You must prevent malware hidden in image files. Which server-side check gives the best practical protection
Only check file extension.
Validate MIME type from client-supplied headers.
Rely on antivirus scanning only.
Inspect file “magic bytes” / file signature and re-encode images server-side.
This question is part of this quiz :
Cyber Quiz Day 35