Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

An administrator is configuring Application Control and URL Filtering on a new Security Gateway. The administrator wants to ensure that the gateway can identify applications and enforce policy correctly. Which two actions are required to enable Application Control and URL Filtering? (Choose two.)

⚠ Common exam trap

The trap here is assuming that additional configurations like HTTPS Inspection or DNS settings are required, when they are optional or unrelated to the basic enablement of the blades.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the Application Control and URL Filtering policy on the Security Gateway.

To enable Application Control and URL Filtering, the administrator must first enable the blade on the Security Gateway object, which activates the inspection capabilities. Then, after configuring the desired rules, the policy must be installed on the gateway to enforce those rules. Both steps are essential for the features to function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable HTTPS Inspection on all rules.

    Why it's wrong here

    HTTPS Inspection is recommended for inspecting encrypted traffic, but it is not a mandatory requirement to enable Application Control and URL Filtering. The blades can function on unencrypted traffic without HTTPS Inspection. While enabling it enhances visibility, it is an optional configuration that depends on the organization's security policy and performance considerations.

  • ✗

    Configure a DNS server for reverse lookups.

    Why it's wrong here

    While DNS is important for general network operations, reverse DNS lookups are not a requirement for Application Control and URL Filtering. The gateway identifies applications and URLs based on signatures and URL databases, not on reverse DNS. Therefore, configuring reverse DNS is not necessary to enable these features, and it would not affect their functionality.

  • ✓

    Install the Application Control and URL Filtering policy on the Security Gateway.

    Why this is correct

    After configuring the blade and rules, the policy must be installed on the gateway. This pushes the configuration and activates the enforcement. Without installing the policy, the gateway continues to operate with its previous configuration, and the new Application Control and URL Filtering rules will not take effect. Policy installation is a critical step in the deployment process.

  • ✓

    Enable the Application Control and URL Filtering blade on the Security Gateway object.

    Why this is correct

    Enabling the Application Control and URL Filtering blade on the Security Gateway is mandatory because it activates the necessary inspection engines and allows the gateway to process traffic according to application and URL policies. Without this blade enabled, the gateway cannot identify applications or categories, and any rules referencing them will not be enforced.

  • ✗

    Create a new administrator account with read-only permissions.

    Why it's wrong here

    Creating a read-only administrator account is unrelated to enabling Application Control and URL Filtering. This feature is about traffic inspection and policy enforcement, not about user permissions. While read-only accounts can be useful for monitoring, they do not contribute to the activation or operation of the Application Control and URL Filtering blades.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.