Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
In Anti-Virus, what is one of the benefits of Deep Scanning?
The correct answer is D. Thorough protection. Deep Scanning is selected when the organization wants broader and more complete Anti-Virus inspection, even at the cost of additional processing. Check Point's Anti-Virus settings documentation shows that administrators can configure file handling to process file types known to contain malware, process specific file-type families, or process all file types. It also states that enabling deep inspection scanning impacts performance.
This is the key tradeoff: Deep Scanning improves protection depth by expanding the set of files and content types subjected to inspection, but it is not the best choice for minimal latency or lowest resource consumption. Options A, B, and C are therefore incorrect because Deep Scanning is not primarily a performance optimization. It can require more CPU, memory, buffering, file classification, and scanning time, especially when paired with archive scanning, HTTPS Inspection, or large file transfers. Its benefit is security completeness: it reduces blind spots by inspecting more file content and providing stronger protection against malware hidden in less common or less obvious file types. Reference topics: Anti-Virus Settings, File Types, Deep Inspection Scanning, process all file types, performance impact, thorough malware protection.
Which location is NOT able to create a Threat Prevention Exception?
The correct answer is D. SmartView. Threat Prevention exceptions are created and managed in SmartConsole policy and log workflows, not from SmartView as the tested location. Check Point documentation states that an exception can be added directly to a rule, and the procedure begins by selecting the rule in the Policy pane and clicking Add Exception. It also documents creating exceptions from IPS Protections and from logs or events in the Logs & Monitor view, where the administrator right-clicks a log and selects Add Exception.
This validates Policy Rule, Log Overview, and Log Details-style workflows as valid exception creation contexts. SmartView, by contrast, is primarily used for browser-based log viewing, reporting, dashboards, and event analysis. It is not the SmartConsole policy-editing context where Threat Prevention exception rules are inserted into the policy package and then installed. The operational reason is enforcement integrity: exceptions modify the compiled Threat Prevention policy, so they must be created in a policy-aware workflow where protected scope, protection/site/file/blade, action, track, install targets, and policy installation are controlled. Reference topics: Exception Rules, Adding Exception to Rule, Creating Exceptions from Logs or Events, IPS Protections exceptions, Threat Prevention Policy installation.
What deployment options for SmartEvent exist?
The correct answer is B. 1. Integrated/Standalone and 2. Dedicated Server. SmartEvent is Check Point's event analysis, correlation, and reporting platform. Official Check Point Logging and Monitoring documentation explains that SmartEvent Server is integrated with the Security Management Server architecture and can communicate with Log Servers to read and analyze logs. It further states that administrators can enable SmartEvent on the Security Management Server or deploy it as a dedicated server. In Multi-Domain environments, Check Point requires SmartEvent on a dedicated server.
This maps directly to the course terminology: integrated or standalone deployment means SmartEvent runs on the existing management architecture, while a dedicated server deployment separates SmartEvent components onto another machine for scale, retention, performance, or Multi-Domain requirements. Option A uses generic distributed language but not the tested Check Point deployment wording. Option C confuses SmartEvent deployment with Threat Prevention enforcement states such as Prevent and Detect. Option D refers to clustering concepts and does not describe SmartEvent deployment models. In production design, dedicated SmartEvent is preferred when log volume is high, reporting is heavily used, or event correlation must not compete with management operations. Reference topics: Deploying SmartEvent, SmartEvent Server, Correlation Unit, Integrated/Standalone deployment, Dedicated SmartEvent Server.
Which is NOT a rating used in IPS Protection selection/activation?
The correct answer is B. CPU Utilization. IPS protection selection and activation are based on protection metadata and profile criteria, not a direct CPU-utilization rating. The official Threat Prevention guide states that a Threat Prevention profile activates protections according to factors including performance impact of the protection, severity of the threat, confidence that a protection can correctly identify an attack, and settings specific to the Software Blade.
The same R81.20 guide shows how the Optimized profile uses these criteria: protections are set to Prevent or Detect based on Confidence Level, Performance Impact, and Severity thresholds. CPU utilization is certainly relevant in performance troubleshooting, capacity planning, and operational monitoring, but it is not one of the IPS protection-selection ratings. In practice, CPU usage is an observed runtime metric, while Performance Impact is the predefined protection attribute used by profiles to decide whether a protection should be active, detect-only, or prevented. This distinction matters in certification: IPS tuning is driven by profile attributes, while CPU utilization is reviewed afterward through monitoring tools such as CPView, logs, and performance diagnostics. Reference topics: IPS Protection ratings, Threat Prevention Profiles, Severity, Confidence Level, Performance Impact, activation criteria.
What is an advantage of SmartEvent Reports over Views?
The correct answer is B. Reports can be delivered to users who are not Check Point administrators. SmartEvent Views are primarily interactive dashboards used by administrators and analysts for live investigation, drill-down, filtering, and operational analysis. Reports are designed for packaged distribution: they summarize security activity, policy enforcement, trends, and incident data into a consumable format. Check Point documentation states that views and reports can be exported to PDF or CSV using defined filters and time frames. It also documents scheduled report delivery, including the option to send a scheduled view or report automatically by email.
This delivery model is why reports are better suited for executives, auditors, business owners, and non-administrator stakeholders. They do not need SmartConsole access or Check Point administrator privileges to consume a PDF or scheduled email report. Option A describes Views more accurately because views are live and interactive. Option C is incorrect because reports do not inherently have more raw detail than views; they present selected information in a structured format. Option D is incorrect because both views and reports can be customized. Reference topics: SmartEvent Reports, Views and Reports, report scheduling, PDF/CSV export, email delivery, non-administrator reporting.
75 questions covering all exam domains, starting from $20
Exam domains verified against: Official CheckPoint 156-590 exam guide, last checked September 2026.
Verify the Security Environment and Connectivity Between Systems. Understand the evolution and significance of threat prevention technologies.
Enable and Configure Custom Threat Prevention. Configure the Inspection Settings, Update IPS Protections, Configure General and Specific Protections, Configure and Test Core Protections.
Sample question from this domain above: Q4
Enable Anti-Bot and Anti-Virus. Configure Anti-Bot and Anti-Virus protections for malware and botnet defense.
Sample question from this domain above: Q1
Create Custom Threat Prevention Profiles. Configure the Custom Profiles and Configure Anti-Bot and Anti-Virus in the Custom Profiles.
Configure Gateway Interface Settings. Configure Threat Prevention Policy Layers and Configure Threat Prevention Rules with Custom Profiles.
Modify Threat Prevention Logs and Configure SmartEvent Settings. Test Threat Prevention Protections, View Threat Prevention Logs and Events, Use Web SmartConsole to View Logs and Events.
Use IPS and Threat Prevention Exceptions. Create an Inspection Settings Exception and Create a Core Activations Exception.
Sample question from this domain above: Q2
Verify SmartEvent Activation. Generate and Verify Logs for Reporting, Configure SmartEvent Views and Reports.
Verify Recent Updates. Configure Update Settings for threat protection database updates.
Analyze Threat Prevention Performance. Create Penalty Box Exceptions and Null Profiles, Test the Panic Button Protocol.
Add a Custom SNORT Rule. Create and Test a Custom Threat Indicator, Observe Traffic Drops in Real Time, Audit Configuration Changes.
Common questions about the exam itself