Courseiva
Advanced Threat Prevention →mediumMultiple Select

CCSM Advanced Threat Prevention Practice Question

Which TWO of the following actions are available when configuring Threat Extraction to handle potentially malicious documents? (Select 2)

⚠ Common exam trap

Candidates select 'Block' or 'Delete' as the primary action. They confuse the Threat Extraction process (which delivers a safe version) with the Threat Emulation process (which blocks malicious files).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Extracting potentially malicious parts like macros and embedded objects.

Threat Extraction focuses on delivering safe content to users instantly by stripping away active or exploitable parts of a file. Understanding the difference between cleaning a file and converting it is essential for balancing document usability with the organization's risk tolerance and security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypting the document with a password before delivery.

    Why it's wrong here

    Encryption is not a function of the Threat Extraction blade. The blade's purpose is to remove threats like macros or embedded links, not to provide confidentiality. Password protecting a file would actually hinder the ability of other security layers to inspect the content in the future.

  • ✓

    Extracting potentially malicious parts like macros and embedded objects.

    Why this is correct

    This action allows the user to receive the original file format (e.g., .docx or .xlsx) but with all active content removed. It is a highly effective way to neutralize document-based threats while maintaining the ability for the user to edit the remaining static content of the file.

  • ✗

    Quarantining the file on the local endpoint for manual review.

    Why it's wrong here

    Quarantining is typically a function of the Anti-Virus or SandBlast Agent on the endpoint, rather than the Threat Extraction blade on the gateway. Threat Extraction is designed for real-time traffic modification to ensure the safe delivery of documents to the end user without manual intervention.

  • ✓

    Converting the document into a PDF format for safe viewing.

    Why this is correct

    Converting a document to PDF is one of the safest extraction methods because it flattens the file, removing all active elements and scripts. This ensures the user can view the visual content of the document without any risk of executing malicious code embedded in the original file.

  • ✗

    Automatically uploading the file to a public malware sandbox.

    Why it's wrong here

    Threat Extraction works locally on the gateway or via the ThreatCloud for the extraction process, but it does not automatically send files to public third-party sandboxes. Integration with Threat Emulation handles the sandbox analysis, while Extraction focuses on the immediate delivery of a safe version.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.