Courseiva
Security Policy and NAT →hardMultiple Choice

156-215.81.20 Security Policy and NAT Practice Question

A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a DMZ. The DMZ contains a mail server with IP address 10.10.10.5 and a web server with IP address 10.10.10.6. Both servers must be accessible from the Internet using separate public IP addresses. The administrator wants to minimize the number of NAT rules and ensure that the translation is applied correctly. Which NAT configuration approach is most appropriate?

⚠ Common exam trap

The trap here is assuming that a NAT pool or Hide NAT can provide separate public IPs for inbound access, when in fact Static NAT is required for one-to-one publishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create two Static NAT rules: one for the mail server and one for the web server, each translating to its respective public IP address.

The most appropriate approach is to create two Static NAT rules, one for each server, mapping each to its own public IP address. This provides deterministic one-to-one translation, enabling inbound access to each server and preserving outbound source IPs. Hide NAT and NAT pools are designed for outbound many-to-one or many-to-many translation and do not support publishing multiple servers on distinct public IPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure NAT on the gateway object to automatically translate all DMZ traffic to the gateway's external IP address.

    Why it's wrong here

    Configuring NAT on the gateway object to translate all DMZ traffic to the gateway's external IP would result in Hide NAT, where all DMZ servers share the gateway's public IP. This does not provide separate public IPs for each server and does not allow inbound connections to specific servers. It also does not meet the requirement of separate public addresses.

  • ✗

    Create a single Hide NAT rule for the entire DMZ subnet, translating to one public IP address.

    Why it's wrong here

    Hide NAT would translate both servers to a single public IP address, which would not allow separate public IPs for each server. Additionally, Hide NAT does not support inbound connections to specific servers, so external users could not reach the mail or web servers individually. This approach fails to meet the requirement of separate public IP addresses.

  • ✗

    Create a single manual NAT rule that translates both servers using a NAT pool of two public IP addresses.

    Why it's wrong here

    A NAT pool is used for Hide NAT to translate multiple internal hosts to a pool of public IP addresses, but it does not provide deterministic one-to-one mappings for inbound access. External users would not know which public IP maps to which server, and inbound connections would not be reliably forwarded. Static NAT is required for publishing individual servers.

  • ✓

    Create two Static NAT rules: one for the mail server and one for the web server, each translating to its respective public IP address.

    Why this is correct

    Static NAT rules provide one-to-one mappings for each server, allowing them to be reached at their own public IP addresses. This is the correct approach because it ensures that inbound connections to each public IP are translated to the correct internal server. It also preserves the original IP addresses for outbound connections, which is important for services like email.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.