CCSM Advanced Threat Prevention Practice Question
An administrator is reviewing a Threat Prevention log and sees a high volume of 'Low Confidence' detections for a custom-protected HTTP header on a public-facing web server. The administrator wants to reduce noise while still logging these events for later analysis, without blocking legitimate traffic. What should the administrator do?
⚠ Common exam trap
The trap here is thinking that any log entry must be either blocked or ignored, when Check Point protections can be tuned by confidence to log only meaningful matches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adjust the protection's confidence level or severity threshold in the Threat Prevention profile to only log higher-confidence matches.
Tuning the confidence or severity threshold for the custom protection allows the administrator to filter out low-confidence matches that generate noise while still logging higher-confidence events. This maintains visibility for later analysis and avoids blocking legitimate traffic, unlike changing the action to Prevent, which would block, or disabling the protection, which would remove logging entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the protection entirely on the web server's Threat Prevention profile.
Why it's wrong here
Disabling the protection stops all inspection and logging for that signature, eliminating both noise and the security coverage it provides. The administrator explicitly wants to keep logging these events for later analysis, so turning off the protection defeats the purpose and removes a layer of defense against real attacks.
- ✗
Change the protection's action from Detect to Prevent on the relevant Threat Prevention profile.
Why it's wrong here
Switching to Prevent would block traffic matching the low-confidence signature, which risks blocking legitimate users and contradicts the goal of reducing noise without blocking. Low-confidence detections are more prone to false positives, so escalating the action increases the chance of disrupting valid traffic rather than reducing noise.
- ✗
Create an exception for the specific source IP addresses generating the low-confidence alerts.
Why it's wrong here
An exception would stop logging and inspection for those sources entirely, which hides the events instead of preserving them for analysis. The administrator wants to keep logging for later review, so excluding sources removes visibility and could allow real attacks from those addresses to go unnoticed.
- ✓
Adjust the protection's confidence level or severity threshold in the Threat Prevention profile to only log higher-confidence matches.
Why this is correct
Many Check Point protections allow tuning the confidence level at which the action is applied. Raising the threshold so only higher-confidence matches trigger the log entry reduces noise from low-confidence hits while still recording the more reliable events. This preserves visibility for analysis without blocking traffic, matching the administrator's requirement.
Visual reference
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.