nerdexam
Check_Point

156-215.80 · Question #355

Which of the following describes how Threat Extraction functions?

The correct answer is B. Proactively detects threats. Threat Extraction proactively sanitizes files by stripping active content before delivery, preventing zero-day attacks without waiting for threat detection or emulation results.

Introduction to Check Point Technology

Question

Which of the following describes how Threat Extraction functions?

Options

  • ADetect threats and provides a detailed report of discovered threats
  • BProactively detects threats
  • CDelivers file with original content
  • DDelivers PDF versions of original files with active content removed

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    88% (49)
  • C
    2% (1)
  • D
    7% (4)

Why each option

Threat Extraction proactively sanitizes files by stripping active content before delivery, preventing zero-day attacks without waiting for threat detection or emulation results.

ADetect threats and provides a detailed report of discovered threats

Providing a detailed report of discovered threats describes Threat Emulation, which sandboxes files and generates behavioral analysis reports - not Threat Extraction.

BProactively detects threatsCorrect

Threat Extraction works proactively by intercepting inbound files, removing potentially exploitable active content such as macros, scripts, and embedded objects, and delivering a clean reconstructed version to the user before any malicious payload can execute. This proactive stance differs from reactive detection tools because threats are neutralized regardless of whether a specific signature or behavior is identified.

CDelivers file with original content

Threat Extraction never delivers files with their original unmodified content; active content is always removed from the reconstructed file by design.

DDelivers PDF versions of original files with active content removed

While Threat Extraction can convert files to PDF format, it also reconstructs original file types with active content removed, making 'PDF versions only' an incomplete and overly narrow description of the feature.

Concept tested: Check Point Threat Extraction proactive file sanitization

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TPG/Threat-Extraction.htm

Topics

#Threat Extraction#SandBlast#active content removal#PDF conversion

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice