Courseiva
Advanced Threat Prevention →mediumMultiple Choice

CCSM Advanced Threat Prevention Practice Question

An administrator is reviewing a Threat Prevention log and sees a high volume of 'Low Confidence' detections for a custom-protected HTTP header on a public-facing web server. The administrator wants to reduce noise while still logging these events for later analysis, without blocking legitimate traffic. What should the administrator do?

⚠ Common exam trap

The trap here is thinking that any log entry must be either blocked or ignored, when Check Point protections can be tuned by confidence to log only meaningful matches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adjust the protection's confidence level or severity threshold in the Threat Prevention profile to only log higher-confidence matches.

Tuning the confidence or severity threshold for the custom protection allows the administrator to filter out low-confidence matches that generate noise while still logging higher-confidence events. This maintains visibility for later analysis and avoids blocking legitimate traffic, unlike changing the action to Prevent, which would block, or disabling the protection, which would remove logging entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the protection entirely on the web server's Threat Prevention profile.

    Why it's wrong here

    Disabling the protection stops all inspection and logging for that signature, eliminating both noise and the security coverage it provides. The administrator explicitly wants to keep logging these events for later analysis, so turning off the protection defeats the purpose and removes a layer of defense against real attacks.

  • ✗

    Change the protection's action from Detect to Prevent on the relevant Threat Prevention profile.

    Why it's wrong here

    Switching to Prevent would block traffic matching the low-confidence signature, which risks blocking legitimate users and contradicts the goal of reducing noise without blocking. Low-confidence detections are more prone to false positives, so escalating the action increases the chance of disrupting valid traffic rather than reducing noise.

  • ✗

    Create an exception for the specific source IP addresses generating the low-confidence alerts.

    Why it's wrong here

    An exception would stop logging and inspection for those sources entirely, which hides the events instead of preserving them for analysis. The administrator wants to keep logging for later review, so excluding sources removes visibility and could allow real attacks from those addresses to go unnoticed.

  • ✓

    Adjust the protection's confidence level or severity threshold in the Threat Prevention profile to only log higher-confidence matches.

    Why this is correct

    Many Check Point protections allow tuning the confidence level at which the action is applied. Raising the threshold so only higher-confidence matches trigger the log entry reduces noise from low-confidence hits while still recording the more reliable events. This preserves visibility for analysis without blocking traffic, matching the administrator's requirement.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.