Courseiva

CCSM Advanced Content Inspection Practice Question

An administrator is configuring HTTPS Inspection on an R81 Security Gateway. The organization uses a custom internal Certificate Authority (CA) for all internal web servers. The administrator wants to ensure that the gateway can inspect HTTPS traffic to these internal servers without generating certificate errors for users. What should the administrator do?

⚠ Common exam trap

Many candidates confuse the direction of trust: the gateway must trust the internal CA, not the other way around.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Import the internal CA certificate into the gateway's trusted CA list and enable HTTPS Inspection for the internal servers.

For HTTPS Inspection to work with internal servers using a custom CA, the gateway must trust that CA. Importing the internal CA certificate into the gateway's trusted CA list allows it to validate the servers' certificates during the inspection process. This ensures that the gateway can decrypt and inspect traffic without certificate errors. The gateway's own inspection CA remains separate and is used to sign certificates presented to clients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the gateway to use the internal CA as its own HTTPS Inspection certificate.

    Why it's wrong here

    The gateway uses its own HTTPS Inspection CA to generate certificates for inspected sites, not the internal CA. Using the internal CA for inspection would be inappropriate and could cause trust issues. The internal CA should be trusted by the gateway, not used as the inspection CA.

  • ✓

    Import the internal CA certificate into the gateway's trusted CA list and enable HTTPS Inspection for the internal servers.

    Why this is correct

    To inspect HTTPS traffic to internal servers using a custom CA, the gateway must trust that CA. Importing the internal CA certificate into the gateway's trusted CA list allows the gateway to validate the servers' certificates during inspection. This prevents certificate errors and enables successful decryption and inspection.

  • ✗

    Install the gateway's HTTPS Inspection CA certificate on the internal web servers.

    Why it's wrong here

    Installing the gateway's CA on internal web servers is not required and does not help. The gateway needs to trust the servers' CA, not the other way around. The servers present certificates signed by the internal CA; the gateway must trust that CA to validate them. Installing the gateway's CA on servers would not resolve inspection issues.

  • ✗

    Disable HTTPS Inspection for internal traffic to avoid certificate errors.

    Why it's wrong here

    Disabling HTTPS Inspection for internal traffic would prevent inspection of that traffic, which contradicts the goal of inspecting internal servers. While it would avoid certificate errors, it also creates a security gap. The administrator should instead configure trust to enable inspection without errors.

About these practice questions

One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.