A user downloads a PDF from the internet that contains a zero-day exploit. The Harmony Endpoint agent is configured with Threat Emulation and Threat Extraction. The policy for both is set to the 'Prevent' action. What is the expected sequence of events when the user attempts to open the file? ```mermaid sequenceDiagram participant User participant Endpoint Agent participant ThreatCloud participant Cleaned File User->>Endpoint Agent: Attempts to open PDF Endpoint Agent->>ThreatCloud: Sends file for analysis Note over ThreatCloud: Emulation & Extraction ThreatCloud-->>Endpoint Agent: ??? Endpoint Agent-->>User: ??? Endpoint Agent-->>Cleaned File: ??? ```