Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

A remote branch office requires a persistent VPN connection to the corporate headquarters. Which feature should be configured to ensure the tunnel remains active even when no user traffic is flowing?

⚠ Common exam trap

Candidates often confuse 'VPN Tunnel Test' with 'Dead Peer Detection' (DPD) or 'Keepalive' settings, not realizing that 'VPN Tunnel Test' is the specific Check Point feature for permanent tunnels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN Tunnel Test

VPN Tunnel Test (Permanent Tunnels) is the standard method in Check Point to ensure a gateway keeps the tunnel alive. By sending periodic probe packets, the gateway prevents the connection from timing out due to inactivity. This is essential for monitoring the health of the connection and ensuring immediate connectivity for time-sensitive applications or branch office operations that require constant reachability to the central data center.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dead Peer Detection (DPD)

    Why it's wrong here

    DPD is primarily designed to detect if a VPN peer has gone offline or become unresponsive. While it uses probes, it does not necessarily force a persistent tunnel state if the intention is specifically for continuous traffic flow simulation for monitoring purposes.

  • ✓

    VPN Tunnel Test

    Why this is correct

    VPN Tunnel Test, when enabled as a 'Permanent Tunnel,' forces the gateway to periodically send traffic through the tunnel. This keeps the SA entries active in the kernel, preventing them from expiring due to inactivity, which is critical for constant branch connectivity.

  • ✗

    IKE Keepalives

    Why it's wrong here

    IKE Keepalives are an older mechanism that is largely deprecated in modern IPsec implementations. Check Point prefers VPN Tunnel Test or DPD for monitoring peer availability and tunnel status, as they are more reliable and adhere better to current RFC standards.

  • ✗

    Aggressive Mode

    Why it's wrong here

    Aggressive mode relates to the speed and verbosity of the Phase 1 handshake, not the persistence of the tunnel. It does not provide any functionality to maintain an idle tunnel, as it is strictly concerned with establishing the initial secure security association.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.