Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

A security engineer configures a Threat Prevention profile with Threat Emulation enabled for PDF files. Users report that some PDF files are not being emulated, and the logs show the action 'Bypass' with the reason 'File size exceeds limit'. The engineer wants to ensure all PDFs are inspected without overloading the gateway. What is the most appropriate action?

⚠ Common exam trap

The trap here is believing that ThreatCloud can emulate files or that a bypass toggle exists, when the actual control is the local maximum file size setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the 'Maximum file size for emulation' in the Threat Emulation blade settings to a value that accommodates the largest PDFs, while monitoring gateway performance.

Threat Emulation bypasses files that exceed the configured maximum size to protect gateway resources. To inspect larger PDFs, the administrator must increase this limit in the Threat Emulation settings. However, because emulation is CPU and memory intensive, the limit should be raised cautiously with performance monitoring. Other options describe non-existent features or incorrect offloading to ThreatCloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Threat Emulation for large files' in the gateway's global properties, which automatically compresses files before emulation to stay under the size limit.

    Why it's wrong here

    There is no global property called 'Threat Emulation for large files' that compresses files. Threat Emulation does not compress files to fit size limits; it either emulates or bypasses based on configured limits. Enabling such a fictitious setting would not resolve the bypass, and compression could alter file behavior, defeating the purpose of emulation.

  • ✗

    Disable the 'Bypass files larger than' option in the Threat Prevention profile, which will force all files to be emulated regardless of size.

    Why it's wrong here

    There is no such option as 'Bypass files larger than' to disable. The maximum file size is a hard limit in the Threat Emulation configuration. Disabling a non-existent bypass would not change behavior. The correct approach is to adjust the maximum size setting, not to look for a bypass toggle that does not exist.

  • ✗

    Configure a file size exception in the Threat Prevention policy for PDF files, specifying that they should be sent to ThreatCloud for emulation instead of local emulation.

    Why it's wrong here

    ThreatCloud does not provide an emulation service for files; Threat Emulation is performed locally on the gateway or on a dedicated emulation appliance. There is no policy exception to offload emulation to ThreatCloud. The bypass is due to local size limits, which must be adjusted locally, not via a ThreatCloud offload.

  • ✓

    Increase the 'Maximum file size for emulation' in the Threat Emulation blade settings to a value that accommodates the largest PDFs, while monitoring gateway performance.

    Why this is correct

    Threat Emulation has a configurable maximum file size; files exceeding it are bypassed to avoid resource exhaustion. Raising this limit allows larger PDFs to be emulated, but the engineer should monitor CPU and memory because emulation is resource-intensive. This directly addresses the bypass reason while balancing performance.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.