156-215.80 · Question #312
Vanessa is expecting a very important Security Report. The Document should be sent as an attachment via e-mail. An e-mail with Security_report.pdf file was delivered to her e-mail inbox. When she…
The correct answer is D. SandBlast Threat Extraction. SandBlast Threat Extraction reconstructs documents by removing potentially dangerous active content, delivering a sanitized file that is missing embedded objects such as graphs, tables, and hyperlinks.
Question
Vanessa is expecting a very important Security Report. The Document should be sent as an attachment via e-mail. An e-mail with Security_report.pdf file was delivered to her e-mail inbox. When she opened the PDF file, she noticed that the file is basically empty and only few lines of text are in it. The report is missing some graphs, tables and links. Which component of SandBlast protection is her company using on a Gateway?
Options
- ASandBlast Threat Emulation
- BSandBlast Agent
- CCheck Point Protect
- DSandBlast Threat Extraction
How the community answered
(52 responses)- A4% (2)
- B12% (6)
- C6% (3)
- D79% (41)
Why each option
SandBlast Threat Extraction reconstructs documents by removing potentially dangerous active content, delivering a sanitized file that is missing embedded objects such as graphs, tables, and hyperlinks.
SandBlast Threat Emulation sandboxes suspicious files in a virtual environment during analysis and would typically hold or block delivery - not deliver a content-stripped version of the file to the recipient.
SandBlast Agent is an endpoint-based client installed on user workstations for local threat prevention, not a gateway component that intercepts and reconstructs email attachments in transit.
'Check Point Protect' is not a recognized Check Point SandBlast gateway component related to email attachment inspection or content reconstruction.
SandBlast Threat Extraction (Content Disarm and Reconstruction - CDR) proactively removes exploitable active content - including embedded macros, JavaScript, graphs, linked objects, and hyperlinks - from documents before delivery, producing a safe, clean version. This matches the scenario exactly: Vanessa received the PDF but it was stripped of graphs, tables, and links because the gateway's Threat Extraction blade reconstructed it by removing potentially malicious active content while preserving the static text.
Concept tested: SandBlast Threat Extraction - Content Disarm and Reconstruction on gateway
Source: https://www.checkpoint.com/products/threat-extraction/
Topics
Community Discussion
No community discussion yet for this question.