Sign In
Home/Check Point/Check Point Certified Threat Prevention Specialist (CTPS)/Free questions

Check Point Certified Threat Prevention Specialist (CTPS) — Free Practice Questions

10 free sample questions from a bank of 39, with the correct answers and explanations. No signup required — start practising right now.

1At what point is the Anti-Bot blade enforced?
  • Pre-infection
  • Post-infection
  • Pre-inspection
  • Post-inspection
Answer: B

Category: Software Blades & Threat Mitigation Stage

The short version

The Anti-Bot blade is enforced post-infection to detect, isolate, and prevent command-and-control (C2) communication from already compromised hosts.

Key concepts in this question

  • Pre-infection vs. Post-infection: Pre-infection blades (such as IPS, Anti-Virus, and Threat Emulation) prevent malicious code from entering the network. Post-infection blades (Anti-Bot) identify systems that have already executed malware and are attempting outbound communication with botnet controllers.
  • Anti-Bot Mechanism: Analyzes network traffic for multi-tier bot signatures, domain name lookups (DGA), and anomalous traffic patterns tied to C2 infrastructure.

Why B is correct

Anti-Bot operates after an endpoint has been infected by malware. Its sole purpose is to identify compromised internal bots and prevent them from exfiltrating data or receiving instructions from bad actors.

Why the others are wrong

  • A. Pre-infection — Refers to preventative software blades like IPS or Anti-Virus that block exploits and payload execution before host infection occurs.
  • C. Pre-inspection — A non-standard stage in the Check Point threat model; inspection must occur to evaluate traffic.
  • D. Post-inspection — Refers to the processing stage after traffic analysis, not the biological/functional stage of host infection.

CTPS Exam Tip

Associate Anti-Bot strictly with Post-infection detection and IPS/Anti-Virus/Threat Emulation with Pre-infection prevention.

---

2Which protection setting is generally the LEAST resource intensive?
  • Prevent
  • Inspect
  • Detect
  • Inactive
Answer: D

Category: Threat Prevention Engine Optimization

The short version

The Inactive protection setting completely disables inspection for a given signature or rule, resulting in zero resource overhead.

Key concepts in this question

  • Action Settings: Protections within Check Point Threat Prevention profiles can be set to Prevent, Detect, Inspect, or Inactive.
  • Resource Consumption: Prevention involves packet modification and drop mechanisms; Detection involves logging; Inactive completely bypasses the inspection pipeline for that specific protection.

Why D is correct

Setting a protection to Inactive turns off inspection logic for that specific signature, meaning the gateway skips rule processing entirely, consuming zero CPU or memory resources for that check.

Why the others are wrong

  • A. Prevent — The most resource-intensive mode because it inspects traffic, creates logs, and generates blocking packets or resets connections.
  • B. Inspect — Performs full deep-packet inspection logic without issuing a drop action.
  • C. Detect — Performs packet analysis and log creation, requiring active engine execution.

CTPS Exam Tip

When asked for the least resource-intensive state, choose Inactive. When asked for the most resource-intensive state, choose Prevent.

---

3What is the primary benefit of DNS Trap?
  • Infected host identification
  • Blocking known bad URLs
  • Blocking outbound malicious DNS queries
  • Blocking inbound malicious DNS queries
Answer: A

Category: DNS Protection & Anti-Bot Mechanisms

The short version

The primary benefit of a DNS Trap is identifying infected internal hosts by intercepting malicious DNS queries and redirecting them to a dummy IP address.

Key concepts in this question

  • DNS Trap Operation: When an infected host requests an IP address for a known malicious domain, the Security Gateway responds with a configured "Bogus IP" (Trap IP).
  • Infected Host Identification: When the infected host subsequently attempts to initiate a connection to that Bogus IP, the gateway immediately flags and pinpoints the internal IP address of the compromised machine.

Why A is correct

Because malicious domains frequently change IP addresses, DNS Trap lures the infected host into connecting to a controlled dummy IP address, guaranteeing positive identification of the compromised client inside the local network.

Why the others are wrong

  • B. Blocking known bad URLs — Handled by the URL Filtering software blade.
  • C. Blocking outbound malicious DNS queries — A secondary operation; the primary diagnostic benefit is identifying which exact internal client is infected.
  • D. Blocking inbound malicious DNS queries — Anti-Bot and DNS Trap target outbound infected client activity requesting external command-and-control servers.

CTPS Exam Tip

Remember that DNS Trap = Bogus IP response = Infected Host Identification.

---

4What happens to traffic that matches the Access Control Policy but not the Threat Prevention Policy?
  • It is dropped and logged.
  • It is accepted.
  • The traffic is not dropped. It is simply not inspected by the Threat Prevention Engine.
  • It is accepted and logged.
Answer: C

Category: Policy Architecture & Packet Flow

The short version

Traffic matching Access Control but not Threat Prevention is accepted and allowed through without inspection by the Threat Prevention Engine.

Key concepts in this question

  • Sequential Inspection Pipeline: In Check Point architecture, traffic must first pass the Access Control Policy (Firewall/Application Control).
  • Policy Separation: The Access Control Policy determines basic connectivity (Accept/Drop). If accepted, traffic flows to the Threat Prevention Policy. If no Threat Prevention rule matches, default handling permits the traffic without threat inspection.

Why C is correct

Access Control grants network layer permission. Failing to match a Threat Prevention rule means no threat inspection engines (IPS, Anti-Virus, Anti-Bot) analyze the payload, but the packet is allowed through because Access Control accepted it.

Why the others are wrong

  • A. It is dropped and logged — Threat Prevention rules do not drop traffic by default if no rule matches; unmatched traffic falls back to default accept.
  • B. It is accepted — Incomplete statement; while it is accepted, the critical technical distinction is that Threat Engine inspection is bypassed.
  • D. It is accepted and logged — Logging only occurs if explicitly configured in rule tracking or cleanup properties.

CTPS Exam Tip

Access Control decides if traffic passes; Threat Prevention decides what inspection applies to accepted traffic. Unmatched traffic passes uninspected.

---

5Which is NOT a rating used in IPS Protection selection/activation?
  • Severity
  • CPU Utilization
  • Confidence Level
  • Performance Impact
Answer: B

Category: IPS Activation & Tuning

The short version

CPU Utilization is not a static protection rating used by Check Point to select or activate IPS protections; the core ratings are Severity, Confidence Level, and Performance Impact.

Key concepts in this question

  • IPS Protection Attributes: Every IPS signature in the ThreatCloud repository is rated by:
  • Severity (Critical, High, Medium, Low)
  • Confidence Level (High, Medium, Low)
  • Performance Impact (Very Low, Low, Medium, High)
  • Profile Activation Rules: Threat Prevention profiles use combinations of these three metrics to decide whether to activate signatures automatically.

Why B is correct

CPU Utilization is a real-time system performance metric, not an intrinsic classification attribute assigned to an IPS signature in SmartConsole.

Why the others are wrong

  • A. Severity — A standard rating measuring potential impact if an attack succeeds.
  • C. Confidence Level — A standard rating measuring the probability of accurate detection without false positives.
  • D. Performance Impact — A standard rating estimating the CPU/RAM load a signature imposes on the firewall gateway.

CTPS Exam Tip

The three pillars of IPS signature activation are Severity, Confidence Level, and Performance Impact. CPU Utilization is a runtime hardware counter.

---

6What is necessary to activate the exception to all Security Gateways?
  • Install Database is sufficient.
  • You have to re-install the Threat Prevention policy.
  • You have to re-install the Access Control policy.
  • The changes will be applied immediately, so no need to do anything.
Answer: B

Category: Policy Installation & Management

The short version

To apply an exception across all Security Gateways, you must re-install the Threat Prevention policy.

Key concepts in this question

  • Policy Packages: Check Point separates Access Control and Threat Prevention into distinct management layers or packages.
  • Policy Compilation: Changes made to Threat Prevention profiles, rules, or global exceptions remain staged in the management database until compiled and pushed via a Threat Prevention policy installation.

Why B is correct

Threat Prevention exceptions belong to the Threat Prevention Policy layer. Pushing changes requires initiating an explicit Threat Prevention policy installation to compile updated rules onto enforcement gateways.

Why the others are wrong

  • A. Install Database is sufficient — Install Database only updates management objects and user databases, not gateway threat inspection rules.
  • C. You have to re-install the Access Control policy — Access Control rule updates do not push Threat Prevention exception modifications.
  • D. The changes will be applied immediately — Check Point policy enforcement is explicit; staged modifications require policy compilation and installation.

CTPS Exam Tip

Threat Prevention changes require a Threat Prevention Policy Installation. Access Control changes require an Access Control Policy Installation.

---

7Which DNS Protection mechanism has been introduced with R81.20?
  • Propagation of a Bogus IP as a response to a DNS request.
  • Malware DNS Trap.
  • ThreatCloud DNS Tunneling Protection.
  • Synchronization of the /etc/hosts file from Protection servers.
Answer: C

Category: DNS Security & Platform Features

The short version

ThreatCloud DNS Tunneling Protection was introduced in R81.20 to detect and block malicious data exfiltration hiding inside DNS queries.

Key concepts in this question

  • DNS Tunneling: Cybercriminals use DNS request payloads (TXT, CNAME, A queries) to bypass firewalls and establish covert data exfiltration channels.
  • R81.20 Enhancements: R81.20 introduced AI-driven inline ThreatCloud DNS Tunneling protection to evaluate domain entropy, payload sizes, and query frequency in real time.

Why C is correct

R81.20 specifically added real-time ThreatCloud-driven DNS Tunneling protection to inspect recursive DNS queries for data leakage and covert C2 tunneling.

Why the others are wrong

  • A. Propagation of a Bogus IP — Part of the legacy DNS Trap functionality available in earlier software releases.
  • B. Malware DNS Trap — Standard legacy feature present well before R81.20.
  • D. Synchronization of the /etc/hosts file — Not a Check Point threat prevention security engine mechanism.

CTPS Exam Tip

Whenever an R81.20 DNS question mentions new protocol protections, select ThreatCloud DNS Tunneling Protection.

---

8Core Activation Exceptions are applied to what?
  • Protection Groups
  • Threat Cloud
  • Inspection Settings
  • Individual Protections
Answer: D

Category: IPS & Exception Management

The short version

Core Activation Exceptions are applied directly to Individual Protections within the IPS database.

Key concepts in this question

  • IPS Exception Hierarchy: Exceptions can be configured globally, per profile, or attached directly to specific individual signatures.
  • Core Activation Exception: Allows an administrator to override profile settings for a specific protection (e.g., setting a High Impact signature to Prevent for a single destination server).

Why D is correct

Core Activation Exceptions target explicit signature IDs (Individual Protections) to grant granular bypasses or enforcement overrides without altering the broader Threat Prevention profile.

Why the others are wrong

  • A. Protection Groups — Collections of protections based on vendor or application type, not the target of core activation exceptions.
  • B. Threat Cloud — The cloud threat intelligence database, not a gateway policy target.
  • C. Inspection Settings — Controls network-layer protocol handling (like TCP SYN enforcement), separate from threat signatures.

CTPS Exam Tip

Exceptions in IPS apply at the granular level: Individual Protections.

---

9SecureXL full acceleration happens on which component?
  • irq
  • snd
  • dynamic dispatcher
  • cpu core
Answer: B

Category: Performance Acceleration & SecureXL

The short version

SecureXL full acceleration processing occurs on the SND (Secure Network Distributor) component.

Key concepts in this question

  • SecureXL Architecture: Offloads traffic processing from the main Firewall Kernel (F2F path) to accelerated paths.
  • SND Core Responsibilities: Handles interrupt requests (IRQs), processes network traffic at Layer 2/3, and executes SecureXL acceleration code (SXL) before handing unaccelerated packets off to worker cores.

Why B is correct

The Secure Network Distributor (SND) runs the SecureXL code directly on dedicated interface processing cores, allowing packets matching accelerated connection tables to be processed entirely inside the SND without reaching Firewall worker cores.

Why the others are wrong

  • A. irq — Interrupt requests handled by hardware pins/drivers, not the software acceleration engine itself.
  • C. dynamic dispatcher — Distributes unaccelerated connections across Firewall worker cores.
  • D. cpu core — Generic term; specifically, the SND-assigned CPU core performs full acceleration.

CTPS Exam Tip

Full acceleration = SND core processing. Slow path / unaccelerated processing = F2F (Firewall Worker cores).

---

10What is a distinct limitation of Active Streaming compared to Passive Streaming in conjunction with Anti- Virus?
  • Only scheduled scans are possible.
  • File size limits.
  • There is no limitation.
  • Only a subset of file types supported.
Answer: D

Category: Anti-Virus Inspection Technologies

The short version

A key limitation of Active Streaming in Anti-Virus inspection is that only a subset of file types is supported.

Key concepts in this question

  • Streaming Technologies: Check Point Anti-Virus uses Active Streaming and Passive Streaming.
  • Active Streaming: Delays file delivery to the client while actively inspecting packets in real time. Because it holds protocol buffers, it only supports specific protocols and file formats.
  • Passive Streaming: Delivers streams to the endpoint while concurrently scanning, sending a reset if malware is detected before the final packet transfer.

Why D is correct

Active Streaming requires protocol-level buffering and parsing capabilities, limiting its capability to a defined subset of standard file types compared to full stream/file reconstruction.

Why the others are wrong

  • A. Only scheduled scans are possible — Anti-Virus operates inline on active traffic, not via static scheduled file system scans.
  • B. File size limits — Applies to both streaming and deep scan modes based on gateway memory thresholds.
  • C. There is no limitation — Protocol and file-type restrictions exist.

CTPS Exam Tip

Active Streaming = Subset of file types supported + Hold mode capability.

---

Want the full bank of 39 questions for Check Point Certified Threat Prevention Specialist (CTPS)? See all practice exams.