CCSM Advanced Content Inspection Practice Question
A Check Point administrator is configuring Threat Extraction on an R81 Security Gateway to sanitize incoming email attachments. The administrator wants to ensure that users can view the original content of a PDF file while also receiving a sanitized version that has active content removed. The administrator enables Threat Extraction and sets it to 'Extract' mode. However, users report that they only receive the sanitized PDF and cannot access the original file. What should the administrator do to allow users to access both the original and the sanitized file?
⚠ Common exam trap
Watch out — candidates often confuse the 'Extract' mode with 'Extract and Deliver' mode, assuming that Extract mode delivers both files when it actually replaces the original.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the Threat Extraction action to 'Extract and Deliver' mode, which provides both the sanitized file and the original file.
Threat Extraction offers three modes: Detect, Extract, and Extract and Deliver. In Extract mode, the original file is replaced with a sanitized version, so users do not receive the original. To deliver both the original and the sanitized file, the administrator must use Extract and Deliver mode. This mode is specifically designed to provide users with both versions, allowing them to access the original content while still benefiting from the sanitized version for safety.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the Threat Extraction action to 'Detect' mode so that the original file is delivered and the sanitized file is not created.
Why it's wrong here
Changing to 'Detect' mode would stop the extraction and sanitization process, delivering only the original file. This does not meet the requirement to provide both original and sanitized versions. Detect mode only logs and allows the file, which defeats the purpose of Threat Extraction and leaves users exposed to active content.
- ✗
Enable 'Threat Extraction' in 'Detect' mode and configure a separate rule to sanitize the file using the Anti-Virus blade.
Why it's wrong here
The Anti-Virus blade does not sanitize files; it only detects and blocks malware. Using Detect mode for Threat Extraction would not create a sanitized file, and the Anti-Virus blade cannot remove active content. This approach would not provide the sanitized version, and users would only receive the original file, which may contain active content.
- ✗
Configure Threat Extraction to 'Extract' mode and enable the 'Deliver original file' option in the Threat Extraction settings.
Why it's wrong here
In Check Point, Threat Extraction does not have a 'Deliver original file' option in Extract mode. The Extract mode replaces the original file with a sanitized version. To deliver both, a different configuration is needed, such as using a policy that allows the original file to be delivered alongside the sanitized one, but that is not a standard option.
- ✓
Set the Threat Extraction action to 'Extract and Deliver' mode, which provides both the sanitized file and the original file.
Why this is correct
The 'Extract and Deliver' mode in Threat Extraction delivers both the sanitized file and the original file to the user. This allows users to view the original content while also having a sanitized version with active content removed. This mode is designed for scenarios where users need access to the original file but the organization still wants to provide a safe version.
About these practice questions
Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.