Courseiva

CCSM Advanced Threat Prevention Practice Question

An organization is concerned about data exfiltration via DNS tunneling. Which THREE configurations should be applied to the Threat Prevention policy to effectively mitigate this risk?

⚠ Common exam trap

Candidates often miss the multi-layered nature of the solution, selecting only one or two options. DNS tunneling requires a combination of protocol inspection, behavioral analysis, and domain reputation to be fully mitigated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Anti-Bot blade with updated signatures to detect C&C patterns.

DNS tunneling uses DNS queries to encapsulate non-DNS data for exfiltration or C&C communication. By enabling the Anti-Bot blade, the gateway can identify botnet-like DNS patterns. Activating IPS protections specific to DNS protocol anomalies detects malformed queries. Finally, configuring DNS Security (part of the Threat Prevention policy) allows for the blocking of malicious domains and detection of suspicious tunneling behaviors, creating a multi-layered defense against this specific exfiltration technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the Anti-Bot blade with updated signatures to detect C&C patterns.

    Why this is correct

    Anti-Bot is critical for detecting the command-and-control behavior associated with DNS tunneling. It tracks the communication patterns of infected hosts and can identify the systematic, periodic queries that are characteristic of automated exfiltration attempts, allowing the gateway to block the traffic before significant data is leaked from the network.

  • ✗

    Configure IPS to block all DNS traffic to external servers to prevent potential leaks.

    Why it's wrong here

    Blocking all external DNS traffic is not a viable strategy as it would break normal network functionality, including web browsing and email delivery. The goal is to identify and block the malicious *tunneling* behavior while allowing legitimate DNS queries, not to disable the core infrastructure of the network.

  • ✓

    Enable IPS protections related to DNS protocol anomalies and malformed DNS queries.

    Why this is correct

    IPS protocol enforcement is designed to catch traffic that deviates from standard protocol specifications. Attackers often use non-standard or malformed DNS packets to hide data within fields where it does not belong. IPS identifies these violations and drops the packets, effectively disrupting the exfiltration channel before the data is exfiltrated.

  • ✓

    Utilize DNS Security to block malicious domains and inspect DNS query traffic.

    Why this is correct

    DNS Security provides the necessary granular control to filter queries based on reputation and behavior. By blocking access to domains known to be used for malicious purposes and inspecting the structure of incoming/outgoing DNS requests, the organization can effectively prevent DNS-based tunneling and command-and-control communications from succeeding.

  • ✗

    Disable HTTPS inspection to reduce latency for DNS-over-HTTPS (DoH) traffic.

    Why it's wrong here

    Disabling HTTPS inspection would make it impossible to inspect DoH traffic, which is a common vehicle for modern DNS tunneling. To prevent this, administrators should actually enforce HTTPS inspection on all outgoing traffic to ensure that encrypted DNS queries can be analyzed by the security gateway for signs of malicious intent.

About these practice questions

One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.