CCSM Advanced Threat Prevention Practice Question
An administrator configures Threat Prevention on a Check Point Security Gateway to inspect incoming SMTP traffic using Threat Emulation and Threat Extraction. A user reports that a legitimate archive file containing confidential reports was modified, and all executable files inside the archive were stripped out. Which configuration adjustment resolves this while maintaining adequate security?
⚠ Common exam trap
Candidates often confuse Threat Extraction settings with Threat Emulation overrides, selecting global bypasses that completely disable security inspection instead of targeting specific file types or extension lists within the profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure file type exclusions or specify safe extension lists within the Threat Extraction profile.
Configuring file type exclusions within the Threat Extraction profile allows specific trusted extensions or container formats to bypass active content removal. This enables users to receive intact compressed archives while still maintaining inspection coverage for standard untrusted file types and executable attachments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable Threat Emulation globally and enable traditional antivirus signature pattern matching only.
Why it's wrong here
Disabling Threat Emulation removes sandbox detonation for all traffic and leaves only signature matching, which cannot detect zero-day or polymorphic malware, weakening protection beyond the reported archive issue. It is tempting because signature-only inspection avoids file modification entirely, and it would be correct where emulation is unsupported or strictly prohibited by policy.
- ✓
Configure file type exclusions or specify safe extension lists within the Threat Extraction profile.
Why this is correct
Threat Extraction strips executables from archives by default, which altered the legitimate file. Configuring file type exclusions or safe extension lists preserves the archive's contents while Threat Emulation continues inspecting it, maintaining security without modifying trusted business files.
- ✗
Switch the Threat Extraction action from 'Prevent' to 'Detect' mode for inbound email vectors.
Why it's wrong here
Switching to 'Detect' mode logs the presence of active content but does not stop Threat Extraction from modifying or stripping files during inline MTA processing. Furthermore, Detect mode lowers the security posture by allowing malicious files to reach user inboxes.
- ✗
Increase the Threat Extraction maximum inspection file size threshold to 500 MB.
Why it's wrong here
Increasing the file size limit ensures larger files are inspected rather than skipped, which would result in more files being processed and stripped, not fewer. Size thresholds dictate whether inspection occurs based on file volume, not how active content is handled.
Visual reference
About these practice questions
One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.