Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

A security administrator notices that users are accessing a gambling website that is not being blocked, even though the 'Gambling' category is set to Block in the URL Filtering policy. The administrator verifies that the policy is installed and the site is indeed categorized as 'Gambling'. What is the most likely reason for this issue?

⚠ Common exam trap

The trap here is assuming that URL Filtering works identically for HTTP and HTTPS without additional configuration; in reality, HTTPS requires inspection to categorize and block based on URL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The users are accessing the site via HTTPS and HTTPS inspection is not enabled.

The most likely cause is that the gambling site is accessed over HTTPS and HTTPS inspection is not enabled. Without inspection, the gateway cannot see the full URL path or the encrypted content, so it cannot accurately categorize the traffic. Enabling HTTPS inspection allows the gateway to decrypt and inspect the traffic, ensuring that URL Filtering policies are enforced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The users are accessing the site via HTTPS and HTTPS inspection is not enabled.

    Why this is correct

    Without HTTPS inspection, the gateway cannot decrypt the traffic to see the full URL and categorize it. It may only see the domain name via SNI, but if the site uses a shared IP or CDN, categorization may fail. Enabling HTTPS inspection allows the gateway to inspect the full URL and enforce the policy correctly.

  • ✗

    The 'Gambling' category is not included in the ThreatCloud database.

    Why it's wrong here

    The 'Gambling' category is a standard URL Filtering category and is included in ThreatCloud. It is regularly updated. The issue is not the absence of the category but rather the inability to inspect the traffic due to encryption.

  • ✗

    The user's browser is using DNS over HTTPS (DoH), bypassing the gateway's DNS filtering.

    Why it's wrong here

    DNS filtering is separate from URL Filtering. Even if DoH is used, URL Filtering operates at the HTTP/HTTPS layer. The gateway would still see the IP and SNI, but without HTTPS inspection, it cannot see the full URL. DoH might bypass DNS-based blocking, but URL Filtering is not DNS-based.

  • ✗

    The URL Filtering policy is applied only to HTTP traffic by default.

    Why it's wrong here

    URL Filtering can apply to both HTTP and HTTPS, but HTTPS requires inspection. By default, HTTPS traffic is not inspected, but that does not mean URL Filtering is limited to HTTP. The policy can enforce categories on HTTPS if inspection is enabled.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.