156-215.81.20 Security Policy and NAT Practice Question
A security administrator is configuring NAT for a new internal server (10.0.0.5) that needs to be accessible from the Internet on port 443 using the public IP 203.0.113.20. The administrator creates a host object for the server and configures a Static NAT rule. Which additional configuration is required to allow inbound HTTPS traffic to reach the server?
⚠ Common exam trap
The trap here is focusing solely on NAT configuration and forgetting that firewall rules must explicitly allow the translated traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall rule allowing HTTPS traffic from the Internet to the public IP 203.0.113.20.
NAT and firewall rules work together. NAT translates the destination IP from public to private, but the firewall must still allow the traffic. A rule permitting HTTPS from the Internet to the public IP (or the internal server object, depending on NAT rule configuration) is essential. Without it, the gateway drops the packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A route on the Security Gateway pointing the public IP 203.0.113.20 to the internal server.
Why it's wrong here
Routing directs packets to the gateway, but the gateway already has a route to the internal network where the server resides. The public IP is typically routed to the gateway by the ISP. Adding a route on the gateway for the public IP to the internal server is unnecessary and could cause routing loops. The missing piece is a firewall rule permitting the traffic.
- ✗
A NAT rule that translates the destination port from 443 to 443 for the server.
Why it's wrong here
Port translation is not needed if the server listens on port 443. Static NAT typically translates IP addresses, not ports, unless port translation is explicitly configured. The scenario does not indicate a port mismatch. The required configuration is a firewall rule to allow the traffic, not additional NAT.
- ✓
A firewall rule allowing HTTPS traffic from the Internet to the public IP 203.0.113.20.
Why this is correct
NAT translates addresses, but firewall rules control whether traffic is allowed. For inbound access to the internal server via its public IP, a firewall rule must permit HTTPS (TCP 443) from the Internet to the translated destination. Without this rule, the traffic will be dropped even if NAT is correctly configured. The rule should reference the public IP or the original destination object, depending on the policy design.
- ✗
A NAT rule that translates the source IP of the server to the public IP for outbound traffic.
Why it's wrong here
Outbound NAT (Hide or Static) is not required for inbound access. The server may need outbound NAT for its own initiated connections, but that is separate from allowing inbound HTTPS. The question asks for additional configuration to allow inbound traffic, which is handled by firewall rules, not outbound NAT.
Visual reference
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.