156-215.80 · Question #301
Which one of the following is true about Threat Extraction?
The correct answer is B. Works on all MS Office, Executables, and PDF files. Check Point Threat Extraction (CDR) reconstructs files by removing active content and supports MS Office, executable, and PDF file types for sanitized delivery.
Question
Which one of the following is true about Threat Extraction?
Options
- AAlways delivers a file to user
- BWorks on all MS Office, Executables, and PDF files
- CCan take up to 3 minutes to complete
- DDelivers file only if no threats found
How the community answered
(27 responses)- A4% (1)
- B85% (23)
- C7% (2)
- D4% (1)
Why each option
Check Point Threat Extraction (CDR) reconstructs files by removing active content and supports MS Office, executable, and PDF file types for sanitized delivery.
Threat Extraction may not deliver a file if it cannot process it (for example, password-protected or corrupted files), so it does not unconditionally always deliver a file to the user.
Check Point Threat Extraction supports MS Office documents, executable files, and PDF files by stripping potentially malicious active content such as macros, scripts, and embedded objects, then reconstructing a safe copy for delivery to the user without delay.
Processing times of up to 3 minutes apply to Threat Emulation (sandbox analysis), not Threat Extraction, which reconstructs and delivers sanitized files near-instantly.
Threat Extraction always delivers a cleaned, reconstructed file regardless of whether threats were found - it removes the threats and delivers the result, which is the opposite of withholding files when threats are detected.
Concept tested: Check Point Threat Extraction supported file types
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPAdmin/TE-Overview.htm
Topics
Community Discussion
No community discussion yet for this question.