156-215.81.20 Security Policy and NAT Practice Question
An administrator is reviewing the NAT configuration on a Check Point R81 Security Gateway. The gateway has two interfaces: eth1 (internal, 192.168.1.1) and eth2 (external, 203.0.113.1). Internal users need to access the Internet, and the administrator wants to hide their private IP addresses behind the external interface IP. The administrator creates a Hide NAT rule for the internal network object. Which statement correctly describes the outcome of this configuration?
⚠ Common exam trap
Many exam-takers confuse Hide NAT with Static NAT, leading to the misconception that Hide NAT translates inbound traffic or performs destination translation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Outbound traffic from internal users will have its source IP translated to 203.0.113.1.
Hide NAT, also known as many-to-one NAT, translates the source IP of outbound traffic to a single public IP, typically the external interface of the gateway. This allows internal users with private addresses to access the Internet while hiding their internal addressing scheme.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The gateway will perform destination NAT on outbound traffic.
Why it's wrong here
Hide NAT performs source NAT, not destination NAT. Destination NAT is used to translate the destination address of inbound traffic, such as with Static NAT for servers. For outbound traffic, the destination is the Internet host, and the source is translated. This option confuses the direction of translation.
- ✓
Outbound traffic from internal users will have its source IP translated to 203.0.113.1.
Why this is correct
Hide NAT translates the source IP of outbound packets to the external interface IP (203.0.113.1). This allows multiple internal users to share a single public IP for Internet access. The translation is applied to the source address, and the gateway maintains a translation table to route return traffic back to the correct internal host.
- ✗
Internal users will be unable to access each other using their private IPs.
Why it's wrong here
Hide NAT only affects traffic that traverses the gateway and matches the NAT rule. Internal-to-internal traffic typically does not pass through the gateway's NAT rules, or if it does, the NAT rule may not apply. In most cases, internal users can still communicate using private IPs. This option incorrectly assumes that Hide NAT disrupts internal communication.
- ✗
Inbound traffic from the Internet will be translated to 192.168.1.1.
Why it's wrong here
Hide NAT is used for outbound traffic, not inbound. It does not translate inbound connections; those would require Static NAT or a similar configuration. Inbound traffic destined to the external IP would not be automatically translated to the internal interface IP. This option mischaracterizes the direction and purpose of Hide NAT.
Visual reference
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.