Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Check Point Certified Threat Prevention Specialist (CTPS) Question and Answers

Check Point Certified Threat Prevention Specialist (CTPS)

Last Update May 30, 2026
Total Questions : 75

We are offering FREE 156-590 Checkpoint exam questions. All you do is to just go and sign up. Give your details, prepare 156-590 free exam questions and then go for complete pool of Check Point Certified Threat Prevention Specialist (CTPS) test questions that will help you more.

156-590 pdf

156-590 PDF

$36.75  $104.99
156-590 Engine

156-590 Testing Engine

$43.75  $124.99
156-590 PDF + Engine

156-590 PDF + Testing Engine

$57.75  $164.99
Questions 1

What is the name of the default Threat Prevention Profile?

Options:

A.  

Basic

B.  

Standard

C.  

Strict

D.  

Optimized

Discussion 0
Questions 2

Which of the following is a searchable field in IPS?

Options:

A.  

update time

B.  

protection

C.  

threat year

D.  

release date

Discussion 0
Questions 3

What is the purpose of the Profile Cleanup option?

Options:

A.  

It lets you start over by removing all administrator overrides.

B.  

It merges protection settings from multiple profiles into the Optimized Profile.

C.  

It serves as a cleanup policy if none of the protection matches the packets.

D.  

It eliminates protections automatically which hasn't been used for a predefined amount of time.

Discussion 0
Questions 4

Which is NOT true of Threat Prevention policy application?

Options:

A.  

Only applied after traffic is accepted by Access Control Policy

B.  

Traffic is matched against all applicable layers at the same time

C.  

Only applies first matched rule

D.  

Applied as ordered layer

Discussion 0
Questions 5

You have been asked to inform your CEO about last week's security incident.

What SmartEvent mechanism are you going to use?

Options:

A.  

You have to use Smart Event threat prevention View to get the information then extract it to csv format and then generate a pdf with this info.

B.  

The executive reports generally contain abstract information without much technical detail. You have to use Smart Event Threat Prevention Report filtered for last week data.

C.  

From the smart log you filter out traffic for last week and export it to a special report generate tool.

D.  

You have to build a view for last week and submit it to your CEO.

Discussion 0
Questions 6

Which mode allows you to tune or troubleshoot the Threat Prevention Blade?

Options:

A.  

Observe Mode

B.  

Detect Mode

C.  

Display Mode

D.  

Watch Mode

Discussion 0
Questions 7

What kind of blade is the IPS considered?

Options:

A.  

Preventative

B.  

Pre-infection

C.  

Inline

D.  

Post-infection

Discussion 0
Questions 8

What is a function of SmartEvent?

Options:

A.  

Runs on the Security Gateway generating events

B.  

Generates logs for customizable views

C.  

A Multi-Domain level log forwarding tool used to forward logs to syslog or similar external tools

D.  

Correlates Security Gateway logs into easily understandable events

Discussion 0
Questions 9

Where is IPS primarily enforced?

Options:

A.  

Post-infection

B.  

Post-inspection

C.  

Pre-infection

D.  

Pre-inspection

Discussion 0
Questions 10

Which is NOT an available setting under Custom Policy Tools?

Options:

A.  

IPS Protections

B.  

UserCheck

C.  

Indicators

D.  

Malicious Activity Detection

Discussion 0
Questions 11

How can the IPS Blade be activated?

Options:

A.  

The IPS Blade must be activated on the Management Server object and can be used on every gateway managed by this Management server.

B.  

No need to activate the IPS Blade as far as you have installed the correct IPS license on the gateways.

C.  

In a ClusterXL deployment, the IPS Blade must be activated on the individual cluster nodes.

D.  

The IPS Blade must be activated on the individual Security Gateway object.

Discussion 0
Questions 12

What does the IPS Follow Protections feature do?

Options:

A.  

Automatically activates new protections based on profile

B.  

Flags newly downloaded protections for review

C.  

Generates a report of activity from new protections

D.  

Highlights log entries for new protections

Discussion 0
Questions 13

What is necessary to do after an IPS Signature update?

Options:

A.  

Perform "Install Database".

B.  

Install the Threat Prevention Policy.

C.  

Those changes are immediately active.

D.  

Install the Access Control Policy.

Discussion 0
Questions 14

What type of layer is the threat Prevention?

Options:

A.  

It can be ordered or inline

B.  

Inline

C.  

Post Access Control follow-up layer

D.  

Ordered

Discussion 0
Questions 15

Which of the following protocols can be scanned by Anti-Virus?

Options:

A.  

RemoteDesktop

B.  

SNMP

C.  

CIFS

D.  

Telnet

Discussion 0
Questions 16

What are examples of evidence of compromises from inside network in conjunction with Bot-infected systems?

Options:

A.  

Users surfing the website directly by IP address or using domains registered within the last 30 days.

B.  

Trying to access web resources using explicit proxy servers instead of transparent ones.

C.  

Repetitive access to the same specific Intranet web servers within business hours.

D.  

Trying to access a web server via HTTP instead of HTTPS.

Discussion 0
Questions 17

Which feature can improve performance by allowing the gateway to bypass Anti-Virus inspection of specific files?

Options:

A.  

Content Control

B.  

Exclusions

C.  

Exceptions

D.  

Bypass

Discussion 0
Questions 18

What does the HealthCheck (HCP) tests include?

Options:

A.  

Assess Health of System

B.  

Assess Health of Console Connections

C.  

Assess Security of System

D.  

Assess status of SmartEvent System

Discussion 0
Questions 19

What is the default Anti-Virus protected scope interface settings?

Options:

A.  

DMZ

B.  

External and DMZ

C.  

External

D.  

All

Discussion 0
Questions 20

What is the action for newly updated protections which is set in Staging Mode?

Options:

A.  

Detect

B.  

Bypass

C.  

None

D.  

Prevent

Discussion 0
Questions 21

What deployment options for SmartEvent exist?

Options:

A.  

1. Standalone and 2. Distributed Deployment

B.  

1. Integrated/Standalone and 2. Dedicated Server

C.  

1. Prevent Mode and 2. Detect Mode

D.  

1. High Availability Mode and 2. Load Sharing Mode

Discussion 0
Questions 22

Which protection setting is generally the LEAST resource intensive?

Options:

A.  

Prevent

B.  

Inspect

C.  

Detect

D.  

Inactive

Discussion 0