Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

A security administrator at a financial firm wants to allow access to the corporate banking portal at 'secure.bank.com' but block all other online banking sites for a specific user group. The policy already includes a rule that blocks the 'Financial Services' category. How should the administrator configure the policy to meet this requirement?

⚠ Common exam trap

The trap here is assuming that Application Control can enforce URL-level exceptions, when it actually classifies traffic by application signature rather than by specific website.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a URL Filtering rule above the blocking rule with an 'Allow' action for the destination 'secure.bank.com'.

The correct approach is to create an Allow rule for the specific URL above the general block rule. URL Filtering rules are evaluated sequentially, so the first matching rule determines the action. This allows precise exceptions without affecting the broader category block. Using Application Control would not provide the URL granularity needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the existing blocking rule to exclude the 'Financial Services' category and create a new rule to block that category.

    Why it's wrong here

    Excluding the category from the blocking rule would allow all financial sites, which is not the goal. Creating another block rule for the same category would be redundant and would not create the specific exception for secure.bank.com. This approach does not achieve granular control.

  • ✓

    Create a URL Filtering rule above the blocking rule with an 'Allow' action for the destination 'secure.bank.com'.

    Why this is correct

    This is correct because URL Filtering rules are processed top-down, so placing an Allow rule for the specific URL before the general block rule ensures that traffic to secure.bank.com is permitted while all other financial sites are blocked. This approach uses explicit exceptions, which is a common best practice in Check Point policies.

  • ✗

    Use an Application Control rule to allow the 'Banking' application and block all others.

    Why it's wrong here

    Application Control identifies applications based on traffic signatures, not specific URLs. While it might recognize a banking application, it cannot distinguish between different banking websites like secure.bank.com and others. The requirement is URL-specific, so URL Filtering is the appropriate tool.

  • ✗

    Add 'secure.bank.com' to the 'Allowed URLs' list in the Threat Prevention policy.

    Why it's wrong here

    Threat Prevention policies handle malware and intrusion prevention, not URL categorization. Allowed URLs are not a standard object there, and this would not override URL Filtering category blocks. The correct place to manage URL access is the URL Filtering policy layer, not Threat Prevention.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.