156-315.81.20 Threat Prevention and SandBlast Practice Question
What happens if a user tries to download a file, and the Threat Emulation service is temporarily unreachable?
⚠ Common exam trap
Candidates often guess that the system defaults to 'block' for safety. However, the behavior is strictly dependent on the specific 'Failure Mode' configuration set by the administrator in the profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file is allowed based on the configured 'Failure Mode' setting in the Threat Prevention profile.
The 'fail-open' vs 'fail-close' behavior is a critical security design decision. If the service is unreachable and the system is set to fail-open, the file is allowed to protect productivity. If set to fail-close, the file is blocked to maintain security. The default behavior is typically to allow the file to pass to prevent service disruption, but this must be aligned with the organization's risk tolerance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file is always blocked to ensure maximum security.
Why it's wrong here
Blocking by default on service failure ('fail-close') is an option but not the default behavior for all deployments. Check Point provides the flexibility to choose, and many organizations prefer to allow files to maintain business operations, making 'always blocked' an incorrect and overly rigid generalization for all security policies.
- ✓
The file is allowed based on the configured 'Failure Mode' setting in the Threat Prevention profile.
Why this is correct
The behavior upon service failure is a configurable setting within the Threat Prevention profile. Administrators can explicitly choose whether the gateway should 'fail-open' (allow the file) or 'fail-close' (block the file) when the Threat Emulation cloud service is unavailable, allowing for a balance between uptime and security posture.
- ✗
The file is cached locally and then re-emulated once the service is back.
Why it's wrong here
The gateway does not cache files to perform retroactive emulation upon service reconnection. If the service is unreachable, the decision must be made at the time of the request. Once the file is delivered, the window for blocking it as a preventative measure is closed, so this is not technically correct.
- ✗
The file is automatically sent to the Threat Extraction engine for sanitization.
Why it's wrong here
Threat Extraction is a separate process from Threat Emulation and does not act as a fallback for Emulation failures. If the Emulation service is unavailable, the system defaults to the configured 'Failure Mode' for emulation, not to a different security blade, as these services have different requirements and analysis capabilities.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.