View Full Checkpoint 156-536 Exam Dumps and Practice Test Dumps.
Question 101. What does Threat Emulation Prevent do?
- Allows every file
- Sends supported files for analysis
- Disables browser protection
- Logs without analysis
Correct Answer: 2. Sends supported files for analysis
Explanation:
In Prevent mode, supported downloaded files are sent for Threat Emulation and, when configured, Threat Extraction. Threat Emulation evaluates suspicious files in a sandbox to determine whether they exhibit malicious behavior, including previously unknown or zero-day activity. Additional settings determine whether the user receives a cleaned copy immediately, waits for emulation to finish, or receives the original file while analysis continues. Prevent mode therefore provides active protection rather than simply recording potentially malicious activity. Administrators can also override the default action for individual supported file types.
Question 102. What suffix is added to an extracted copy?
- .safe
- .scan
- .extract
- .cleaned
Correct Answer: 4. .cleaned
Explanation:
When Harmony Endpoint delivers an extracted copy before Threat Emulation completes, the system appends .cleaned to the file name. For example, a document might be delivered as report.docx.cleaned. The cleaned copy is designed to let the user access safe content quickly while the original file continues through inspection. Administrators can choose to remove potentially malicious elements while keeping the original file type or convert supported content to PDF. This approach improves user productivity without requiring users to wait for the complete emulation process.
Question 103. What can Threat Extraction remove?
- Potentially malicious active elements
- Endpoint licenses
- User accounts
- Network routes
Correct Answer: 1. Potentially malicious active elements
Explanation:
Threat Extraction can remove potentially dangerous active content from supported files before those files are delivered to users. Examples in Check Point documentation include macros, JavaScript, and similar embedded elements that could be used to execute malicious actions. The cleaned file remains available in its original supported file type when this extraction method is selected. This allows users to access document content while reducing the risk posed by executable or active components. Threat Extraction complements Threat Emulation, which separately analyzes suspicious files for malicious behavior in a sandbox.
Question 104. What can Threat Extraction convert a file to?
- XML
- CSV
- MSI
Correct Answer: 3. PDF
Explanation:
One Threat Extraction option converts supported documents to PDF while preserving the text and formatting as much as possible. This removes many active elements that could otherwise execute malicious content. Check Point also provides an alternative extraction mode that preserves the original file format but removes potentially malicious elements such as macros or scripts. For PDFs using right-to-left languages or Asian fonts, Check Point recommends extracting potentially malicious components instead of converting to PDF to improve document-processing accuracy.
Question 105. What happens when downloads are suspended for emulation?
- Users receive the original immediately
- Files are never analyzed
- Only the log is updated
- Users wait for the verdict
Correct Answer: 4. Users wait for the verdict
Explanation:
The Suspend download until emulation completes option prevents the user from accessing the original file while Threat Emulation performs its analysis. If the file is determined to be benign, the original file is delivered using its original file name. If the file is malicious, the user receives a block page instead of the file. This approach provides stronger protection because the endpoint never receives an unverified original file, although it can introduce a delay while sandbox analysis finishes.
Question 106. What happens if a suspended file is malicious?
- It is renamed
- Access is blocked
- It is always delivered
- It becomes a lookup
Correct Answer: 2. Access is blocked
Explanation:
When download suspension is enabled and Threat Emulation determines that the file is malicious, the user does not receive the original file. Instead, the system presents a block page. If the same file is found to be benign, the original is delivered after analysis. This behavior provides stronger preventive security because malicious content is withheld before the user can open or execute it. The tradeoff is additional download time while Threat Emulation completes its analysis.
Question 107. What is the risk of emulating without suspending access?
- A malicious original may reach the user
- No event is logged
- The file is never downloaded
- The browser is removed
Correct Answer: 1. A malicious original may reach the user
Explanation:
When Emulate original file without suspending access is selected, the original file is delivered to the user while Threat Emulation analyzes it. The advantage is that the user does not have to wait for a sandbox verdict. The security disadvantage is that the user can receive and potentially open the file even if later analysis determines that it is malicious. This setting therefore prioritizes availability and user experience over the stronger preventive control provided by suspending the download until the verdict is known.
Question 108. What does Allow do for a supported file type?
- Converts it to PDF
- Quarantines it
- Allows it without emulation
- Deletes it
Correct Answer: 3. Allows it without emulation
Explanation:
The Allow action lets a supported file type pass without Threat Emulation. Check Point states that this per-file setting overrides the general Prevent configuration selected on the main protection page. This allows administrators to treat particular file types differently from the global default when business requirements justify the exception. Because allowing a file type removes sandbox analysis for that content, administrators should use the override carefully and understand the security implications before exempting file types from emulation.
Question 109. What does Threat Emulation Detect mode do?
- Analyzes, logs, and allows access
- Blocks every file
- Converts every file to PDF
- Disables logging
Correct Answer: 1. Analyzes, logs, and allows access
Explanation:
In Detect mode, the original file is emulated without suspending user access, and the incident is logged. This means Harmony Endpoint still evaluates the file for malicious behavior, but the user is not prevented from receiving or accessing the original while analysis occurs. Detect mode is therefore useful for monitoring and evaluating the impact of Threat Emulation before enforcing stronger preventive behavior. Administrators should remember that it provides visibility but does not provide the same protection as suspending the download until a safe verdict is available.
Question 110. What does Threat Emulation Off mode do?
- Blocks all downloads
- Extracts macros
- Sends files to sandbox only
- Allows files without emulation or extraction
Correct Answer: 4. Allows files without emulation or extraction
Explanation:
When Threat Emulation protection is set to Off for the relevant files, downloads are allowed without Threat Emulation or Threat Extraction. No sandbox analysis is performed and no cleaned copy is created through the extraction process. This setting provides the least protection of the available modes and should therefore be used only when the organization intentionally does not want those files analyzed. Prevent and Detect both perform emulation, while Off bypasses these protections entirely.
Question 111. Where are unsupported download file types configured?
- Deployment Policy
- Full Disk Encryption
- Unsupported Files settings
- Compliance Policy
Correct Answer: 3. Unsupported Files settings
Explanation:
File types that are not supported by Threat Emulation and Threat Extraction can be controlled through the Unsupported Files settings under advanced download protection. Administrators can choose whether unsupported file types should be allowed or blocked. Check Point notes that the settings configured for unsupported files override relevant selections made on the main protection page. This provides a separate control for content that the emulation or extraction engines cannot analyze, preventing unsupported formats from being treated automatically in the same way as supported files.
Question 112. What controls the largest file sent for emulation?
- URL category
- Emulation Environments setting
- Uninstall password
- Heartbeat interval
Correct Answer: 2. Emulation Environments setting
Explanation:
The Emulation Environments advanced setting controls the maximum file size that Harmony Endpoint sends for Threat Emulation. Administrators configure the value through the option that specifies the size under which files should be uploaded and emulated. Setting an appropriate maximum helps balance security coverage with upload time, sandbox processing, and network usage. Very large files may consume significant bandwidth or analysis resources, while a limit that is too restrictive may prevent some potentially dangerous files from receiving sandbox inspection.
Question 113. What is Zero Phishing designed to detect?
- Disk corruption
- Failed software deployment
- Botnet bandwidth
- Fraudulent websites
Correct Answer: 4. Fraudulent websites
Explanation:
Zero Phishing analyzes website characteristics to determine whether a site is pretending to be another legitimate site or attempting to trick users into entering sensitive information. It is part of Harmony Endpoint Credential Protection. The feature is intended to reduce the risk of credential theft through deceptive websites, including phishing pages designed to imitate trusted services. Depending on policy mode, Zero Phishing can block malicious sites, detect and log them, or be turned off.
Question 114. What does Password Reuse Protection warn against?
- Using corporate passwords on non-corporate sites
- Using long passwords
- Changing passwords frequently
- Using MFA
Correct Answer: 1. Using corporate passwords on non-corporate sites
Explanation:
Password Reuse Protection is designed to detect when users attempt to reuse corporate passwords on non-corporate domains. Reusing a corporate password on an external site increases risk because compromise of that external service may expose credentials that can later be used against organizational systems. Check Point provides modes such as Detect & Alert, Detect, and Off for this protection. The feature complements Zero Phishing by focusing specifically on dangerous password reuse rather than only identifying fraudulent websites.
Question 115. What is the default limitation for local HTML phishing scans?
- Files are always deleted
- Chromium extensions cannot access local files by default
- Local files are always trusted
- Only PDF files are scanned
Correct Answer: 2. Chromium extensions cannot access local files by default
Explanation:
By default, the Harmony browser extension in Chromium-based browsers cannot access local HTML files opened from the endpoint filesystem. Administrators can enable the Scan local HTML files option, after which users are prompted to grant the browser extension permission to access file URLs. Once permission is granted, local HTML pages containing input fields can be scanned for phishing behavior. This protection is especially useful against locally stored phishing content that attempts to collect credentials even though the page was not loaded from a traditional website.
Question 116. Which permission enables local HTML scanning in Chrome?
- Allow pop-ups
- Allow downloads
- Allow access to file URLs
- Allow microphone
Correct Answer: 3. Allow access to file URLs
Explanation:
For Chromium-based browsers such as Chrome, users must enable the browser extension option Allow access to file URLs before Harmony Endpoint can scan local HTML files for phishing activity. The administrator first enables the local HTML scanning capability, then the user grants the required browser permission. If a local HTML file includes an input field, Harmony Browse can inspect the page and block it if it is identified as phishing. This permission is necessary because Chromium normally restricts extension access to local files by default.
Question 117. Which browser receives the Endpoint Security Browser Extension in R81.20?
- Google Chrome
- Firefox only
- Opera only
- Internet Explorer only
Correct Answer: 2. Google Chrome
Explanation:
The R81.20 Endpoint Security administration documentation identifies Google Chrome as the supported browser for the Endpoint Security Browser Extension in the referenced Threat Extraction and Threat Emulation configuration. The extension protects against malicious files downloaded from internet sources and provides browser-related web protection capabilities. Threat Emulation logs generated through the browser extension can also be distinguished from local file-monitor events through their monitor-type information. Browser support can change in newer Harmony Endpoint releases, so exam preparation should follow the version-specific R81.20 material.
Question 118. Which monitor type identifies browser-extension files?
- File Monitor
- Network Monitor
- Process Monitor
- Browser Extension
Correct Answer: 4. Browser Extension
Explanation:
Threat Extraction and Threat Emulation logs related to files handled through the Endpoint Security Browser Extension show Monitor Type – Browser Extension. The browser field identifies Chrome in the R81.20 documentation. This information helps administrators distinguish files intercepted through web-download protection from files analyzed directly on the endpoint filesystem. Being able to identify the protection source is useful during troubleshooting because administrators can determine whether the event originated from browser-based web protection or another endpoint monitoring mechanism.
Question 119. Which monitor type identifies local computer files?
- Browser Extension
- URL Monitor
- File Monitor
- Email Monitor
Correct Answer: 3. File Monitor
Explanation:
Threat Emulation logs associated with files analyzed directly from the endpoint computer use Monitor Type – File Monitor. This distinguishes them from downloaded files inspected through the browser extension, which are labeled as Browser Extension events. Understanding the monitor type can help administrators identify where a suspicious file originated and which Harmony Endpoint protection path handled it. It is especially useful when troubleshooting differences between browser download protection and local file Threat Emulation behavior.
Question 120. What BEST protects users before a download verdict is known?
- Provide an extracted safe copy
- Always send the original immediately
- Disable Threat Emulation
- Allow unsupported files
Correct Answer: 1. Provide an extracted safe copy
Explanation:
Providing an extracted copy allows users to access document content while Threat Emulation continues analyzing the original file. Threat Extraction removes potentially malicious elements or converts supported content to a safer PDF representation, depending on policy. This approach combines productivity with preventive protection because the user does not need immediate access to the unverified original file. If maximum security is required and delay is acceptable, administrators can instead suspend the entire download until emulation completes. Both approaches are safer than immediately allowing an unverified original file.