156-315.81.20 Threat Prevention and SandBlast Practice Question
An administrator notices that the Threat Emulation blade is not inspecting files downloaded over HTTP from a specific internal web server. The administrator confirms that the Threat Prevention policy includes the internal network as a protected scope. What is the most likely reason?
⚠ Common exam trap
The trap here is assuming that including the internal network in the protected scope is sufficient, when traffic must also traverse the gateway and match an enforcing rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The connection is being matched by a rule that does not have Threat Prevention blades enabled, or the traffic is bypassing the gateway entirely.
Threat Emulation inspects files only when traffic passes through the gateway and matches a rule with Threat Prevention enabled. If the internal server's traffic bypasses the gateway or hits a rule without blades, no inspection occurs. The administrator should check the rulebase and routing to ensure the traffic is subject to inspection. Other options are less likely given the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The connection is being matched by a rule that does not have Threat Prevention blades enabled, or the traffic is bypassing the gateway entirely.
Why this is correct
If the traffic from the internal server does not traverse the gateway, or if it matches a rule that does not enforce Threat Prevention, files will not be inspected. This is a common cause: internal traffic may be routed directly, or a rule may have blades disabled. The administrator should verify the rulebase and routing.
- ✗
The internal web server's IP address is included in the 'Trusted Sources' exception list in the Threat Prevention profile.
Why it's wrong here
Trusted Sources are typically used to exclude internal traffic from inspection, but if the internal network is in the protected scope, trusted sources would not automatically bypass emulation unless explicitly configured. The scenario states the protected scope includes the internal network, so a trusted source exception is less likely than a protocol or direction issue.
- ✗
The HTTP traffic from the internal server is being decrypted and inspected, but the file type is not supported by Threat Emulation.
Why it's wrong here
If the file type were unsupported, the logs would show a bypass reason for unsupported file type. The scenario does not mention file type; it simply says files are not inspected. This is a possible cause but less likely than a configuration oversight, and it does not explain why only this specific server is affected.
- ✗
Threat Emulation is only applied to files downloaded from external sources by default, and internal traffic is excluded unless explicitly enabled.
Why it's wrong here
Threat Emulation applies to all traffic within the protected scope, regardless of source. There is no default exclusion for internal sources. If the internal network is in the protected scope, emulation should occur. Thus, this is not the reason for the lack of inspection.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.