Courseiva
Security Policy and NAT →mediumMultiple Choice

156-215.81.20 Security Policy and NAT Practice Question

A company uses Hide NAT to allow internal users to access the Internet through a single public IP address on the gateway. The security administrator notices that external servers cannot initiate connections to internal hosts, but internal users can reach external services. Which statement explains why external servers cannot initiate connections to internal hosts in this scenario?

⚠ Common exam trap

The trap here is thinking that Hide NAT blocks inbound traffic by policy, when the real limitation is that many-to-one translation provides no unique address for external hosts to target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hide NAT uses a one-to-many mapping, so external hosts have no unique internal address to connect to.

Hide NAT maps many internal addresses to one public address, so external systems cannot determine which internal host to reach. Without a unique one-to-one mapping such as Static NAT, inbound connections initiated from the Internet cannot be delivered to a specific internal machine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The gateway drops all inbound traffic by default unless a corresponding NAT rule exists.

    Why it's wrong here

    Security Policy controls whether inbound traffic is allowed or dropped. The absence of a NAT rule is not what blocks inbound connections; rather, Hide NAT does not create a unique mapping that would allow external hosts to reach a specific internal host.

  • ✗

    Hide NAT is only applied to outbound traffic, so inbound connections are never translated.

    Why it's wrong here

    Hide NAT is indeed typically used for outbound traffic, but the fundamental reason inbound connections fail is the many-to-one mapping, not a restriction that prevents inbound translation altogether. The gateway could translate inbound traffic if a static mapping existed, but Hide NAT does not provide one.

  • ✓

    Hide NAT uses a one-to-many mapping, so external hosts have no unique internal address to connect to.

    Why this is correct

    Hide NAT translates many internal addresses to one public address, so there is no unique mapping that an external host could use to reach a specific internal host. Inbound connections cannot be directed to a particular internal machine because the public address represents multiple internal hosts.

  • ✗

    Hide NAT requires a separate public IP address for each internal host, which is not configured.

    Why it's wrong here

    Hide NAT is specifically designed to share a single public IP address among many internal hosts. Requiring a separate public IP per host would be Static NAT, not Hide NAT, so this statement mischaracterizes how Hide NAT operates.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.