Hi!
Having read a few articles and skimmed thru the Threat Prevention admin manual I seem to be missing the point of using Threat Extraction.
In my limited experience with dealing with spam(managing filters, quarantine), I haven't encountered a case where an email was both infected and containing actual useful information for the recipient.
In some cases, someone might have hijacked an account and added a malicious attachment or url to the original email. But if this is just a copy of already consumed information, it would not serve any purpose to the recipient (after Threat Extraction did its job), except to confuse them.
So I'm probably missing something but I don't know what.