Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

A security administrator needs to allow access to a specific website that is categorized as 'Social Networking' while blocking all other social networking sites. The administrator wants to ensure that only that particular URL is allowed. What is the most efficient way to achieve this in the URL Filtering policy?

⚠ Common exam trap

Many exam-takers confuse 'Category Override' with rule exceptions; Category Override changes the category, while a specific allow rule above a block rule is the direct method for exceptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a rule with the action 'Allow' for the specific URL and place it above the rule that blocks the 'Social Networking' category.

To allow a specific URL while blocking its category, the administrator can create an allow rule for that URL and position it above the category block rule. Check Point evaluates rules top-down, so the specific allow rule will match first, granting access to that URL. Other social networking sites will not match the allow rule and will be blocked by the category rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the 'Social Networking' category to exclude the specific URL.

    Why it's wrong here

    The default categories cannot be modified; they are maintained by Check Point. Administrators cannot exclude URLs from a predefined category. While custom categories can be used, simply modifying the default category is not possible. Therefore, this approach is invalid.

  • ✓

    Create a rule with the action 'Allow' for the specific URL and place it above the rule that blocks the 'Social Networking' category.

    Why this is correct

    By creating an allow rule for the specific URL and placing it above the block rule, the gateway will match the allow rule first for that URL, permitting access. All other social networking sites will not match the allow rule and will be blocked by the subsequent category block rule. This is efficient and precise.

  • ✗

    Use the 'Category Override' feature to allow the URL for all users.

    Why it's wrong here

    Category Override is used to change the category of a URL, not to create exceptions in rules. It would reclassify the URL, but then the block rule for 'Social Networking' would no longer apply if the URL is moved to a different category. However, this changes categorization globally and may have unintended effects. It is not the most efficient way for a single URL exception.

  • ✗

    Create a new rule with the action 'Block' for the specific URL and place it above the block rule for 'Social Networking'.

    Why it's wrong here

    Blocking the specific URL would prevent access, which is the opposite of the requirement. The administrator needs to allow that URL while blocking others. Placing a block rule for the URL would deny access to it, so this action is incorrect for the scenario.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.