nerdexam
Check_Point

156-215.80 · Question #301

Which one of the following is true about Threat Extraction?

The correct answer is B. Works on all MS Office, Executables, and PDF files. Check Point Threat Extraction (CDR) reconstructs files by removing active content and supports MS Office, executable, and PDF file types for sanitized delivery.

Security Policy Management

Question

Which one of the following is true about Threat Extraction?

Options

  • AAlways delivers a file to user
  • BWorks on all MS Office, Executables, and PDF files
  • CCan take up to 3 minutes to complete
  • DDelivers file only if no threats found

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    85% (23)
  • C
    7% (2)
  • D
    4% (1)

Why each option

Check Point Threat Extraction (CDR) reconstructs files by removing active content and supports MS Office, executable, and PDF file types for sanitized delivery.

AAlways delivers a file to user

Threat Extraction may not deliver a file if it cannot process it (for example, password-protected or corrupted files), so it does not unconditionally always deliver a file to the user.

BWorks on all MS Office, Executables, and PDF filesCorrect

Check Point Threat Extraction supports MS Office documents, executable files, and PDF files by stripping potentially malicious active content such as macros, scripts, and embedded objects, then reconstructing a safe copy for delivery to the user without delay.

CCan take up to 3 minutes to complete

Processing times of up to 3 minutes apply to Threat Emulation (sandbox analysis), not Threat Extraction, which reconstructs and delivers sanitized files near-instantly.

DDelivers file only if no threats found

Threat Extraction always delivers a cleaned, reconstructed file regardless of whether threats were found - it removes the threats and delivers the result, which is the opposite of withholding files when threats are detected.

Concept tested: Check Point Threat Extraction supported file types

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPAdmin/TE-Overview.htm

Topics

#Threat Extraction#SandBlast#file types#threat prevention

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice