156-215.81.20 Security Policy and NAT Practice Question
A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a web server farm. The administrator needs to ensure that external users can access the web servers using a single public IP, and that the web servers can initiate outbound connections to the Internet. The administrator decides to use manual NAT rules. Which two statements are correct regarding the configuration of manual NAT rules in this scenario? (Choose two.)
⚠ Common exam trap
The trap here is assuming that manual NAT rules are limited to a single direction or that they require a special mode, when they are flexible and processed before automatic rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manual NAT rules can be configured to translate both source and destination in a single rule.
Manual NAT rules are processed before automatic NAT rules, allowing administrators to override automatic translations. They also support translation of both source and destination in a single rule, which is useful for complex scenarios involving web servers that need bidirectional translation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Manual NAT rules can be configured to translate both source and destination in a single rule.
Why this is correct
Manual NAT rules allow you to specify both original and translated source and destination. This is useful for scenarios where you need to translate both the source and destination addresses, such as when a server needs to appear as a different address to external clients while also hiding its own source. In this scenario, you could translate the destination to the web server's private IP and the source to the public IP.
- ✓
Manual NAT rules are processed before automatic NAT rules.
Why this is correct
Manual NAT rules are always evaluated before automatic NAT rules, which are generated from object NAT settings. This allows administrators to override automatic NAT behavior with more specific rules. In this scenario, placing manual rules first ensures that the desired translation for the web servers takes precedence over any automatic rules that might be generated from their objects.
- ✗
Manual NAT rules are evaluated after the security policy.
Why it's wrong here
NAT rules are evaluated before the security policy for inbound traffic, and after for outbound? Actually, in Check Point, NAT is applied before the security policy for inbound and after for outbound? The correct order is that NAT is applied before the security policy for inbound and after for outbound? Wait, in Check Point, the order is: for inbound, NAT is applied before the security policy; for outbound, NAT is applied after the security policy. But manual NAT rules are part of the NAT rulebase, which is processed before the security policy for inbound and after for outbound? Actually, the Check Point order is: 1. NAT (for inbound), 2. Security Policy, 3. NAT (for outbound). So this statement is incorrect because it oversimplifies the order.
- ✗
Manual NAT rules require the gateway to be in a NAT-enabled mode.
Why it's wrong here
There is no separate NAT-enabled mode for the gateway. NAT is configured on the gateway object, and manual NAT rules are part of the security policy. The gateway always processes NAT rules if they are installed. This statement is misleading because it suggests a specific mode that does not exist.
- ✗
Manual NAT rules are only applied to inbound traffic.
Why it's wrong here
Manual NAT rules can be applied to both inbound and outbound traffic. They are not restricted to a single direction. In this scenario, the administrator needs both inbound access to the web servers and outbound connectivity for the servers, so manual rules can handle both. This statement is incorrect because it limits the scope of manual NAT rules.
Visual reference
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.