Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

A Check Point R81 gateway is using Threat Emulation. An administrator observes that a PDF file was emulated, and the log shows the verdict as 'Malicious'. However, the user was able to open the file without any warning. What is the most likely cause of this behavior?

⚠ Common exam trap

The trap here is assuming that a malicious verdict always results in a block, but the blade's mode (Detect vs. Prevent) determines whether the file is actually blocked.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Threat Emulation blade was configured in 'Detect' mode instead of 'Prevent' mode.

The most likely cause is that Threat Emulation is configured in Detect mode, which only logs malicious files without blocking them. This allows users to open the file despite the malicious verdict. Switching to Prevent mode would block the file and prevent user access, aligning with the security policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The PDF file was corrupted and could not be executed, so it was allowed.

    Why it's wrong here

    If the file was corrupted, Threat Emulation might not return a malicious verdict. A malicious verdict indicates the file was analyzed and found to be harmful. Corruption would not lead to an allowed action; it would likely result in an emulation error, not a malicious log.

  • ✓

    The Threat Emulation blade was configured in 'Detect' mode instead of 'Prevent' mode.

    Why this is correct

    Threat Emulation can be set to Detect or Prevent mode. In Detect mode, malicious files are logged but not blocked, allowing the user to access them. This matches the observed behavior where the file was opened despite a malicious verdict. The administrator should switch to Prevent mode to block such files.

  • ✗

    The file was downloaded over HTTPS, which bypasses Threat Emulation.

    Why it's wrong here

    Threat Emulation can inspect files over HTTPS if HTTPS inspection is enabled. If it were bypassed, the log would not show a malicious verdict. Since the log shows emulation occurred and a verdict was reached, this is not the cause.

  • ✗

    The user has administrative privileges and overrode the block.

    Why it's wrong here

    Threat Emulation does not provide a user override option for malicious files. If the file was blocked, the user would not be able to open it. The fact that the user opened it suggests the file was not blocked, not that an override occurred.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.