156-215.81 · Question #686
Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?
The correct answer is D. Threat Extraction. Threat Extraction is the Security Blade that needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network. It can strip out active content, embedded objects, and other risky elements from documents and…
Question
Which Security Blade needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network?
Options
- AThreat Emulation
- BAnti-Malware
- CAnti-Virus
- DThreat Extraction
How the community answered
(31 responses)- A10% (3)
- B3% (1)
- C16% (5)
- D71% (22)
Explanation
Threat Extraction is the Security Blade that needs to be enabled in order to sanitize and remove potentially malicious content from files, before those files enter the network. It can strip out active content, embedded objects, and other risky elements from documents and deliver a safe version of the file to the user.
Topics
Community Discussion
5Threat Extraction is your answer here, D. That blade is the one that actually strips out potentially malicious content from files in real time before they reach the user, while Threat Emulation (A) runs files in a sandbox to detect threats after the fact, so if you mix those two up on the exam you will lose easy points.
Bao is right to call out that distinction, but to sharpen the mnemonic: Threat Emulation emulates an environment to observe behavior, Threat Emulation does the detecting, and Threat Extraction does the sanitizing, so remember E for Examine and X for eXcise, because on the exam they will absolutely put both in the same question stem to see if you flinch.
Think about which blade reconstructs the file clean rather than just inspecting it.
Threat Extraction is the bouncer who strips the weapon before letting the guest in, not after, and that image locked in D for me the moment I saw this one.
That analogy is solid but remember the bouncer does not change the guest at all, which is the key edge over sanitization where you might still let a slightly altered original through.