156-215.80 · Question #316
What is the mechanism behind Threat Extraction?
The correct answer is D. Any active contents of a document, such as JavaScripts, macros and links will be removed from. Check Point Threat Extraction works by removing active content such as macros, JavaScripts, and embedded links from documents before delivering a sanitized version to the user.
Question
What is the mechanism behind Threat Extraction?
Options
- AThis is a new mechanism which extracts malicious files from a document to use it as a counter-
- BThis is a new mechanism which is able to collect malicious files out of any kind of file types to
- CThis is a new mechanism to identify the IP address of the sender of malicious codes and to put it
- DAny active contents of a document, such as JavaScripts, macros and links will be removed from
How the community answered
(41 responses)- A2% (1)
- B2% (1)
- C5% (2)
- D90% (37)
Why each option
Check Point Threat Extraction works by removing active content such as macros, JavaScripts, and embedded links from documents before delivering a sanitized version to the user.
Threat Extraction does not extract malicious files to use as counter-measures; that description does not correspond to any real Check Point feature or security mechanism.
Collecting malicious files from any file type for analysis describes Threat Emulation (sandbox analysis), not Threat Extraction, and Threat Extraction does not support all file types.
Identifying the IP address of a malicious sender and blocking it describes a reputation or geo-blocking feature, not Threat Extraction, which operates on document content rather than network identity.
Threat Extraction sanitizes documents by stripping all potentially dangerous active content - including JavaScript, macros, and hyperlinks - from supported file types (PDF, Office documents, etc.) before delivering the cleaned file to the recipient. This ensures the user receives a safe, functional document immediately without waiting for emulation, eliminating the risk of embedded exploit code executing on the endpoint.
Concept tested: Check Point Threat Extraction active content removal mechanism
Source: https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ThreatPrevention_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.