Exam 156-590 Topic 5 Question 3 Discussion

Actual exam question for CheckPoint's 156-590 exam
Question #: 3
Topic #: 5
Which protection setting is generally the MOST resource intensive?

Suggested Answer: B Vote an answer

The correct answer is B. Prevent . From a performance perspective, the most resource-intensive setting is generally the one that requires the gateway not only to inspect and identify the threat, but also to enforce a blocking decision inline. Prevent mode means the protection is actively applied to traffic and the gateway must make a real-time enforcement decision. Check Point explains that Threat Prevention profiles activate protections based on factors that include the performance impact of the protection , threat severity, confidence level, and blade-specific settings. Check Point's IPS optimization guidance also warns that some protections require more system resources to inspect traffic and recommends focusing on lower-impact protections when reducing gateway resource use is necessary.
By comparison, Inactive is the least intensive because the protection is not enforced. Detect can log or report detection without blocking, which is useful for staging and troubleshooting. Inspect still consumes inspection resources, but Prevent typically represents the highest operational burden because it performs inline analysis and enforcement, and may require buffering, stream handling, packet modification, or connection termination depending on blade and protocol. In real deployments, the exact resource cost also depends on traffic mix, protocol, file size, SSL inspection, protection complexity, and whether traffic remains accelerated. Reference topics: IPS Profile Settings, protection activation, Prevent versus Detect, Performance Impact, IPS optimization.

by vcm93737 at Oct 04, 2026, 01:07 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
vcm93737
2026-10-04 13:07:17
Selected Answer: D
Detect prevents the engine from dropping the packet early. The gateway is forced to carry the malicious payload through the entire remaining inspection pipeline and log generation engine, grinding down CPU cycles continuously without the performance saving "early exit" that a Prevent (drop) action provides.
Because Detect forces full traversal of the inspection stack for matching malicious streams without ever discarding the traffic, D. Detect is officially the most resource-intensive setting.
upvoted 1 times
...
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10