156-315.81.20 Threat Prevention and SandBlast Practice Question
An administrator configures a Threat Emulation profile to use 'Hold until scanned' mode for email traffic. Users report that inbound emails with PDF attachments are delayed by several minutes. What is the operational impact and architectural reason for this delay?
⚠ Common exam trap
Candidates often mistake this latency for a network or routing issue, forgetting that 'Hold until scanned' is an intentional security trade-off that forces synchronous analysis before file delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email gateway intercepts the attachment and delays delivery until the sandbox environment completes behavioral execution analysis.
The 'Hold until scanned' setting ensures that files are completely analyzed by the Threat Emulation sandbox before being released to the recipient. This security mechanism eliminates the window of exposure to zero-day threats but introduces processing latency, which is critical for administrators to balance against business operational requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The gateway is caching the emails locally while waiting for ThreatCloud to update its daily anti-spam signature database.
Why it's wrong here
ThreatCloud anti-spam signature updates are unrelated to Threat Emulation; the delay arises because the gateway holds the message until the sandbox returns a verdict. Caching while awaiting signature refresh would be the cause if the profile used anti-spam or reputation lookups, not emulation scanning.
- ✓
The email gateway intercepts the attachment and delays delivery until the sandbox environment completes behavioral execution analysis.
Why this is correct
Hold until scanned mode explicitly pauses file delivery at the gateway until the emulation engine finishes detonating the file in a sandbox and confirms it is benign. This prevents zero-day malware from reaching endpoints but causes a temporary delivery delay.
- ✗
Threat Extraction is failing to convert the PDF attachments, causing the mail server to retry transmission continuously.
Why it's wrong here
Threat Extraction strips active content and runs separately from emulation; a conversion failure would surface as an extraction error, not a consistent multi-minute hold. It is tempting because both features process attachments, but extraction would be the cause if the profile were configured for sanitisation rather than 'Hold until scanned'.
- ✗
The SMTP daemon on the Security Gateway is experiencing buffer overflows due to excessive concurrent attachment transfers.
Why it's wrong here
Buffer overflows are not the mechanism; 'Hold until scanned' deliberately queues the message while the gateway submits the attachment to the emulation service and awaits a verdict. It is tempting because large attachments consume gateway resources, which would be the cause if the delay correlated with concurrent volume rather than scan latency.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.