156-315.81.20 Threat Prevention and SandBlast Practice Question
A security administrator has enabled the Threat Extraction blade on a gateway and set it to extract and sanitize all PDF files delivered to users. A user reports that a PDF file now contains only text and images, but all interactive form fields are gone. The administrator checks the Threat Extraction log and sees the action 'Extract'. Which statement explains this behavior?
⚠ Common exam trap
The trap here is assuming that Threat Extraction only removes executable content, while it actually strips all active content, including interactive form fields in documents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Extraction removes all active content, including JavaScript, macros, and embedded objects, to deliver a safe, sanitized version of the file.
Threat Extraction sanitizes files by removing active content that could carry exploits, such as JavaScript, macros, and embedded objects. In this scenario, the PDF's interactive form fields are active content and are therefore removed. The resulting file contains only static elements like text and images, which are safe for the user. This behavior is by design and confirms that the blade is functioning correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat Extraction replaces the original file with a clean, reconstructed version that includes only static content, but the original file is still available for download from the log.
Why it's wrong here
Threat Extraction does not keep the original file available for download through the log. The original file may be stored temporarily for analysis, but it is not offered to the user. The user receives only the sanitized version. The log records the action but does not provide a download link for the original malicious file, as that would defeat the purpose of extraction.
- ✓
Threat Extraction removes all active content, including JavaScript, macros, and embedded objects, to deliver a safe, sanitized version of the file.
Why this is correct
Threat Extraction is designed to remove potentially malicious active content from files. In this scenario, the PDF's interactive form fields are considered active content and are stripped during the extraction process. The sanitized file retains only the static text and images, which are safe to deliver. This matches the administrator's observation that form fields are missing while text and images remain.
- ✗
Threat Extraction failed to process the file properly, and the missing form fields indicate a corruption that should be reported to Check Point support.
Why it's wrong here
The removal of form fields is not a failure or corruption; it is the intended behavior of Threat Extraction. The blade is designed to strip active content, which includes interactive form fields, to prevent potential exploits. Reporting this as a corruption would be incorrect because the log clearly shows the 'Extract' action, indicating successful sanitization.
- ✗
Threat Extraction only removes executable files, so the loss of form fields indicates a separate issue with the PDF viewer.
Why it's wrong here
Threat Extraction does not limit itself to executable files; it processes a wide range of document types, including PDFs, and removes active content such as JavaScript, macros, and embedded objects. Form fields are considered active content, so their removal is expected. The PDF viewer is not the cause, as the log shows the 'Extract' action was taken by the gateway.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.