156-215.81.20 Application Control and URL Filtering Practice Question
A company wants to prevent employees from uploading files to cloud storage sites. Which action should the administrator take in the Application Control rule?
⚠ Common exam trap
Candidates often default to blocking the entire application or domain. They overlook the granularity provided by Application Control features, which allow for specific actions like blocking uploads while permitting downloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Select the application and disable the 'Upload' feature.
To restrict uploads, the administrator should locate the specific cloud storage application in the Application Control rule and use the 'Features' column to disable the 'Upload' capability. This is more effective than blocking the entire domain, as it preserves access to cloud storage for viewing and downloading files while strictly enforcing the corporate policy against data exfiltration through these commonly used tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable HTTPS Inspection and block the site entirely.
Why it's wrong here
Blocking the site entirely would stop both uploads and downloads, which is too restrictive for the business case. HTTPS Inspection is necessary to see the traffic, but blocking the entire domain defeats the purpose of allowing users to view or download files from legitimate cloud services for work.
- ✗
Enable the 'Upload' feature in the application signature.
Why it's wrong here
Enabling the 'Upload' feature would likely grant permission rather than restrict it. The correct approach involves selecting the 'Upload' sub-feature and setting it to 'Drop' or 'Block', while keeping the parent application permitted, ensuring the policy enforces the restriction rather than granting additional access rights to employees.
- ✓
Select the application and disable the 'Upload' feature.
Why this is correct
Selecting the application within the rule and specifically disabling the 'Upload' sub-feature is the correct configuration. This allows the user to still access the cloud storage application for legitimate tasks like downloading or viewing files, while preventing the specific action of uploading data to external cloud storage sites.
- ✗
Create a URL Filtering exception for the domain.
Why it's wrong here
URL Filtering works by blocking entire domains or categories. It does not possess the granular capability to block specific features like 'uploading' inside a website. Using a URL filter exception would only apply to the entire domain, missing the requirement to maintain access to other non-upload features.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.