156-315.81.20 Threat Prevention and SandBlast Practice Question
A security engineer configures Threat Emulation to inspect incoming archive files containing nested compressed directories. During testing, an archive containing six nested levels of ZIP files bypasses deep emulation inspection. What is the most likely configuration cause?
⚠ Common exam trap
Candidates often assume the file was blocked due to a policy restriction. They fail to consider that technical resource limits, like extraction depth, cause the engine to skip inspection entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The maximum archive extraction depth limit in the Threat Emulation advanced settings was reached and traversal stopped.
SandBlast Threat Emulation enforces strict limits on archive extraction depth to protect gateway CPU and memory resources from denial-of-service attacks utilizing zip bombs. Exceeding the maximum archive depth threshold stops recursive extraction, meaning deeply nested files are passed without full emulation analysis. Administrators must balance security depth against gateway performance limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file type filter profile was configured to exclude compressed archives exceeding four megabytes from sandbox evaluation.
Why it's wrong here
File size limits dictate the maximum individual file size sent for emulation rather than the recursive depth of compressed archive structures. An archive exceeding the size limit would be dropped or bypassed entirely rather than having its inner contents selectively ignored.
- ✓
The maximum archive extraction depth limit in the Threat Emulation advanced settings was reached and traversal stopped.
Why this is correct
Check Point gateways enforce a configurable maximum archive depth to prevent CPU exhaustion caused by maliciously crafted recursive zip files. When the threshold of nested levels is surpassed, extraction ceases and the remaining layers bypass deep emulation inspection.
- ✗
Threat Extraction was disabled in the active policy layer, causing compressed payloads to bypass all inspection engines automatically.
Why it's wrong here
Disabling Threat Extraction stops file sanitization and conversion, but it does not dictate how the separate Threat Emulation engine processes archive depth. Threat Emulation operates using its own dedicated profile settings for archive extraction limits.
- ✗
The local Threat Emulation private cloud appliance encountered a CPU throttling event during the nested extraction phase.
Why it's wrong here
CPU throttling on a private emulation appliance results in queuing delays or fallback actions specified in the profile rather than silently bypassing nested archive structures. The failure to inspect deep layers stems from policy depth restrictions.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.