156-215.81.20 Application Control and URL Filtering Practice Question
A security administrator needs to block access to a specific unknown application that uses HTTP but does not match any signature in the current Application Control database. The administrator wants to ensure the application is blocked immediately without waiting for a database update. What is the most efficient way to achieve this?
⚠ Common exam trap
The trap here is assuming that ThreatCloud updates are instantaneous or that URL Filtering can block any application based on URLs alone.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom application signature using the 'Custom Application' feature in SmartConsole.
The Custom Application feature in Check Point allows administrators to define signatures for applications not yet recognized by the Application Control database. This provides immediate enforcement without relying on external updates, ensuring the unknown application is blocked promptly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom application signature using the 'Custom Application' feature in SmartConsole.
Why this is correct
Custom Application signatures allow administrators to define new applications based on specific patterns (e.g., URL, header, or payload). This enables immediate blocking without waiting for a database update, as the signature is locally defined and enforced by the gateway.
- ✗
Configure a firewall rule to block all traffic on the application's default port.
Why it's wrong here
Blocking a port is a blunt approach that may disrupt other legitimate services using the same port. It also fails if the application uses standard ports like 80 or 443. Application Control is designed to identify and block applications regardless of port.
- ✗
Use a URL Filtering category override to block the application's known URLs.
Why it's wrong here
Category override is for reclassifying URLs, not for creating new application signatures. If the application uses dynamic URLs or non-standard ports, URL Filtering may not reliably block it. This method is indirect and may not cover all traffic patterns.
- ✗
Enable 'Application Control' in 'Detect' mode and rely on ThreatCloud to update the signature.
Why it's wrong here
Detect mode only logs traffic; it does not block. Relying on ThreatCloud updates introduces delay, and the application may remain unblocked until a signature is available. The scenario requires immediate blocking, so this approach is insufficient.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.