156-215.81.20 Security Policy and NAT Practice Question
A security administrator is troubleshooting a NAT configuration on a Check Point Security Gateway. Internal users cannot reach an external web server through a manual Hide NAT rule, although the Security Policy allows the traffic. The administrator suspects that the NAT rule is not being applied. Which two actions should the administrator take to verify that NAT translation is occurring as expected? (Choose two.)
⚠ Common exam trap
The trap here is assuming that disabling the Security Policy or checking ARP will reveal NAT issues, when NAT operates independently and rule order plus packet inspection are the reliable verification methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the fw monitor command to capture packets before and after NAT translation.
To confirm NAT translation, the administrator should use fw monitor to observe packets before and after translation, and verify the NAT rule base order to ensure the correct rule is matched first. These actions directly show whether translation is applied and whether rule precedence is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the fw monitor command to capture packets before and after NAT translation.
Why this is correct
fw monitor can capture packets at multiple points in the kernel, including before and after NAT. By examining the pre-NAT and post-NAT addresses in the capture, the administrator can confirm whether source or destination translation is being applied as intended.
- ✗
Disable the Security Policy temporarily to see if NAT starts working.
Why it's wrong here
Disabling the Security Policy does not help verify NAT translation and would expose the network. NAT is applied independently of the Security Policy rule base, so this action would not confirm whether the NAT rule is being applied and could create a security risk.
- ✗
Review the gateway's ARP cache to see if the NAT IP is resolved.
Why it's wrong here
ARP resolves IP addresses to MAC addresses on the local subnet. The NAT IP is usually a public address routed to the gateway, so ARP cache entries do not indicate whether NAT translation is occurring. This action is irrelevant to verifying NAT rule application.
- ✓
Check the NAT rule base order to ensure the Hide NAT rule is above any conflicting rules.
Why this is correct
NAT rules are processed in order, and the first matching rule is applied. If a broader rule appears above the Hide NAT rule, it may match first and prevent the intended translation. Verifying rule order helps confirm that the correct NAT rule is being evaluated.
- ✗
Enable IP forwarding on the gateway to allow NAT to function.
Why it's wrong here
IP forwarding is a general routing function, not a NAT-specific setting. On Check Point gateways, NAT is handled by the firewall kernel, and IP forwarding is typically enabled by default. Toggling it does not help diagnose whether the NAT rule is being matched.
Visual reference
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.