CCSM Advanced Security Management Practice Question
When reviewing the 'Threat Prevention' policy, an administrator notices that some rules are set to 'Prevent' while others are set to 'Detect'. What is the functional difference between these two actions?
⚠ Common exam trap
Candidates often assume 'Detect' mode will block traffic if the threat is severe enough, failing to understand that 'Detect' explicitly disables the blocking mechanism regardless of the threat's severity score.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prevent blocks traffic, Detect allows it.
The 'Prevent' action actively blocks malicious traffic based on the signature or anomaly detected, providing real-time protection. 'Detect' only logs the malicious activity without blocking the packet, allowing it to pass through the gateway. Understanding this distinction is vital for tuning the Security Gateway, as it allows administrators to monitor new traffic patterns without risking false positives that could disrupt legitimate business operations before finalizing security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prevent sends logs to the SIEM, Detect does not.
Why it's wrong here
Both Prevent and Detect actions generate logs and can be configured to send them to a SIEM. The difference lies in the traffic handling (blocking vs. allowing), not the log logging capability. Security teams often use both actions to ensure comprehensive visibility, regardless of whether the traffic is ultimately permitted.
- ✓
Prevent blocks traffic, Detect allows it.
Why this is correct
The primary functional difference is that Prevent drops malicious packets, while Detect allows them to continue while recording the incident. This is essential for phased deployment of security blades, where administrators 'detect' potential threats to test the policy before switching to 'prevent' mode to enforce the security posture.
- ✗
Prevent uses high-priority, Detect uses low-priority.
Why it's wrong here
Prioritization of traffic is handled by the security policy rules and kernel-level flow handling, not by the Threat Prevention action mode. Both actions are processed by the same inspection engine; the only difference is the final decision made on the packet flow after the inspection signature match is confirmed.
- ✗
Detect is only available for IPS, not Anti-Bot.
Why it's wrong here
Both IPS and Anti-Bot (as well as Anti-Virus) support both Prevent and Detect modes. These modes are universal across the Threat Prevention blade set. Limiting the understanding of these modes to a single blade is incorrect and fails to recognize the cross-blade utility of these defensive strategies in Check Point security.
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.