156-215.81.20 Application Control and URL Filtering Practice Question
A security administrator needs to create a rule that matches HTTP traffic based on the specific web application 'LinkedIn' rather than the entire 'Social Networking' category. The administrator has already enabled Application Control and URL Filtering on the Security Gateway. In SmartConsole, which object type should be used in the Source or Destination column of the security rule to match the application directly?
⚠ Common exam trap
Watch out — candidates often confuse application-level matching with traditional network or service objects, assuming that port-based or IP-based rules can achieve the same granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application/Site
Application/Site objects are the correct choice because they are purpose-built for Application Control and URL Filtering, enabling the administrator to match specific applications like 'LinkedIn' instead of broad categories. This allows precise enforcement of policies that differentiate between individual applications and their parent categories, which is essential for granular control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network object
Why it's wrong here
Network objects represent IP addresses or subnets. They do not understand application-level protocols or web categories. Using a Network object would match traffic based solely on IP, which cannot distinguish 'LinkedIn' from other social networking sites or even other applications hosted on the same IP. Therefore, it fails to meet the requirement of application-specific matching.
- ✗
Service object
Why it's wrong here
Service objects define protocols and ports, such as TCP/443 or HTTP. While necessary for basic traffic matching, they do not provide application-level granularity. A Service object for HTTPS would match all encrypted traffic, not just the 'LinkedIn' application. Thus, it cannot differentiate between different web applications sharing the same port, making it unsuitable for this requirement.
- ✓
Application/Site
Why this is correct
Application/Site objects are specifically designed for Application Control and URL Filtering. They allow the administrator to match individual applications or websites, such as 'LinkedIn', rather than broad categories. This granularity is exactly what the scenario requires to differentiate the application from the overall category. Using this object in the rule base ensures the gateway inspects and enforces policy at the application layer.
- ✗
User object
Why it's wrong here
User objects represent individual users or groups for identity-based policies. They are used in the Source column to enforce rules based on who is accessing the resource, not what application is being accessed. Using a User object would not match the application itself; it would only restrict which users are subject to the rule, leaving the application matching unaddressed.
Visual reference
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.