An administrator is configuring Threat Extraction on a R81.20 Security Gateway. They want to ensure that files are sanitized and delivered quickly while maintaining security. Which TWO actions should they take? (Choose two.)
Threat Emulation can run in the background on the original file while the sanitized version is delivered to the user. If the original is found malicious, the user can be alerted or the file can be blocked. This combination provides fast delivery and security.
Why this answer
Threat Extraction delivers a sanitized file immediately while Threat Emulation runs in the background on the original. This combination ensures fast delivery with security. Disabling emulation or delivering the original file first compromises security, and size-based sanitization is not a recommended practice.
Exam trap
The trap here is thinking that Threat Extraction alone is sufficient, or that delivering the original file first is acceptable, when the best practice is to combine immediate sanitization with background emulation.