Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

An organization requires that all incoming files be sanitized immediately to ensure business continuity. Which configuration setting is most appropriate?

⚠ Common exam trap

Candidates often confuse Threat Extraction with Threat Emulation, failing to realize that emulation introduces latency because it waits for sandbox analysis, whereas extraction provides immediate file sanitization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Threat Extraction' in the Threat Prevention policy.

Threat Extraction is the only technology that offers near-instant sanitization. By removing active content from documents, it provides a safe version of the file immediately to the user. This satisfies the business requirement for continuity while maintaining a strong security posture by preventing malicious active content from being executed on the user's host, even before the longer emulation process completes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Hold' mode for Threat Emulation on all files.

    Why it's wrong here

    Hold mode causes delays for every file download, which directly conflicts with the requirement for immediate file access. While it is secure, the latency introduced by waiting for the sandbox to finish makes it unsuitable for environments where business continuity requires files to be available without significant, user-facing delays.

  • ✓

    Enable 'Threat Extraction' in the Threat Prevention policy.

    Why this is correct

    Threat Extraction provides the fastest possible response by sanitizing files on-the-fly. By flattening documents and removing active content, it allows users to continue working immediately. This fulfills the need for speed and continuity, serving as a primary defense for document-based attacks while the emulation engine continues its deeper, longer analysis.

  • ✗

    Disable Threat Emulation and rely solely on IPS.

    Why it's wrong here

    Disabling Threat Emulation leaves the network vulnerable to zero-day file-based threats that IPS signatures cannot catch. This would satisfy the requirement for speed, but at the expense of security. A proper solution must address both the need for business continuity and the need for robust protection against malicious active content.

  • ✗

    Increase the timeout for Threat Emulation to 600 seconds.

    Why it's wrong here

    Increasing the timeout does not improve speed or user experience; it only allows the emulation process more time to complete before giving up. This would actually increase the wait time for users in 'Hold' mode, further hurting business continuity without providing any immediate, sanitized content to the user.

About these practice questions

This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.