The CE Plus auditor sends test files including known malicious file types to in scope mailboxes to verify that malicious attachments are blocked or detonated safely.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.