Courseiva

CCSM Advanced Threat Prevention Practice Question

An administrator is hardening a Threat Prevention policy against zero-day exploits. The goal is to reduce exposure to unknown exploits while limiting false positives on business-critical applications. Which TWO measures are appropriate for this objective? (Choose two.)

⚠ Common exam trap

The trap here is treating false-positive avoidance as a reason to broadly exempt critical servers, which removes protection from the very assets being hardened.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the relevant IPS protections, including those marked as high confidence for the affected services, and set the profile to Prevent.

Hardening against zero-day exploits calls for complementary layers. Enabling high-confidence IPS protections in Prevent mode blocks known exploitation techniques on the services in use, while Threat Emulation detonates unknown files delivered to critical hosts and blocks malicious ones. Scoping emulation to critical hosts manages performance, and high-confidence IPS keeps false positives low, together reducing exposure without broadly exempting valuable assets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the relevant IPS protections, including those marked as high confidence for the affected services, and set the profile to Prevent.

    Why this is correct

    Enabling IPS protections that match the services in use, especially high-confidence ones, and enforcing them in Prevent mode directly reduces exploit exposure while keeping false positives manageable. High-confidence protections are tuned to fire reliably, so they are a sound first line for zero-day defense. This aligns with reducing unknown-exploit risk on business-critical services.

  • ✓

    Configure Threat Emulation to inspect files delivered to business-critical hosts and act in Prevent mode for unknown files.

    Why this is correct

    Emulation detonates unknown files in a sandbox, catching zero-day payloads that signature-based protections miss. Applying it to critical hosts and blocking unknown malicious files in Prevent mode closes the gap for file-borne exploits. This complements IPS by addressing the delivery vector, and scoping it to critical hosts keeps the performance impact contained.

  • ✗

    Add broad exceptions for all protections on business-critical servers to eliminate any chance of false positives.

    Why it's wrong here

    Blanket exceptions remove protection from exactly the assets that matter most. While they eliminate false positives, they also reopen the exploit surface the exercise is trying to shrink. The objective is to reduce exposure, not to exempt critical servers from inspection. Targeted, documented exceptions for verified benign behavior are acceptable, but broad ones undermine the goal.

  • ✗

    Rely solely on Anti-Bot to block command-and-control callbacks, since exploit traffic is always part of a botnet.

    Why it's wrong here

    Anti-Bot targets outbound command-and-control and malware communication, not the initial exploit delivery or exploitation itself. Exploit traffic does not always involve a botnet, so relying on Anti-Bot alone leaves the exploit path open. Defense in depth requires IPS and emulation in addition to Anti-Bot, not instead of them.

  • ✗

    Disable IPS protections rated as low confidence to reduce noise, leaving only medium and high confidence enabled.

    Why it's wrong here

    Low-confidence protections often flag genuinely suspicious behavior that high-confidence signatures miss, and they can be valuable for zero-day coverage when tuned. Removing them wholesale reduces detection breadth, which conflicts with the hardening objective. A better approach is to review and tune noisy protections rather than disable an entire confidence tier.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.