CCSM Advanced Threat Prevention Practice Question
An administrator notices that the Anti-Bot software blade is generating numerous high-severity alerts for an internal server, but investigation reveals the traffic is generated by a legitimate corporate vulnerability scanner. Which action should the administrator take to prevent these false positives while maintaining maximum security for actual client subnets?
⚠ Common exam trap
Candidates often suggest adding the scanner to a global exclusion list or turning off Anti-Bot heuristics completely, rather than applying a precise exception rule for the specific source IP and signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a Threat Prevention exception for the vulnerability scanner source IP address and associated signatures.
Creating a Threat Prevention exception rule targeting the vulnerability scanner's source IP address and specific Anti-Bot protections prevents false positives without disabling protection globally. This precision ensures that security controls remain active for standard endpoints while accommodating specialized administrative tooling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the Anti-Bot software blade entirely on the internal security gateway security policy package.
Why it's wrong here
Disabling Anti-Bot globally removes protection against command and control communications, leaving all internal workstations vulnerable to active infections. Security policies should be fine-tuned using granular exceptions rather than compromising overall network posture for administrative convenience.
- ✓
Add a Threat Prevention exception for the vulnerability scanner source IP address and associated signatures.
Why this is correct
Threat Prevention exceptions allow administrators to exclude specific source IPs, destinations, or signature IDs from inspection. This targeted exclusion eliminates false positives generated by administrative scanners while keeping critical anti-bot defenses active for the rest of the network.
- ✗
Modify the Anti-Bot protection confidence level globally from Critical to High across all profiles.
Why it's wrong here
Altering the global confidence level weakens detection thresholds across all systems, potentially allowing actual sophisticated malware to slip past. Exceptions should always be scoped narrowly to specific assets rather than lowering security baselines across the entire enterprise.
- ✗
Change the Anti-Bot mode from Prevent to Detect mode for the entire internal security zone.
Why it's wrong here
Switching an entire zone to Detect mode means actual malware infections will only generate logs instead of being blocked in real time. Prevention mode is critical for stopping active command and control communication before data exfiltration occurs.
Visual reference
About these practice questions
One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.