156-315.81.20 · domain
Threat Prevention and SandBlast
This domain covers Check Point Threat Prevention and SandBlast: profiles, Threat Emulation and Threat Extraction, indicators, exceptions, and logging. Questions are scenario-based, requiring you to read CLI output, SmartLog entries, and profile settings to diagnose blocked files, missing notifications, and emulation mode behavior on Security Gateways.
Focused practice
Practice Threat Prevention and SandBlast questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Threat Prevention and SandBlast
Be able to select and justify Threat Prevention profiles, interpret Threat Emulation verdicts in CLI and SmartLog, and explain Hold versus Background delivery. The critical skill is tracing a blocked file from emulation verdict through logging to the user notification path.
Threat Prevention 'Recommended' profile versus custom profile benefits and trade-offs
Threat Emulation modes: 'Hold' versus 'Background' and their effect on file delivery
Troubleshooting blocked downloads using CLI output and SmartLog Threat Emulation verdicts
Configuring UserCheck notifications so blocked-file pages reach the end user
Watch out for
Common Threat Prevention and SandBlast exam traps
- ▸Assuming 'Recommended' profile is fully customizable; it is maintained by Check Point and overrides manual tuning.
- ▸Confusing Hold mode (file delayed until verdict) with Background mode (file delivered immediately, later remediated).
- ▸Forgetting that UserCheck notification requires the correct gateway/portal configuration and client reachability, not just a block action.
Question index
All Threat Prevention and SandBlast questions (41)
Click any question to see the full explanation, or start a practice session above.
An administrator is configuring Threat Extraction on a R81.20 Security Gateway. They want to ensure that files are sanitized and delivered quickly while maintaining security. Which TWO actions should they take? (Choose two.)
Hard2How can an administrator monitor the effectiveness of the Threat Prevention blades over time?
Medium3Refer to the exhibit. Why was 'invoice.pdf' blocked?
Hard4Which component of the Check Point Threat Prevention architecture is responsible for providing real-time, global threat intelligence updates to the security gateway?
Easy5A security administrator is configuring Threat Prevention profiles on a Check Point R81.20 Security Gateway. The administrator wants to ensure that the organization benefits from Check Point's recommended settings for Threat Emulation and Threat Extraction. Which two of the following are characteristics of the 'Recommended' Threat Prevention profile? (Choose two.)
Medium6Which component acts as the centralized repository for global threat intelligence in a Check Point deployment?
Easy7A security administrator is configuring Threat Prevention on a R81.20 Security Gateway. They enable Threat Emulation for incoming files and want to reduce the gateway's CPU load by having emulation performed by a dedicated appliance rather than the gateway itself. Which Check Point component should they deploy and configure to achieve this?
Medium8Which of the following describes the 'Threat Emulation' process correctly?
Easy9A Check Point administrator is troubleshooting a Threat Emulation issue where a specific PDF file was not emulated, despite the Threat Prevention policy being configured to inspect PDFs. The log shows the file was allowed with the action 'Bypass' under Threat Emulation. The administrator verifies that the file is not password-protected and is under the maximum file size limit. What is the most likely reason for the bypass?
Hard10An administrator configures a Threat Emulation profile to use 'Hold until scanned' mode for email traffic. Users report that inbound emails with PDF attachments are delayed by several minutes. What is the operational impact and architectural reason for this delay?
Medium11What is the primary advantage of deploying Threat Emulation on a Security Gateway rather than just using endpoint-based protection?
Medium12A Check Point R81 gateway is using Threat Emulation. An administrator observes that a PDF file was emulated, and the log shows the verdict as 'Malicious'. However, the user was able to open the file without any warning. What is the most likely cause of this behavior?
Hard13Which TWO of the following are primary components of the Check Point SandBlast Threat Extraction solution?
Medium14In which scenario should a security administrator choose to use 'Threat Extraction' over 'Threat Emulation'?
Medium15A security administrator notices that a user downloaded a file that was flagged as malicious by Threat Emulation, but the file was not blocked. The Threat Prevention policy shows that the Threat Emulation blade is set to 'Detect' mode for that user group. What is the most likely reason the file was not blocked?
Medium16An administrator is troubleshooting why Threat Emulation is not inspecting files downloaded over HTTPS. The gateway is configured with HTTPS Inspection, but files are still bypassing emulation. What is the most likely cause?
Hard17A security analyst is reviewing logs and sees multiple entries indicating that files were sent to Threat Emulation but the verdict was 'Malicious'. However, the files were not blocked. What is the most likely cause?
Easy18A Check Point administrator is analyzing logs and notices that a file was marked as 'Emulation Failed' in the Threat Emulation logs. The file was downloaded from a reputable website and is a common document format. The administrator wants to understand why this status occurred. Which of the following is the most likely cause for an 'Emulation Failed' status?
Hard19An organization requires that all incoming files be sanitized immediately to ensure business continuity. Which configuration setting is most appropriate?
Hard20An administrator is configuring Threat Emulation on a Check Point R81.20 Security Gateway. The administrator wants to ensure that files downloaded from the internet are inspected in a sandbox environment. Which of the following best describes the function of the Threat Emulation blade?
Easy21A Check Point R81 gateway is configured with Threat Emulation. An administrator notices that a suspicious executable file downloaded via HTTP was not emulated. The log shows the action as 'Bypassed'. Which of the following is the most likely reason for this bypass?
Hard22Which file type is most commonly targeted by Threat Extraction for active content removal?
Medium23Refer to the exhibit. An administrator is troubleshooting a file download issue. The CLI output confirms the file is blocked by Threat Emulation. What is the next logical step to investigate why this specific file was classified as malicious?
Hard24A security engineer configures a Threat Prevention profile with Threat Emulation enabled for PDF files. Users report that some PDF files are not being emulated, and the logs show the action 'Bypass' with the reason 'File size exceeds limit'. The engineer wants to ensure all PDFs are inspected without overloading the gateway. What is the most appropriate action?
Hard25A security administrator has enabled the Threat Extraction blade on a gateway and set it to extract and sanitize all PDF files delivered to users. A user reports that a PDF file now contains only text and images, but all interactive form fields are gone. The administrator checks the Threat Extraction log and sees the action 'Extract'. Which statement explains this behavior?
Hard26A security administrator notices that Threat Emulation is bypassing all files from a specific internal server. They want to ensure that files from this server are emulated. What is the most likely reason for the bypass, and how can it be resolved?
Medium27Why might a file be marked as 'Emulation Failed' in the logs?
Medium28An administrator notices that the Threat Emulation blade is not inspecting files downloaded over HTTP from a specific internal web server. The administrator confirms that the Threat Prevention policy includes the internal network as a protected scope. What is the most likely reason?
Easy29Which TWO of the following are benefits of using the Threat Prevention 'Recommended' profile over a custom profile?
Medium30When configuring Threat Prevention, what is the significance of the 'Hold' vs. 'Background' emulation mode?
Medium31An administrator is reviewing Threat Prevention logs and notices that a file was marked as 'Benign' by Threat Emulation. The file was downloaded from a known malicious site but did not exhibit malicious behavior during emulation. What is the most likely reason for this verdict?
Easy32A Check Point administrator wants to ensure that files downloaded from the internet are inspected by Threat Emulation before reaching the user. Which blade must be enabled in the Threat Prevention policy to achieve this?
Easy33What is the primary function of the 'ThreatCloud' service in the context of SandBlast Threat Prevention?
Medium34Which TWO of the following are primary functions of the Threat Extraction blade in Check Point SandBlast? (Choose two)
Medium35An administrator notices that the Threat Extraction blade is converting incoming Microsoft Word documents into static PDF files, but users complain that embedded dynamic macros are completely missing from the converted documents. What is the cause of this behavior?
Medium36A security administrator needs to ensure that all encrypted traffic is inspected by the Threat Prevention blades. What is the mandatory requirement for this?
Medium37A security administrator is configuring a Check Point R81 gateway running Threat Emulation and Threat Extraction blades. They want to ensure that files downloaded by users are inspected and, when necessary, sanitized before delivery. Which two of the following statements correctly describe the behavior of Threat Extraction? (Choose two.)
Medium38Which THREE of the following are valid methods for deploying the SandBlast Threat Emulation service?
Hard39An administrator notices that files are being successfully blocked by Threat Emulation, but the user is not seeing the block notification page. Which configuration must be verified to ensure the user receives the notification?
Medium40What happens if a user tries to download a file, and the Threat Emulation service is temporarily unreachable?
Hard41A security engineer configures Threat Emulation to inspect incoming archive files containing nested compressed directories. During testing, an archive containing six nested levels of ZIP files bypasses deep emulation inspection. What is the most likely configuration cause?
HardOther domains
All 156-315.81.20 exam domains
Frequently asked questions
- What does the Threat Prevention and SandBlast domain cover on the 156-315.81.20 exam?
- Be able to select and justify Threat Prevention profiles, interpret Threat Emulation verdicts in CLI and SmartLog, and explain Hold versus Background delivery. The critical skill is tracing a blocked file from emulation verdict through logging to the user notification path.
- How many questions are in this domain?
- This page lists all 41 Threat Prevention and SandBlast questions in the 156-315.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Threat Prevention and SandBlast questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.