Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

A security administrator notices that a user downloaded a file that was flagged as malicious by Threat Emulation, but the file was not blocked. The Threat Prevention policy shows that the Threat Emulation blade is set to 'Detect' mode for that user group. What is the most likely reason the file was not blocked?

⚠ Common exam trap

Test-takers frequently confuse detection with prevention, assuming that any flag automatically blocks the file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Threat Emulation blade is configured to only detect and not block malicious files.

When Threat Emulation is set to Detect mode, it logs malicious files but does not block them. To block, the action must be Prevent. The scenario shows the file was flagged, so the blade is active, but the action is set to Detect, resulting in no block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user has administrator privileges, which bypass Threat Emulation blocking.

    Why it's wrong here

    Administrator privileges do not automatically bypass Threat Emulation. The policy applies based on user group and blade configuration. Privileges might affect access to certain features, but they do not override threat prevention actions in this context.

  • ✗

    The file was not actually malicious; the detection was a false positive.

    Why it's wrong here

    The scenario states the file was flagged as malicious by Threat Emulation, indicating a positive detection. A false positive would be incorrect here because the system identified it as malicious; the issue is the action taken, not the detection accuracy.

  • ✓

    The Threat Emulation blade is configured to only detect and not block malicious files.

    Why this is correct

    In Detect mode, Threat Emulation does not block malicious files; it only logs the detection. The administrator must change the action to 'Prevent' to block such files. This matches the scenario where the file was flagged but not blocked.

  • ✗

    The Threat Emulation blade is not enabled for the user's group.

    Why it's wrong here

    If the blade were not enabled, the file would not have been flagged at all. The scenario indicates the file was flagged, so the blade must be active. The issue is the configured action, not blade enablement.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.