As others have observed not sure exactly why you would want to do this, but to reinstall the Threat Prevention policy only and not the Access Control policy with it, the command would be fw amw fetch <MGMT IP Address>
The gateway dynamically receives pattern/signature updates for the various TP blades automatically, so there is no need to reinstall/fetch the AMW/TP policy to make those updates take effect.
Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones