Courseiva
Security Policy and NAT →easyMultiple Choice

156-215.81.20 Security Policy and NAT Practice Question

An administrator is configuring NAT on a Check Point R81 Security Gateway. A web server with a private IP address of 10.1.1.10 must be reachable from the Internet at the public IP address 203.0.113.10. The administrator creates a host object for the web server and configures a Static NAT rule. Which translation method should be selected in the NAT rule so that the internal IP address is translated to the public IP address?

⚠ Common exam trap

Many candidates confuse Hide NAT with Static NAT and assuming that hiding a server behind a public IP will make it reachable from the Internet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static

Static NAT is the correct translation method because it creates a permanent one-to-one mapping between the internal web server address and the public address. This enables external clients to initiate connections to the server and ensures that return traffic is correctly translated back to the internal address. Hide NAT is designed for outbound connections and does not provide inbound reachability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hide behind gateway

    Why it's wrong here

    Hiding behind the gateway IP address would cause all outbound traffic from the web server to appear to originate from the gateway's public IP, but it would not create an inbound mapping to the web server. Inbound connections to the gateway IP would not be forwarded to the web server, so the web server would remain unreachable from the Internet.

  • ✗

    Hide

    Why it's wrong here

    Hide NAT performs many-to-one translation, which would allow the web server to initiate outbound connections but would not make it reachable from the Internet at a specific public IP address. It also does not preserve the original source IP address for inbound connections, so clients would not be able to connect to the web server. Static translation is required.

  • ✗

    Hide behind cluster

    Why it's wrong here

    Hiding behind a cluster applies to outbound traffic from multiple hosts, using the cluster's virtual IP as the translated source. It does not provide a one-to-one static mapping for inbound access to a specific internal server. This option would not allow external clients to initiate connections to the web server at 203.0.113.10.

  • ✓

    Static

    Why this is correct

    Static NAT creates a one-to-one mapping between the original and translated IP addresses. This allows the internal web server at 10.1.1.10 to be consistently reachable from the Internet at 203.0.113.10, and it preserves the original IP address in both directions. This is the correct translation method for publishing an internal server with a public address.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.