156-315.81.20 Threat Prevention and SandBlast Practice Question
An administrator is configuring Threat Extraction on a R81.20 Security Gateway. They want to ensure that files are sanitized and delivered quickly while maintaining security. Which TWO actions should they take? (Choose two.)
⚠ Common exam trap
The trap here is thinking that Threat Extraction alone is sufficient, or that delivering the original file first is acceptable, when the best practice is to combine immediate sanitization with background emulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Threat Emulation to run in the background while the sanitized file is delivered.
Threat Extraction delivers a sanitized file immediately while Threat Emulation runs in the background on the original. This combination ensures fast delivery with security. Disabling emulation or delivering the original file first compromises security, and size-based sanitization is not a recommended practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable Threat Emulation to reduce latency.
Why it's wrong here
Disabling Threat Emulation would reduce security by not checking the original file for malicious behavior. Threat Extraction alone may not catch all threats, especially zero-days. The goal is to maintain security while delivering quickly, so emulation should be used in conjunction.
- ✗
Configure Threat Extraction to only sanitize files larger than 10 MB.
Why it's wrong here
Size-based sanitization is not a standard configuration and would leave smaller files unsanitized, potentially exposing users to threats. Threat Extraction should be applied to all relevant file types regardless of size, unless specific exceptions are defined.
- ✓
Configure Threat Emulation to run in the background while the sanitized file is delivered.
Why this is correct
Threat Emulation can run in the background on the original file while the sanitized version is delivered to the user. If the original is found malicious, the user can be alerted or the file can be blocked. This combination provides fast delivery and security.
- ✗
Set Threat Extraction to deliver the original file and then sanitize it if malicious.
Why it's wrong here
Delivering the original file before sanitization defeats the purpose of Threat Extraction, as the user could be exposed to malicious content. Threat Extraction should deliver a sanitized version immediately, while the original is checked in the background.
- ✓
Enable Threat Extraction to remove active content from files and deliver a sanitized version immediately.
Why this is correct
Threat Extraction removes active content such as macros and scripts from files, delivering a sanitized version to the user immediately. This provides both speed and security, as the original file is not delivered until it is verified. This is a core feature of Threat Extraction.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.