156-315.81.20 Threat Prevention and SandBlast Practice Question
Which file type is most commonly targeted by Threat Extraction for active content removal?
⚠ Common exam trap
Candidates often select raw text files or plain images, forgetting that Threat Extraction specifically targets formats capable of containing active content, scripting, or macros like Microsoft Word.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Word documents
Threat Extraction is highly effective for documents that support scripting or active objects, such as Microsoft Office files (Word, Excel, PowerPoint) and PDFs. These formats frequently contain macros or OLE objects that attackers use to deliver malware. By stripping these elements, the gateway ensures the file remains functional for the user while removing the potential for malicious code execution, which is the primary goal of the extraction technology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
JPEG images
Why it's wrong here
JPEG images are static formats and generally do not contain active executable content like macros. While they can contain metadata, they are not the primary target for Threat Extraction's active content removal logic, which focuses on document formats that allow for embedded scripts and OLE objects to function.
- ✓
Microsoft Word documents
Why this is correct
Microsoft Word files are a primary vector for malware via embedded macros. Threat Extraction specifically targets these files to strip out the active content, leaving the document in a safe state for the user while still allowing them to view the text and basic formatting without the risk.
- ✗
Compressed ZIP files
Why it's wrong here
ZIP files are containers, not the documents themselves. While the gateway inspects the contents of a ZIP file, the extraction process is applied to the individual files inside the archive. The archive format itself is not the document being 'extracted' by the blade, but rather a container for others.
- ✗
MP3 audio files
Why it's wrong here
Audio files are not document formats that support active content execution. Therefore, they do not present the same security risks related to macro-based malware as office documents. Threat Extraction is not designed to sanitize audio files, as they lack the scripting features that the blade is intended to neutralize.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.