Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

An administrator is configuring Threat Emulation on a Check Point R81.20 Security Gateway. The administrator wants to ensure that files downloaded from the internet are inspected in a sandbox environment. Which of the following best describes the function of the Threat Emulation blade?

⚠ Common exam trap

Watch out — candidates often confuse Threat Emulation with Threat Extraction, as both deal with files but have different purposes: emulation executes files in a sandbox, while extraction removes active content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It executes files in a virtual sandbox to detect malicious behavior and block threats.

Threat Emulation is a Check Point blade that sends files to a sandbox for dynamic analysis, executing them in a virtual environment to detect malicious behavior. This allows it to catch unknown threats that signature-based methods might miss. The other options describe different blades: Threat Extraction sanitizes content, Anti-Virus uses signatures, and Anti-Bot monitors traffic, none of which provide sandbox execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It inspects network traffic for command and control communication and blocks it.

    Why it's wrong here

    This describes the Anti-Bot blade, which monitors outbound traffic for signs of botnet communication. Threat Emulation focuses on file analysis, not network traffic patterns. The administrator's request is about file inspection in a sandbox, so this option is not relevant.

  • ✗

    It scans files for known virus signatures and blocks them based on a signature database.

    Why it's wrong here

    Signature-based scanning is the function of the Anti-Virus blade, not Threat Emulation. Threat Emulation uses behavioral analysis in a sandbox, which can detect zero-day threats that lack signatures. Since the administrator specifically wants sandbox inspection, this option does not meet the requirement.

  • ✗

    It extracts malicious macros from documents and replaces them with benign content.

    Why it's wrong here

    This describes Threat Extraction, not Threat Emulation. Threat Extraction sanitizes documents by removing active content, while Threat Emulation executes files in a sandbox to observe behavior. The scenario asks about inspecting files in a sandbox, which is emulation, not extraction. Therefore, this option is incorrect.

  • ✓

    It executes files in a virtual sandbox to detect malicious behavior and block threats.

    Why this is correct

    Threat Emulation runs suspicious files in a contained virtual environment, observing their actions to identify malicious behavior such as registry changes, network connections, or file modifications. If malicious activity is detected, the file is blocked and the user is notified. This matches the administrator's goal of sandbox inspection.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.