An administrator is deploying Threat Extraction on a Check Point R81 Security Gateway to sanitize documents downloaded from the internet. The administrator wants to ensure that the solution meets security and usability requirements. Which two statements are true regarding Threat Extraction? (Choose two.)
Threat Extraction can be set to provide a link to the original file, often with a warning page. This allows users to access the unsanitized version if they accept the risk, which is useful for usability when sanitization breaks functionality. This feature is configurable and is part of the blade's flexible policy options.
Why this answer
Threat Extraction reconstructs files to remove active content, ensuring safe delivery, and can optionally provide a link to the original file for user access with a warning. These two statements accurately describe its capabilities. The blade operates independently of Threat Emulation and does not rely on Anti-Virus verdicts to decide when to sanitize.
Exam trap
The trap here is assuming Threat Extraction depends on Threat Emulation or Anti-Virus verdicts, when it actually sanitizes proactively based on file type and policy.