The Anti-Bot blade is enforced post-infection to detect, isolate, and prevent command-and-control (C2) communication from already compromised hosts.
Key concepts in this question
Pre-infection vs. Post-infection: Pre-infection blades (such as IPS, Anti-Virus, and Threat Emulation) prevent malicious code from entering the network. Post-infection blades (Anti-Bot) identify systems that have already executed malware and are attempting outbound communication with botnet controllers.
Anti-Bot Mechanism: Analyzes network traffic for multi-tier bot signatures, domain name lookups (DGA), and anomalous traffic patterns tied to C2 infrastructure.
Why B is correct
Anti-Bot operates after an endpoint has been infected by malware. Its sole purpose is to identify compromised internal bots and prevent them from exfiltrating data or receiving instructions from bad actors.
Why the others are wrong
A. Pre-infection — Refers to preventative software blades like IPS or Anti-Virus that block exploits and payload execution before host infection occurs.
C. Pre-inspection — A non-standard stage in the Check Point threat model; inspection must occur to evaluate traffic.
D. Post-inspection — Refers to the processing stage after traffic analysis, not the biological/functional stage of host infection.
CTPS Exam Tip
Associate Anti-Bot strictly with Post-infection detection and IPS/Anti-Virus/Threat Emulation with Pre-infection prevention.
---
2Which protection setting is generally the LEAST resource intensive?
Prevent
Inspect
Detect
Inactive
Answer: D
Category: Threat Prevention Engine Optimization
The short version
The Inactive protection setting completely disables inspection for a given signature or rule, resulting in zero resource overhead.
Key concepts in this question
Action Settings: Protections within Check Point Threat Prevention profiles can be set to Prevent, Detect, Inspect, or Inactive.
Resource Consumption: Prevention involves packet modification and drop mechanisms; Detection involves logging; Inactive completely bypasses the inspection pipeline for that specific protection.
Why D is correct
Setting a protection to Inactive turns off inspection logic for that specific signature, meaning the gateway skips rule processing entirely, consuming zero CPU or memory resources for that check.
Why the others are wrong
A. Prevent — The most resource-intensive mode because it inspects traffic, creates logs, and generates blocking packets or resets connections.
B. Inspect — Performs full deep-packet inspection logic without issuing a drop action.
C. Detect — Performs packet analysis and log creation, requiring active engine execution.
CTPS Exam Tip
When asked for the least resource-intensive state, choose Inactive. When asked for the most resource-intensive state, choose Prevent.
---
3What is the primary benefit of DNS Trap?
Infected host identification
Blocking known bad URLs
Blocking outbound malicious DNS queries
Blocking inbound malicious DNS queries
Answer: A
Category: DNS Protection & Anti-Bot Mechanisms
The short version
The primary benefit of a DNS Trap is identifying infected internal hosts by intercepting malicious DNS queries and redirecting them to a dummy IP address.
Key concepts in this question
DNS Trap Operation: When an infected host requests an IP address for a known malicious domain, the Security Gateway responds with a configured "Bogus IP" (Trap IP).
Infected Host Identification: When the infected host subsequently attempts to initiate a connection to that Bogus IP, the gateway immediately flags and pinpoints the internal IP address of the compromised machine.
Why A is correct
Because malicious domains frequently change IP addresses, DNS Trap lures the infected host into connecting to a controlled dummy IP address, guaranteeing positive identification of the compromised client inside the local network.
Why the others are wrong
B. Blocking known bad URLs — Handled by the URL Filtering software blade.
C. Blocking outbound malicious DNS queries — A secondary operation; the primary diagnostic benefit is identifying which exact internal client is infected.
D. Blocking inbound malicious DNS queries — Anti-Bot and DNS Trap target outbound infected client activity requesting external command-and-control servers.
CTPS Exam Tip
Remember that DNS Trap = Bogus IP response = Infected Host Identification.
---
4What happens to traffic that matches the Access Control Policy but not the Threat Prevention Policy?
It is dropped and logged.
It is accepted.
The traffic is not dropped. It is simply not inspected by the Threat Prevention Engine.
It is accepted and logged.
Answer: C
Category: Policy Architecture & Packet Flow
The short version
Traffic matching Access Control but not Threat Prevention is accepted and allowed through without inspection by the Threat Prevention Engine.
Key concepts in this question
Sequential Inspection Pipeline: In Check Point architecture, traffic must first pass the Access Control Policy (Firewall/Application Control).
Policy Separation: The Access Control Policy determines basic connectivity (Accept/Drop). If accepted, traffic flows to the Threat Prevention Policy. If no Threat Prevention rule matches, default handling permits the traffic without threat inspection.
Why C is correct
Access Control grants network layer permission. Failing to match a Threat Prevention rule means no threat inspection engines (IPS, Anti-Virus, Anti-Bot) analyze the payload, but the packet is allowed through because Access Control accepted it.
Why the others are wrong
A. It is dropped and logged — Threat Prevention rules do not drop traffic by default if no rule matches; unmatched traffic falls back to default accept.
B. It is accepted — Incomplete statement; while it is accepted, the critical technical distinction is that Threat Engine inspection is bypassed.
D. It is accepted and logged — Logging only occurs if explicitly configured in rule tracking or cleanup properties.
CTPS Exam Tip
Access Control decides if traffic passes; Threat Prevention decides what inspection applies to accepted traffic. Unmatched traffic passes uninspected.
---
5Which is NOT a rating used in IPS Protection selection/activation?
Severity
CPU Utilization
Confidence Level
Performance Impact
Answer: B
Category: IPS Activation & Tuning
The short version
CPU Utilization is not a static protection rating used by Check Point to select or activate IPS protections; the core ratings are Severity, Confidence Level, and Performance Impact.
Key concepts in this question
IPS Protection Attributes: Every IPS signature in the ThreatCloud repository is rated by:
Severity (Critical, High, Medium, Low)
Confidence Level (High, Medium, Low)
Performance Impact (Very Low, Low, Medium, High)
Profile Activation Rules: Threat Prevention profiles use combinations of these three metrics to decide whether to activate signatures automatically.
Why B is correct
CPU Utilization is a real-time system performance metric, not an intrinsic classification attribute assigned to an IPS signature in SmartConsole.
Why the others are wrong
A. Severity — A standard rating measuring potential impact if an attack succeeds.
C. Confidence Level — A standard rating measuring the probability of accurate detection without false positives.
D. Performance Impact — A standard rating estimating the CPU/RAM load a signature imposes on the firewall gateway.
CTPS Exam Tip
The three pillars of IPS signature activation are Severity, Confidence Level, and Performance Impact. CPU Utilization is a runtime hardware counter.
---
6What is necessary to activate the exception to all Security Gateways?
Install Database is sufficient.
You have to re-install the Threat Prevention policy.
You have to re-install the Access Control policy.
The changes will be applied immediately, so no need to do anything.
Answer: B
Category: Policy Installation & Management
The short version
To apply an exception across all Security Gateways, you must re-install the Threat Prevention policy.
Key concepts in this question
Policy Packages: Check Point separates Access Control and Threat Prevention into distinct management layers or packages.
Policy Compilation: Changes made to Threat Prevention profiles, rules, or global exceptions remain staged in the management database until compiled and pushed via a Threat Prevention policy installation.
Why B is correct
Threat Prevention exceptions belong to the Threat Prevention Policy layer. Pushing changes requires initiating an explicit Threat Prevention policy installation to compile updated rules onto enforcement gateways.
Why the others are wrong
A. Install Database is sufficient — Install Database only updates management objects and user databases, not gateway threat inspection rules.
C. You have to re-install the Access Control policy — Access Control rule updates do not push Threat Prevention exception modifications.
D. The changes will be applied immediately — Check Point policy enforcement is explicit; staged modifications require policy compilation and installation.
CTPS Exam Tip
Threat Prevention changes require a Threat Prevention Policy Installation. Access Control changes require an Access Control Policy Installation.
---
7Which DNS Protection mechanism has been introduced with R81.20?
Propagation of a Bogus IP as a response to a DNS request.
Malware DNS Trap.
ThreatCloud DNS Tunneling Protection.
Synchronization of the /etc/hosts file from Protection servers.
Answer: C
Category: DNS Security & Platform Features
The short version
ThreatCloud DNS Tunneling Protection was introduced in R81.20 to detect and block malicious data exfiltration hiding inside DNS queries.
Key concepts in this question
DNS Tunneling: Cybercriminals use DNS request payloads (TXT, CNAME, A queries) to bypass firewalls and establish covert data exfiltration channels.
R81.20 Enhancements: R81.20 introduced AI-driven inline ThreatCloud DNS Tunneling protection to evaluate domain entropy, payload sizes, and query frequency in real time.
Why C is correct
R81.20 specifically added real-time ThreatCloud-driven DNS Tunneling protection to inspect recursive DNS queries for data leakage and covert C2 tunneling.
Why the others are wrong
A. Propagation of a Bogus IP — Part of the legacy DNS Trap functionality available in earlier software releases.
B. Malware DNS Trap — Standard legacy feature present well before R81.20.
D. Synchronization of the /etc/hosts file — Not a Check Point threat prevention security engine mechanism.
CTPS Exam Tip
Whenever an R81.20 DNS question mentions new protocol protections, select ThreatCloud DNS Tunneling Protection.
---
8Core Activation Exceptions are applied to what?
Protection Groups
Threat Cloud
Inspection Settings
Individual Protections
Answer: D
Category: IPS & Exception Management
The short version
Core Activation Exceptions are applied directly to Individual Protections within the IPS database.
Key concepts in this question
IPS Exception Hierarchy: Exceptions can be configured globally, per profile, or attached directly to specific individual signatures.
Core Activation Exception: Allows an administrator to override profile settings for a specific protection (e.g., setting a High Impact signature to Prevent for a single destination server).
Why D is correct
Core Activation Exceptions target explicit signature IDs (Individual Protections) to grant granular bypasses or enforcement overrides without altering the broader Threat Prevention profile.
Why the others are wrong
A. Protection Groups — Collections of protections based on vendor or application type, not the target of core activation exceptions.
B. Threat Cloud — The cloud threat intelligence database, not a gateway policy target.
C. Inspection Settings — Controls network-layer protocol handling (like TCP SYN enforcement), separate from threat signatures.
CTPS Exam Tip
Exceptions in IPS apply at the granular level: Individual Protections.
---
9SecureXL full acceleration happens on which component?
irq
snd
dynamic dispatcher
cpu core
Answer: B
Category: Performance Acceleration & SecureXL
The short version
SecureXL full acceleration processing occurs on the SND (Secure Network Distributor) component.
Key concepts in this question
SecureXL Architecture: Offloads traffic processing from the main Firewall Kernel (F2F path) to accelerated paths.
SND Core Responsibilities: Handles interrupt requests (IRQs), processes network traffic at Layer 2/3, and executes SecureXL acceleration code (SXL) before handing unaccelerated packets off to worker cores.
Why B is correct
The Secure Network Distributor (SND) runs the SecureXL code directly on dedicated interface processing cores, allowing packets matching accelerated connection tables to be processed entirely inside the SND without reaching Firewall worker cores.
Why the others are wrong
A. irq — Interrupt requests handled by hardware pins/drivers, not the software acceleration engine itself.
C. dynamic dispatcher — Distributes unaccelerated connections across Firewall worker cores.
D. cpu core — Generic term; specifically, the SND-assigned CPU core performs full acceleration.
10What is a distinct limitation of Active Streaming compared to Passive Streaming in conjunction with Anti- Virus?
Only scheduled scans are possible.
File size limits.
There is no limitation.
Only a subset of file types supported.
Answer: D
Category: Anti-Virus Inspection Technologies
The short version
A key limitation of Active Streaming in Anti-Virus inspection is that only a subset of file types is supported.
Key concepts in this question
Streaming Technologies: Check Point Anti-Virus uses Active Streaming and Passive Streaming.
Active Streaming: Delays file delivery to the client while actively inspecting packets in real time. Because it holds protocol buffers, it only supports specific protocols and file formats.
Passive Streaming: Delivers streams to the endpoint while concurrently scanning, sending a reset if malware is detected before the final packet transfer.
Why D is correct
Active Streaming requires protocol-level buffering and parsing capabilities, limiting its capability to a defined subset of standard file types compared to full stream/file reconstruction.
Why the others are wrong
A. Only scheduled scans are possible — Anti-Virus operates inline on active traffic, not via static scheduled file system scans.
B. File size limits — Applies to both streaming and deep scan modes based on gateway memory thresholds.
C. There is no limitation — Protocol and file-type restrictions exist.
CTPS Exam Tip
Active Streaming = Subset of file types supported + Hold mode capability.