Courseiva
Security Policy and NAT →easyMultiple Choice

156-215.81.20 Security Policy and NAT Practice Question

An administrator needs to allow internal users to access the Internet using Hide NAT. The internal network is 192.168.1.0/24, and the gateway's external interface IP is 203.0.113.5. Which NAT rule should be configured?

⚠ Common exam trap

The trap here is mixing up source and destination translation fields, or selecting a rule that translates the destination instead of the source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Source: 192.168.1.0/24, Destination: Any, Service: Any, Translated Source: 203.0.113.5, Translated Destination: Original

To hide internal users behind the gateway's external IP for outbound Internet access, the NAT rule must specify the internal network as the source and the public IP as the translated source. The destination should remain original because Hide NAT only translates the source address for outbound traffic. This allows multiple internal users to share the single public IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Source: 192.168.1.0/24, Destination: Any, Service: Any, Translated Source: 203.0.113.5, Translated Destination: Original

    Why this is correct

    This rule hides the internal network behind the gateway's external IP for all outbound traffic. The source is the internal network, and the translated source is the public IP. The destination remains original, which is correct for Hide NAT because only the source is translated for outbound connections.

  • ✗

    Source: Any, Destination: 192.168.1.0/24, Service: Any, Translated Source: Original, Translated Destination: 203.0.113.5

    Why it's wrong here

    This rule would translate the destination for traffic destined to the internal network, which is the opposite of what is needed. It would be used for inbound NAT, not for hiding internal users accessing the Internet.

  • ✗

    Source: 203.0.113.5, Destination: 192.168.1.0/24, Service: Any, Translated Source: Original, Translated Destination: Original

    Why it's wrong here

    This rule does not perform any translation; it simply matches traffic from the public IP to the internal network. It would not hide internal addresses and is not a valid NAT rule for the described requirement.

  • ✗

    Source: 192.168.1.0/24, Destination: Any, Service: Any, Translated Source: Original, Translated Destination: 203.0.113.5

    Why it's wrong here

    This rule translates the destination to the public IP, which is incorrect for outbound Hide NAT. It would likely break outbound connections because the destination would be changed to the gateway's IP, not the original external server.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.