156-215.80 · Question #460
The _____ software blade package uses CPU-level and OS-level sandboxing in order to delect and block malware.
The correct answer is B. Next Generation Threat Emulation. Check Point's Threat Emulation blade uses CPU-level and OS-level sandboxing to detonate suspicious files and detect malware before it reaches endpoints. This is distinct from extraction, which sanitizes files instead.
Question
The _____ software blade package uses CPU-level and OS-level sandboxing in order to delect and block malware.
Options
- ANext Generation Threat Prevention
- BNext Generation Threat Emulation
- CNext Generation Threat Extraction
- DNext Generation Firewall
How the community answered
(37 responses)- A3% (1)
- B89% (33)
- C3% (1)
- D5% (2)
Why each option
Check Point's Threat Emulation blade uses CPU-level and OS-level sandboxing to detonate suspicious files and detect malware before it reaches endpoints. This is distinct from extraction, which sanitizes files instead.
Next Generation Threat Prevention is a bundled software blade package that includes multiple blades, not a single blade that performs sandboxing itself.
Next Generation Threat Emulation specifically employs CPU-level and OS-level sandbox environments to execute and observe potentially malicious files, detecting zero-day exploits and unknown malware by analyzing behavior rather than signatures. The CPU-level sandbox catches exploits that attempt to evade OS-level detection, making this a two-layer approach unique to Threat Emulation.
Next Generation Threat Extraction sanitizes and reconstructs documents to remove potentially malicious content, but does not use sandboxing to detonate or analyze malware behavior.
Next Generation Firewall focuses on application control, identity awareness, and IPS - it does not perform CPU-level or OS-level sandboxing.
Concept tested: Check Point Threat Emulation sandboxing capability
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatEmulation_AdminGuide/Content/Topics-TEG/Overview.htm
Topics
Community Discussion
No community discussion yet for this question.