Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

A network administrator is configuring a VPN community that includes a Check Point R81 Security Gateway and a third-party IPsec gateway. The administrator needs to ensure that the VPN tunnel uses specific encryption and hashing algorithms that are supported by both devices. Where should the administrator configure these settings in SmartConsole?

⚠ Common exam trap

The trap here is assuming that encryption algorithms are configured globally or on the gateway object, rather than within the VPN community where they apply to specific peer relationships.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the VPN community's 'Encryption' properties.

The VPN community's 'Encryption' properties allow administrators to define the encryption and hashing algorithms for that specific community. This is crucial when interoperating with third-party gateways that may not support the default algorithms. Other locations like Global Properties or gateway IPsec settings do not provide per-community algorithm configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    In the VPN community's 'Encryption' properties.

    Why this is correct

    Within a VPN community object, the 'Encryption' section allows administrators to specify the encryption and hashing algorithms to be used for that community. This is essential when connecting to third-party gateways that may not support the default Check Point algorithms. Configuring these settings ensures compatibility and successful tunnel establishment.

  • ✗

    In the Global Properties under 'VPN > Advanced'.

    Why it's wrong here

    Global Properties contain system-wide VPN settings, but they are not used to define specific encryption and hashing algorithms for a particular community. These properties control general VPN behavior and are not the place to set per-community algorithms for interoperability with third-party gateways.

  • ✗

    In the Security Gateway object's 'IPsec' section.

    Why it's wrong here

    The Security Gateway object contains IPsec settings, but these are typically used for the gateway's own IPsec parameters, not for defining the algorithms for a specific VPN community. For community-specific algorithm negotiation, the VPN community's encryption properties must be used.

  • ✗

    In the 'VPN Clients' section of the gateway object.

    Why it's wrong here

    The 'VPN Clients' section is used for Remote Access VPN settings, such as Office Mode and visitor mode. It does not control encryption algorithms for Site-to-Site VPN communities. This option is irrelevant to the scenario of configuring algorithms for a third-party IPsec gateway.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.