Be able to verify a URL's category, explain AppWiki, decide when a Custom Application is needed, and configure granular Application Control rules. The key is matching the right blade and object type to the requirement, not just blocking broadly.
Start practicing
Application Control and URL Filtering — choose a session length
Free · No account required
Domain overview
This domain covers Check Point's Application Control and URL Filtering blades on R80. x gateways and management. You must know how AppWiki categorization works, how to verify a URL's category, when to build Custom Applications, and how to apply granular application and URL filtering rules in policy.
Exam objectives
Using the URL categorization tool to verify a specific URL's category
AppWiki's role as the application signature and categorization database
Creating Custom Applications for traffic not covered by standard signatures
Granular application control, such as allowing specific features within social media apps
Confusing URL Filtering category checks with Application Control signatures; they are separate blades with different matching logic.
Assuming Custom Applications replace standard ones; they supplement signatures for unsupported or internal applications.
Believing application control blocks an entire app only; granular per-feature or per-category actions are configurable.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to restrict access to social media applications while allowing access to specific professional features. Which feature in the Application Control blade provides this granularity?
2Refer to the exhibit. An administrator sees the following debug output while troubleshooting a blocked connection. What is the most likely cause for this traffic being dropped?
3A company wants to prevent employees from uploading files to cloud storage sites. Which action should the administrator take in the Application Control rule?
4An administrator wants to ensure that all URLs are categorized correctly. Which tool is used to verify the category of a specific URL?
5What happens when the URL Filtering database is unreachable by the gateway?
6Which blade must be active to perform HTTPS Inspection on traffic?
7When would an administrator use a 'Custom Application' instead of a standard application in the Application Control blade?
8Refer to the exhibit. An administrator is troubleshooting Application Control traffic. What does the CLI output verify regarding the traffic flow?
9Refer to the exhibit. An administrator sees this error in the logs. What is the most effective way to resolve this for better visibility?
10Which object type should an administrator use to block access to a wide range of websites deemed inappropriate, such as adult content?
11What is the primary benefit of the 'ThreatCloud' service for URL Filtering?
12Refer to the exhibit. The log shows a drop. What does this indicate about the rule base?
13What is the primary function of the 'Application Wiki' (AppWiki) in Check Point?
14An administrator wants to ensure that users are warned before accessing a potentially high-risk website. Which feature should be used?
15An administrator needs to block a specific web application that is not recognized by the default Application Control signature database. The application uses a custom protocol on TCP port 8443. What is the most appropriate method to achieve this?
16A security administrator at a financial firm needs to block all peer-to-peer file-sharing applications for the entire company, but must allow legitimate business use of instant messaging. The administrator wants the least administrative effort and automatic updates of new application signatures. What should the administrator do?
17An administrator notices that Application Control is not identifying a popular cloud-based application even though it is listed in the Application Control database. The gateway is running R81.10 and the database is up to date. What could be the cause?
18A security administrator notices that users are accessing a newly registered domain that is not yet categorized by Check Point. The administrator wants to block access to uncategorized sites until they are reviewed. Which URL Filtering action should be configured?
19A security administrator needs to block access to a specific unknown application that uses HTTP but does not match any signature in the current Application Control database. The administrator wants to ensure the application is blocked immediately without waiting for a database update. What is the most efficient way to achieve this?
20A security policy requires that users are presented with a warning page before accessing sites categorized as 'High Risk'. After the warning, they can choose to proceed. Which URL Filtering action should be configured in the rule?
21An administrator notices that a user is able to access a website categorized as 'Social Networking' even though the URL Filtering policy blocks that category. The administrator confirms the policy is installed and the user's traffic is inspected. What is the most likely cause?
22A security administrator is configuring a rule in the Application Control policy to block all peer-to-peer file sharing applications. After enabling the rule, users report that they can still use uTorrent to download files. The administrator checks the logs and sees that the uTorrent traffic is being matched by a different rule that allows all allowed applications. What is the most likely cause of this issue?
23An administrator wants to enforce a policy that blocks access to websites categorized as 'Hacking' but allows access to 'Computer Security' sites. The administrator creates a URL Filtering rule with the action 'Block' for the 'Hacking' category and places it above a rule that allows 'Computer Security'. However, users report that they can still access some hacking-related sites. Upon investigation, the administrator finds that these sites are categorized as 'Computer Security' by the Check Point URL Filtering database. What should the administrator do to ensure these sites are blocked?
24A security administrator at a financial firm wants to allow access to the corporate banking portal at 'secure.bank.com' but block all other online banking sites for a specific user group. The policy already includes a rule that blocks the 'Financial Services' category. How should the administrator configure the policy to meet this requirement?
25A security administrator needs to allow access to a specific website that is categorized as 'Social Networking' while blocking all other social networking sites. The administrator wants to ensure that only that particular URL is allowed. What is the most efficient way to achieve this in the URL Filtering policy?
26A security administrator needs to create a rule that matches HTTP traffic based on the specific web application 'LinkedIn' rather than the entire 'Social Networking' category. The administrator has already enabled Application Control and URL Filtering on the Security Gateway. In SmartConsole, which object type should be used in the Source or Destination column of the security rule to match the application directly?
27An administrator needs to ensure that employees cannot access known malicious websites. The company uses Check Point URL Filtering with ThreatCloud. Which action should the administrator take to block access to these sites?
28A security administrator has configured a URL Filtering rule to block the 'Gambling' category. Users report that they can still access some gambling sites. The administrator checks the logs and sees that the traffic is being allowed by a rule that allows 'Any' application and 'Any' URL. The administrator verifies that the block rule is above the allow rule. What is the most likely reason for the issue?
29An administrator has configured a rule to block the 'File Storage and Sharing' category. Users report that they can still access 'Dropbox' via the web interface, but the log shows the connection as allowed. The administrator verifies that the rule is correctly placed and the Application Control blade is enabled. Which action should the administrator take to ensure 'Dropbox' is blocked?
30A security administrator notices that users are accessing a gambling website that is not being blocked, even though the 'Gambling' category is set to Block in the URL Filtering policy. The administrator verifies that the policy is installed and the site is indeed categorized as 'Gambling'. What is the most likely reason for this issue?
31An administrator is configuring Application Control and URL Filtering on a new Security Gateway. The administrator wants to ensure that the gateway can identify applications and enforce policy correctly. Which two actions are required to enable Application Control and URL Filtering? (Choose two.)
Be able to verify a URL's category, explain AppWiki, decide when a Custom Application is needed, and configure granular Application Control rules. The key is matching the right blade and object type to the requirement, not just blocking broadly.
The Courseiva 156-215.81.20 question bank contains 31 questions in the Application Control and URL Filtering domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Application Control and URL Filtering domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included