156-215.81.20 Application Control and URL Filtering Practice Question
A security administrator has configured a URL Filtering rule to block the 'Gambling' category. Users report that they can still access some gambling sites. The administrator checks the logs and sees that the traffic is being allowed by a rule that allows 'Any' application and 'Any' URL. The administrator verifies that the block rule is above the allow rule. What is the most likely reason for the issue?
⚠ Common exam trap
The trap here is assuming that URL Filtering can categorize all HTTPS sites without decryption; in reality, without HTTPS Inspection, only limited information is visible, leading to missed blocks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The gambling sites are using HTTPS, and HTTPS Inspection is not enabled, so the gateway cannot see the full URL and thus cannot categorize it.
When HTTPS traffic is not inspected, the gateway can only see the server name indication (SNI) or the IP address, not the full URL. Many gambling sites use HTTPS, and if the domain alone is not categorized as Gambling, the block rule will not match. Enabling HTTPS Inspection allows the gateway to decrypt the traffic and inspect the full URL, ensuring proper categorization and blocking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The allow rule is using a different action that overrides the block rule.
Why it's wrong here
If the block rule is above the allow rule, the block should take precedence when it matches. The problem is that the block rule is not matching due to lack of visibility into the HTTPS traffic. The allow rule is not overriding; it is simply the first rule that matches because the block rule doesn't match. So this is not the reason.
- ✓
The gambling sites are using HTTPS, and HTTPS Inspection is not enabled, so the gateway cannot see the full URL and thus cannot categorize it.
Why this is correct
Without HTTPS Inspection, the gateway can only see the domain (via SNI) but not the full URL path. If the domain is not categorized as Gambling or if the categorization is based on the full URL, the traffic may not match the block rule. Enabling HTTPS Inspection allows the gateway to decrypt and inspect the full URL, enabling accurate categorization and blocking.
- ✗
The gateway is not licensed for URL Filtering, so it ignores the block rule.
Why it's wrong here
If the gateway were not licensed, no URL Filtering would occur, and the logs would not show any URL categorization attempts. Since the administrator sees logs and the block rule is not matching, the license is likely present. The issue is HTTPS inspection, not licensing.
- ✗
The 'Gambling' category is not included in the URL Filtering database by default.
Why it's wrong here
The 'Gambling' category is a standard category in the Check Point URL Filtering database. It is included by default. The issue is not the absence of the category, but rather the gateway's inability to inspect the encrypted traffic to categorize it correctly. Therefore, this is not the cause.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.