Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

A security administrator is configuring a Check Point R81 gateway running Threat Emulation and Threat Extraction blades. They want to ensure that files downloaded by users are inspected and, when necessary, sanitized before delivery. Which two of the following statements correctly describe the behavior of Threat Extraction? (Choose two.)

⚠ Common exam trap

Candidates often confuse Threat Extraction with Threat Emulation, where Emulation analyzes files in a sandbox and blocks malicious ones, while Extraction sanitizes and delivers safe content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Extraction removes potentially malicious content from supported file types and delivers a sanitized version to the user.

Threat Extraction sanitizes supported files by removing active content and delivers a safe version to the user. It can also reconstruct the original file if needed and if the file is clean. These two behaviors are fundamental to the blade's operation and align with the administrator's goal of inspecting and sanitizing downloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Threat Extraction requires a separate license and is not included with the Threat Prevention blades.

    Why it's wrong here

    Threat Extraction is part of the Check Point Threat Prevention suite and is licensed under the SandBlast subscription. It does not require a separate license beyond the SandBlast package. This statement is incorrect and would cause unnecessary licensing confusion for the administrator.

  • ✗

    Threat Extraction only works on files transferred over HTTP and does not support SMTP or FTP.

    Why it's wrong here

    Threat Extraction supports multiple protocols, including HTTP, SMTP, FTP, and others, depending on the gateway configuration. It is not limited to HTTP. This statement incorrectly narrows the scope of the blade and would mislead an administrator configuring comprehensive protection across different traffic types.

  • ✓

    Threat Extraction removes potentially malicious content from supported file types and delivers a sanitized version to the user.

    Why this is correct

    Threat Extraction is designed to strip active content such as macros, embedded objects, and scripts from files, delivering a clean, safe version to the user. This allows the user to access the file's content without the risk of executing malicious code. This behavior is the core function of the Threat Extraction blade and is correct in this scenario.

  • ✓

    Threat Extraction can reconstruct the original file if the user requires the removed content, provided the original is deemed safe.

    Why this is correct

    Threat Extraction can retain the original file and allow reconstruction if the user needs the full content. This is often used when the sanitized version lacks necessary functionality. The original is stored securely, and reconstruction is permitted only if the file is clean. This feature is part of the Threat Extraction blade's capabilities in R81.

  • ✗

    Threat Extraction sends the original file to ThreatCloud for analysis and blocks it if malicious.

    Why it's wrong here

    Threat Extraction does not send files to ThreatCloud for analysis; that is the role of Threat Emulation. Threat Extraction locally sanitizes files by removing risky content and delivering a safe version. It does not rely on cloud analysis to block files. Therefore, this statement misrepresents the function of Threat Extraction in this scenario.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.