156-215.81.20 VPN Basics Practice Question
A remote branch office requires a persistent VPN connection to the corporate headquarters. Which feature should be configured to ensure the tunnel remains active even when no user traffic is flowing?
⚠ Common exam trap
Candidates often confuse 'VPN Tunnel Test' with 'Dead Peer Detection' (DPD) or 'Keepalive' settings, not realizing that 'VPN Tunnel Test' is the specific Check Point feature for permanent tunnels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPN Tunnel Test
VPN Tunnel Test (Permanent Tunnels) is the standard method in Check Point to ensure a gateway keeps the tunnel alive. By sending periodic probe packets, the gateway prevents the connection from timing out due to inactivity. This is essential for monitoring the health of the connection and ensuring immediate connectivity for time-sensitive applications or branch office operations that require constant reachability to the central data center.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dead Peer Detection (DPD)
Why it's wrong here
DPD is primarily designed to detect if a VPN peer has gone offline or become unresponsive. While it uses probes, it does not necessarily force a persistent tunnel state if the intention is specifically for continuous traffic flow simulation for monitoring purposes.
- ✓
VPN Tunnel Test
Why this is correct
VPN Tunnel Test, when enabled as a 'Permanent Tunnel,' forces the gateway to periodically send traffic through the tunnel. This keeps the SA entries active in the kernel, preventing them from expiring due to inactivity, which is critical for constant branch connectivity.
- ✗
IKE Keepalives
Why it's wrong here
IKE Keepalives are an older mechanism that is largely deprecated in modern IPsec implementations. Check Point prefers VPN Tunnel Test or DPD for monitoring peer availability and tunnel status, as they are more reliable and adhere better to current RFC standards.
- ✗
Aggressive Mode
Why it's wrong here
Aggressive mode relates to the speed and verbosity of the Phase 1 handshake, not the persistence of the tunnel. It does not provide any functionality to maintain an idle tunnel, as it is strictly concerned with establishing the initial secure security association.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.