156-215.81.20 Security Policy and NAT Practice Question
An administrator needs to allow internal users to access the Internet using Hide NAT. The internal network is 192.168.1.0/24, and the gateway's external interface IP is 203.0.113.5. Which NAT rule should be configured?
⚠ Common exam trap
The trap here is mixing up source and destination translation fields, or selecting a rule that translates the destination instead of the source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source: 192.168.1.0/24, Destination: Any, Service: Any, Translated Source: 203.0.113.5, Translated Destination: Original
To hide internal users behind the gateway's external IP for outbound Internet access, the NAT rule must specify the internal network as the source and the public IP as the translated source. The destination should remain original because Hide NAT only translates the source address for outbound traffic. This allows multiple internal users to share the single public IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Source: 192.168.1.0/24, Destination: Any, Service: Any, Translated Source: 203.0.113.5, Translated Destination: Original
Why this is correct
This rule hides the internal network behind the gateway's external IP for all outbound traffic. The source is the internal network, and the translated source is the public IP. The destination remains original, which is correct for Hide NAT because only the source is translated for outbound connections.
- ✗
Source: Any, Destination: 192.168.1.0/24, Service: Any, Translated Source: Original, Translated Destination: 203.0.113.5
Why it's wrong here
This rule would translate the destination for traffic destined to the internal network, which is the opposite of what is needed. It would be used for inbound NAT, not for hiding internal users accessing the Internet.
- ✗
Source: 203.0.113.5, Destination: 192.168.1.0/24, Service: Any, Translated Source: Original, Translated Destination: Original
Why it's wrong here
This rule does not perform any translation; it simply matches traffic from the public IP to the internal network. It would not hide internal addresses and is not a valid NAT rule for the described requirement.
- ✗
Source: 192.168.1.0/24, Destination: Any, Service: Any, Translated Source: Original, Translated Destination: 203.0.113.5
Why it's wrong here
This rule translates the destination to the public IP, which is incorrect for outbound Hide NAT. It would likely break outbound connections because the destination would be changed to the gateway's IP, not the original external server.
Visual reference
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.