Exam 156-590 Topic 2 Question 74 Discussion
Actual exam question for CheckPoint's 156-590 exam
Question #: 74
Topic #: 2
Question #: 74
Topic #: 2
What does the IPS Follow Protections feature do?
Suggested Answer: A Vote an answer
The correct answer is A. Automatically activates new protections based on profile . IPS protections are governed by Threat Prevention profiles, and those profiles determine which protections are activated for a rule or policy. Check Point documentation states that a Threat Prevention profile determines which protections are activated and which Software Blades are enabled for the specified rule or policy. For newly downloaded IPS protections, Check Point documents that automatic IPS update behavior can use the profile settings as the default action for those newly downloaded protections.
This is the core logic behind the answer: IPS Follow Protections aligns newly available protections with the active profile's protection-selection logic instead of requiring the administrator to manually evaluate and activate every update. The profile already contains the criteria for activation, including threat severity, confidence, and performance considerations. Option B describes a different review-oriented workflow, commonly associated with marking protections for follow-up or staging. Option C is incorrect because reporting is a SmartEvent or logging function, not the purpose of Follow Protections. Option D is also incorrect because highlighting log entries does not activate enforcement. Reference topics: IPS profile settings, newly updated IPS protections, automatic update behavior, activation according to profile settings, IPS protection lifecycle.
This is the core logic behind the answer: IPS Follow Protections aligns newly available protections with the active profile's protection-selection logic instead of requiring the administrator to manually evaluate and activate every update. The profile already contains the criteria for activation, including threat severity, confidence, and performance considerations. Option B describes a different review-oriented workflow, commonly associated with marking protections for follow-up or staging. Option C is incorrect because reporting is a SmartEvent or logging function, not the purpose of Follow Protections. Option D is also incorrect because highlighting log entries does not activate enforcement. Reference topics: IPS profile settings, newly updated IPS protections, automatic update behavior, activation according to profile settings, IPS protection lifecycle.
by vcm93737 at Oct 04, 2026, 12:25 PM
0
0
0
10
Comments
vcm93737
2026-10-04 12:25:08• The Practical Function: When you activate this feature for updates, it automatically marks newly downloaded or updated protections with a visual flag. This acts as a working task list for administrators, allowing them time to manually evaluate, test, or fine-tune new signatures before they fully enforce them across their environments
Option A — "Automatically activates new protections based on profile" — is incorrect because that describes what the assigned Threat Prevention profile does, not what "Follow Protections" does.
Here's the distinction:
Activation of new protections is governed by the profile settings (Severity, Confidence Level, Performance Impact thresholds) assigned to a rule. When a new protection is downloaded, whether it's turned on automatically is decided by whether it matches the active/inactive criteria already configured in that profile (e.g., the Optimized profile auto-activates protections meeting certain Severity/Performance thresholds). That activation logic belongs to the profile, not to "Follow Protections."
"Follow Protections" is a separate, distinct mechanism: it simply marks/flags newly downloaded or updated protections so an administrator can go find and review them — it's a review/tracking aid, not an activation engine. This is explicitly what your internal lab doc describes:"To be able to tell which protection were updated, they are marked by default. Review the settings under 'Follow Protections.'"
So A conflates two different things that Check Point treats separately — profile-driven auto-activation vs. Follow Protections' flag-for-review function. Since the question specifically asks what the Follow Protections feature does, A describes the wrong mechanism, and B is the one that matches its actual documented purpose.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).