156-215.81.20 Security Policy and NAT Practice Question
A Check Point administrator is configuring NAT for a new subnet that will be used for a guest wireless network. The guest subnet is 172.16.50.0/24, and the administrator wants to hide all guest traffic behind the external interface IP 203.0.113.5. The administrator creates a network object for the guest subnet and configures Hide NAT using the external interface. After testing, guests can access the Internet, but the administrator notices that the translation is not being applied to traffic originating from the guest subnet when it is destined to a server on the internal network (192.168.1.0/24). What is the most likely reason for this behavior?
⚠ Common exam trap
The trap here is assuming that NAT rules apply to all traffic, including internal-to-internal, when in fact they only apply to traffic traversing the gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The NAT rule is only applied to traffic that traverses the gateway; internal-to-internal traffic does not match the rule.
NAT rules in Check Point are applied only to traffic that passes through the Security Gateway. Guest-to-internal traffic may be routed internally without going through the gateway, or the gateway may not apply NAT to that traffic. Therefore, the Hide NAT rule is not triggered, and the source IP remains unchanged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The NAT rule is only applied to traffic that traverses the gateway; internal-to-internal traffic does not match the rule.
Why this is correct
NAT rules are applied to traffic that passes through the Security Gateway. Traffic from the guest subnet to an internal server may be routed directly within the internal network without traversing the gateway, or the gateway may not apply NAT to traffic that does not cross an interface pair subject to NAT. Thus, the Hide NAT rule is not triggered for that internal traffic.
- ✗
The Hide NAT rule must be placed below the internal cleanup rule to take effect.
Why it's wrong here
NAT rules are processed before the security policy cleanup rule. The cleanup rule is part of the security policy, not the NAT rulebase. Placing a NAT rule below a cleanup rule is not possible because they are in different rulebases. This option confuses the order of NAT and security policy processing.
- ✗
The guest subnet object must be configured with a Static NAT rule for internal traffic.
Why it's wrong here
Static NAT is used for one-to-one mapping, typically for inbound access to servers. It is not required for internal traffic. The issue is not the type of NAT but whether the traffic traverses the gateway and matches the NAT rule. Configuring Static NAT would not solve the problem and could introduce additional complexity.
- ✗
The external interface IP 203.0.113.5 is not reachable from the internal network, so NAT fails.
Why it's wrong here
NAT translation occurs before routing, so reachability of the external IP from the internal network is not relevant. The translation itself does not depend on the destination being able to reach the translated source. The real issue is that the traffic does not match the NAT rule because it does not traverse the gateway in the expected direction.
Visual reference
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.