C&C IPs linked to file hashes, and Anti-Bot logs capture outbound C&C traffic. Together, these actions efficiently identify C&C infrastructure. The other options are either less direct or focus on host remediation rather than network indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check the Threat Emulation report for the malware sample to see if it lists C&C domains.

    Why it's wrong here

    Threat Emulation reports focus on behavior and may include network activity, but they do not always list C&C domains. While useful, it is not a reliable primary method to identify C&C servers. The question asks for actions to identify C&C, and this is less direct than ThreatCloud or Anti-Bot logs.

  • ✗

    Analyze firewall logs for inbound connections from known malicious IPs.

    Why it's wrong here

    Firewall logs show inbound connections, but C&C communication is typically outbound from the infected host. Analyzing inbound connections is less likely to reveal C&C servers. This action is not as effective as checking outbound Anti-Bot logs or ThreatCloud.

  • ✓

    Query ThreatCloud for the malware's hash to retrieve associated C&C IP addresses.

    Why this is correct

    ThreatCloud maintains a database of malware indicators, including C&C IPs associated with file hashes. Querying by hash can reveal known C&C infrastructure. This is a direct method to identify C&C servers using Check Point's threat intelligence.

  • ✓

    Review Anti-Bot logs in SmartLog for outbound connections to suspicious IPs.

    Why this is correct

    Anti-Bot logs record outbound connections that match botnet patterns, including C&C communication. Reviewing these logs can identify the C&C servers the malware is contacting. This is a key step in incident response within Check Point environments.

  • ✗

    Run a full system scan on the infected host using Anti-Virus.

    Why it's wrong here

    A full system scan detects malware on the host but does not directly identify C&C servers. While it may remove the malware, it does not provide network indicators. The goal is to identify C&C infrastructure, not just clean the host.

About these practice questions

One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.