Courseiva

156-315.81.20 Threat Prevention and SandBlast Practice Question

Which file type is most commonly targeted by Threat Extraction for active content removal?

⚠ Common exam trap

Candidates often select raw text files or plain images, forgetting that Threat Extraction specifically targets formats capable of containing active content, scripting, or macros like Microsoft Word.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Word documents

Threat Extraction is highly effective for documents that support scripting or active objects, such as Microsoft Office files (Word, Excel, PowerPoint) and PDFs. These formats frequently contain macros or OLE objects that attackers use to deliver malware. By stripping these elements, the gateway ensures the file remains functional for the user while removing the potential for malicious code execution, which is the primary goal of the extraction technology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    JPEG images

    Why it's wrong here

    JPEG images are static formats and generally do not contain active executable content like macros. While they can contain metadata, they are not the primary target for Threat Extraction's active content removal logic, which focuses on document formats that allow for embedded scripts and OLE objects to function.

  • ✓

    Microsoft Word documents

    Why this is correct

    Microsoft Word files are a primary vector for malware via embedded macros. Threat Extraction specifically targets these files to strip out the active content, leaving the document in a safe state for the user while still allowing them to view the text and basic formatting without the risk.

  • ✗

    Compressed ZIP files

    Why it's wrong here

    ZIP files are containers, not the documents themselves. While the gateway inspects the contents of a ZIP file, the extraction process is applied to the individual files inside the archive. The archive format itself is not the document being 'extracted' by the blade, but rather a container for others.

  • ✗

    MP3 audio files

    Why it's wrong here

    Audio files are not document formats that support active content execution. Therefore, they do not present the same security risks related to macro-based malware as office documents. Threat Extraction is not designed to sanitize audio files, as they lack the scripting features that the blade is intended to neutralize.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.