when you copy a file from USB to the local PC it is automatically sent in parallel to Threat Emulation cloud (TE).
if TE returns a malicious verdict (between a couple of sec and a couple of min, depends on the scenario), SBA will immediately delete the file.
SBA does not block the copy itself until the verdict returns. this is in order to provide a smooth user experience as the TE result can take up to a couple of min. the file is accessible immediately and is getting deleted only when a malicious verdict received from TE.