
156-590 100% Pass Guaranteed Download CTPS Exam PDF Q&A
156-590 Practice Test Dumps with 100% Passing Guarantee
NEW QUESTION # 45
Task: Modify Anti-Bot to monitor C&C traffic only without blocking it.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open the custom profile in SmartConsole.
2- Under Anti-Bot, change all threat confidence levels to Detect.
3- Disable "Prevent" settings temporarily for testing.
4- Save the profile and apply to a staging policy rule.
5- Verify logs show detections without blocks.
NEW QUESTION # 46
What is a function of SmartEvent?
- A. Correlates Security Gateway logs into easily understandable events
- B. Runs on the Security Gateway generating events
- C. Generates logs for customizable views
- D. A Multi-Domain level log forwarding tool used to forward logs to syslog or similar external tools
Answer: A
Explanation:
The correct answer is D. Correlates Security Gateway logs into easily understandable events . SmartEvent is Check Point's event-correlation and analysis system. It does not simply generate raw logs; logs are generated by Security Gateways and other Check Point components. SmartEvent consumes those logs, analyzes them against event policies, identifies patterns, and produces higher-level events suitable for investigation, dashboards, reports, and incident workflows. Check Point documentation explains that the SmartEvent Correlation Unit analyzes each log entry from a Log Server, looks for patterns according to the installed Event Policy, and forwards identified events to the SmartEvent Server.
This directly eliminates the distractors. SmartEvent does not run on the Security Gateway as the log- generating enforcement component. It does not generate logs merely so views can be customized; rather, it indexes, correlates, and presents logs and events. It is not principally a Multi-Domain syslog-forwarding tool.
Its architectural value is correlation: it transforms large volumes of gateway logs into meaningful security events, reducing analyst workload and enabling threat timelines, reports, executive summaries, and incident management. Reference topics: SmartEvent Architecture, SmartEvent Correlation Unit, Event Policy, Log Server analysis, threat-event correlation.
NEW QUESTION # 47
Task: Verify if Anti-Bot and Anti-Virus protections are active on a Security Gateway.
Answer:
Explanation:
See the Explanation.Explanation:
1- SSH into the gateway.
2- Run: cpstat antimalware and cpstat anti-bot.
3- Confirm both blades are "Active" and signatures are "Up-to-date."
4- Check with cpview > Threat Prevention section.
5- Use watch -n 5 cpstat antimalware to monitor real-time status.
NEW QUESTION # 48
What is the purpose of the Packet Capture Track option?
- A. The security Gateway sends a packet capture file along with the log file. The former can by analyzed with an external tool, such as WireShark.
- B. You can specify a threshold value which serves as a limit after which the connection will be reset.
- C. You can specify the time after which the connection has to be reinitialized.
- D. You can visualize traffic information with a third-party XDR tool.
Answer: A
Explanation:
The correct answer is B. The Security Gateway sends a packet capture file along with the log file. The former can be analyzed with an external tool, such as Wireshark . Packet Capture is a tracking enhancement used when logs alone are not enough to understand the traffic that triggered a security event.
Check Point documentation explains that Packet Capture lets administrators capture network traffic and that the packet-capture content provides greater insight into the traffic that generated the log. When this feature is activated, the Security Gateway sends a packet-capture file with the log to the Log Server.
This is especially useful for IPS and Threat Prevention troubleshooting because analysts can inspect payload structure, headers, protocol behavior, retransmissions, and exact traffic context behind a prevention or detection event. Packet captures can then be opened in external protocol-analysis tools such as Wireshark for deeper investigation. Option A is incorrect because Packet Capture is not specifically an XDR visualization feature. Option C is unrelated to tracking and describes a timeout-style behavior. Option D describes threshold
/reset logic, not packet evidence collection. Reference topics: Packet Capture Track option, Logs & Monitor, Threat Prevention event analysis, IPS troubleshooting, packet-level evidence.
NEW QUESTION # 49
Task: Revert a mistakenly modified IPS protection to its default state.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to IPS Protections > Locate modified entry.
2- Click "Revert to Check Point default."
3- Confirm action and apply changes.
4- Publish and install policy.
5- Log actions confirm protection now behaves as default.
NEW QUESTION # 50
Task: Confirm proper DNS resolution from the Security Gateway.
Answer:
Explanation:
See the Explanation.Explanation:
1- SSH into the Gateway.
2- Run: nslookup checkpoint.com.
3- Validate /etc/resolv.conf for correct DNS servers.
4- Test with dig or host command.
5- Ensure outbound UDP/53 traffic is not being blocked.
NEW QUESTION # 51
What is the action for newly updated protections which is set in Staging Mode?
- A. None
- B. Prevent
- C. Detect
- D. Bypass
Answer: C
Explanation:
The correct answer is A. Detect . IPS Staging Mode is designed to introduce newly updated protections safely by observing their effect before enforcing active prevention. Check Point documentation states that when newly updated protections are set to Staging Mode , they remain in staging until the administrator changes their configuration. The default action for protections in staging mode is Detect , and this can be changed manually in the IPS Protections page. The R81.20 guide states the same behavior: newly updated protections in staging mode remain there until changed, and their default action is Detect.
This behavior is important during IPS lifecycle management because new signatures can introduce unexpected matches in production traffic. Detect mode allows the gateway to log and expose what the protection would have matched while avoiding immediate blocking. That gives administrators time to validate logs, tune exceptions, confirm confidence level, and assess business impact before switching to Prevent.
Bypass would skip inspection and is not the staging default. None is not the default action. Prevent may be the final desired enforcement state, but staging intentionally avoids immediate prevention until analysis is complete. Reference topics: IPS Updates Policy, Staging Mode, Newly Updated Protections, Detect action, IPS protection rollout.
NEW QUESTION # 52
That Tracking option can be used to capture additional data for analysis by Check Point TAC?
- A. Forensics
- B. User Defined
- C. SNMP
- D. Alert
Answer: A
Explanation:
The correct answer is B. Forensics . In Threat Prevention policy tracking, Forensics is the tracking option intended to enrich Threat Prevention logs with additional investigation data. Check Point documentation states that the Forensics option adds fields to the Threat Prevention logs , and that this extra information provides a deeper understanding of an attack. The Monitoring Threat Prevention section further explains that Advanced Forensics Details can appear in logs for supported protocols such as DNS, FTP, SMTP, HTTP, and HTTPS, and that this additional information is used by Check Point researchers to analyze attacks.
This is why Forensics is the correct TAC-oriented tracking choice. Alert is a notification-style tracking action, not a deep forensic enrichment mechanism. SNMP sends a management notification, and User Defined invokes administrator-defined alert handling rather than supplying advanced attack-analysis fields. In operational troubleshooting, Forensics is valuable because it preserves richer evidence around the inspected connection, affected blade, protocol behavior, and detection context. Reference topics: Threat Prevention Policy Track Options, Advanced Forensics Details, Logs & Monitor, TAC escalation analysis.
NEW QUESTION # 53
Task: Monitor if Anti-Bot is detecting lateral movement inside the network.
Answer:
Explanation:
See the Explanation.Explanation:
1- Use simulated internal bot communication in test lab.
2- Logs & Monitor > Filter blade:"Anti-Bot" and internal source/destination IPs.
3- Check behavior pattern logs, not just single IP detection.
4- Review communication timeline and triggered protections.
5- Use this to tune bot detection rules in the profile.
NEW QUESTION # 54
What are the three IPS update options?
- A. Update Now, Schedule Update, Follow policy
- B. Manual Update, Scheduled Update, Auto Update
- C. Update Now, Schedule Update, Follow Protections
- D. Auto Update, Policy Update, Update Now
Answer: C
Explanation:
The correct answer is B. Update Now, Schedule Update, Follow Protections . Check Point IPS protection maintenance includes manual updating, scheduled updating, and a follow-up workflow for newly updated protections. The official IPS Protections documentation explains that administrators can immediately update IPS from Custom Policy Tools > Updates > IPS > Update Now , and that IPS protections can also be updated by configuring a schedule for automatic downloads. It also notes that IPS updates require Threat Prevention Policy installation for enforcement.
The same IPS Protections section describes Follow Up behavior for protections: administrators can mark protections for follow-up, filter on them later, and updated protections can be automatically marked for follow- up so they can be reviewed after update. In the course-question wording, this maps to "Follow Protections." The purpose is operational control: update now provides immediate package retrieval, scheduled update automates routine maintenance, and follow protections gives administrators a practical workflow to review newly added or changed IPS protections. The other options either use non-standard names or omit the protection-review workflow. Reference topics: IPS Protections, Update Now, Scheduling IPS Updates, Follow Up Protections, Threat Prevention Policy installation.
NEW QUESTION # 55
Task: Exclude traffic to internal update servers from Anti-Virus scanning.
Answer:
Explanation:
See the Explanation.Explanation:
1- Open Threat Prevention Policy.
2- Add a rule: Source = Internal Gateway, Destination = AV Server.
3- Assign a profile with AV blade disabled.
4- Set Track = Log and Action = Accept.
5- Place rule before general AV rule, publish, and install.
NEW QUESTION # 56
Task: Simulate a malicious file download and validate AV detection.
Answer:
Explanation:
See the Explanation.Explanation:
1- In test environment, download EICAR test file.
2- Monitor logs: blade:"Anti-Virus" AND action:"Prevented".
3- Confirm file type, source IP, and destination file path.
4- Check associated protection name.
5- Ensure AV blade action is set to "Prevent."
NEW QUESTION # 57
Task: Create a custom Threat Prevention profile enabling only Anti-Bot and Anti-Virus protections.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Threat Prevention > Profiles.
2- Click "New Profile," name it (e.g., "AV_AB_Only").
3- Enable "Anti-Bot" and "Anti-Virus"; disable IPS and TE.
4- Set Action to "Prevent" for high/medium confidence threats.
5- Save and apply this profile to your Threat Prevention rule.
NEW QUESTION # 58
Task: Enable "Update Automatically" for IPS database.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Threat Prevention > Updates in SmartConsole.
2- Enable "Check for updates automatically."
3- Set interval (e.g., every 6 hours).
4- Tick "Install updates automatically" with warning prompt.
5- Click OK, publish, and monitor update logs.
NEW QUESTION # 59
Task: View logs of Anti-Bot detections in SmartConsole.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Logs & Monitor.
2- Use search filter: blade:"Anti-Bot" and time range = last 24 hours.
3- View events showing Botnet communication attempts.
4- Double-click logs to review source, domain contacted, and action taken.
5- Save filtered logs as report if needed.
NEW QUESTION # 60
Which statement is true concerning the Custom Policy Tools?
- A. Indicators - Configure indicators for benign activity.
- B. Allow List Files - Configure allowed files.
- C. Block List files - Configure disallowed files.
- D. Profiles - Edit profiles which are only available for Autonomous Threat Prevention.
Answer: C
Explanation:
The correct answer is A. Block List files - Configure disallowed files . Custom Policy Tools are used to manage Threat Prevention objects and enforcement helpers under the Threat Prevention policy view. A Block List file is used to define files that should be treated as disallowed, blocked, or explicitly malicious/undesired according to the policy objective. This is the opposite of the Allow List, which Check Point documents as a list of trusted files that the Threat Prevention engine does not inspect for malware, viruses, and bots, helping reduce gateway resource utilization. The official guide shows Allow List Files under Threat Prevention > Custom Policy Tools > Allow List Files .
Option A is therefore the correct true statement because it accurately describes the role of block-list file handling. Option B sounds plausible but is not the tested correct statement in this question's answer key; the course item is specifically validating the Block List definition. Option C is incorrect because indicators are not "benign activity"; indicators usually represent observables such as IPs, domains, URLs, or hashes used for threat intelligence or enforcement. Option D is incorrect because profiles are not only available for Autonomous Threat Prevention; Custom Threat Prevention also uses profiles such as Basic, Optimized, and Strict. Reference topics: Custom Policy Tools, Block List Files, Allow List Files, Indicators, Threat Prevention Profiles.
NEW QUESTION # 61
Task: Create a new Threat Prevention profile in SmartConsole.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Threat Prevention > Profiles.
2- Click "New Profile" and name it.
3- Adjust IPS, Anti-Bot, and AV settings to "Prevent" or "Detect."
4- Save and assign it to relevant policy layers.
5- Publish and install policy.
NEW QUESTION # 62
Task: Configure inspection settings for mobile VPN users.
Answer:
Explanation:
See the Explanation.Explanation:
1- Go to Threat Prevention > Inspection Settings.
2- Add a new exception group for mobile user IP pool.
3- Set reduced inspection sensitivity for this group.
4- Save, publish, and test VPN user traffic.
5- Ensure logs still show critical threats being detected.
NEW QUESTION # 63
Task: Configure protections against known CVEs.
Answer:
Explanation:
See the Explanation.Explanation:
1- Filter IPS Protections by CVE number (e.g., CVE-2023-XXXX).
2- Confirm CVE protection is available and enabled.
3- Set action to "Prevent."
4- Link it to custom profile.
5- Test and validate using test exploit traffic or logs.
NEW QUESTION # 64
Mike wants to block all files in the event of internal failure; what option should he choose?
- A. closed system
- B. fail-close
- C. open system
- D. fail-open
Answer: B
Explanation:
The correct answer is B. fail-close . Fail mode defines how the Threat Prevention inspection engine behaves when it is overloaded or experiences an internal failure. Check Point's Threat Prevention Engine Settings documentation defines two options: Allow all connections (Fail-open) and Block all connections (Fail- close) . Fail-open allows connections when the engine is overloaded or fails; Fail-close blocks connections in that condition.
Because the question specifically says Mike wants to block all files if an internal failure occurs, the secure choice is fail-close. This prioritizes protection and containment over availability. It is appropriate where allowing unscanned files would be unacceptable, such as highly regulated environments, malware-sensitive segments, or traffic paths carrying untrusted downloads. The tradeoff is operational: fail-close can interrupt business traffic if the inspection engine is unavailable, overloaded, or unable to complete the decision. Fail- open is the default availability-oriented behavior because it keeps traffic moving during failure, but it permits files or connections that may not have completed inspection. "Open system" and "closed system" are not the correct Check Point Threat Prevention fail-mode terms in this context. Reference topics: Threat Prevention Engine Settings, ThreatSpect fail mode, fail-open, fail-close, inspection failure handling.
NEW QUESTION # 65
......
156-590 PDF Dumps Are Helpful To produce Your Dreams Correct QA's: https://www.braindumpsit.com/156-590_real-exam.html
New 156-590 exam Free Sample Questions to Practice: https://drive.google.com/open?id=1IpH1iz8Zl8n1GAIC6qg4WAAhfaoQxqra