Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

A security analyst is reviewing logs and sees multiple entries indicating that files were sent to Threat Emulation but the verdict was 'Malicious'. However, the files were not blocked. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that Threat Emulation always blocks malicious files, when in reality the enforcement action depends on the Threat Prevention policy mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Threat Prevention policy is configured in 'Detect' mode instead of 'Prevent' mode.

When Threat Prevention is set to 'Detect' mode, malicious files are logged but not blocked. This mode is often used during initial deployment or testing. To enforce blocking, the policy must be changed to 'Prevent' mode. The logs clearly show detection without prevention, pointing to the policy mode as the cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Threat Prevention policy is configured in 'Detect' mode instead of 'Prevent' mode.

    Why this is correct

    In 'Detect' mode, Threat Prevention logs malicious verdicts but does not block the files. This allows administrators to monitor without disrupting traffic. To block, the policy must be set to 'Prevent' mode. The logs showing 'Malicious' but no block action strongly indicate a detect-only configuration.

  • ✗

    Threat Emulation only detects but never blocks; blocking is handled by another blade.

    Why it's wrong here

    Threat Emulation can both detect and block malicious files when the policy is in 'Prevent' mode. It is not limited to detection. The blocking action is part of the Threat Prevention policy enforcement. This option incorrectly states that Threat Emulation cannot block, which is false.

  • ✗

    The files were allowed because the user has administrator privileges and bypassed the policy.

    Why it's wrong here

    Check Point does not automatically bypass policies for administrators. Bypass rules can be configured based on user or group, but this is not a default behavior. The scenario does not mention any such exception, so this is unlikely. The more common cause is the policy mode.

  • ✗

    The gateway is not licensed for Threat Emulation, so it only logs and does not block.

    Why it's wrong here

    If the gateway were not licensed for Threat Emulation, the blade would not function at all, and no emulation logs would be generated. The presence of 'Malicious' verdicts indicates the blade is active and licensed. Licensing issues would typically result in no inspection rather than detection without blocking.

About these practice questions

This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.