Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

An administrator needs to block a specific web application that is not recognized by the default Application Control signature database. The application uses a custom protocol on TCP port 8443. What is the most appropriate method to achieve this?

⚠ Common exam trap

The trap here is assuming that blocking the port or server is sufficient, but Application Control requires application-level identification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new Application Control signature using the Application Control Signature Tool.

To block a custom application not in the signature database, the administrator must create a custom Application Control signature using the Application Control Signature Tool. This tool allows defining the application based on port, protocol, and other characteristics. Port-based blocking or URL categorization would not accurately target the application and could cause collateral damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the 'Application Control' blade and rely on its heuristic engine to detect the application.

    Why it's wrong here

    The Application Control blade uses signatures and behavioral analysis, but it does not automatically detect unknown applications without a signature. Heuristics may identify some patterns, but for a custom protocol, a signature is required. Relying solely on heuristics is unreliable and not a supported method for blocking a specific unrecognized application.

  • ✓

    Create a new Application Control signature using the Application Control Signature Tool.

    Why this is correct

    The Application Control Signature Tool allows administrators to create custom signatures for applications not covered by the default database. By defining the protocol characteristics, such as port and pattern, the gateway can identify and block the custom application. This is the intended method for handling proprietary or niche applications in Check Point.

  • ✗

    Use a URL Filtering category override to block all traffic to the server hosting the application.

    Why it's wrong here

    Category Override is used to reclassify specific URLs or IP addresses into a different URL Filtering category. It does not create application signatures based on protocol or port. Blocking the server would affect all applications on that server, not just the custom one, and it would not identify the application itself.

  • ✗

    Configure a firewall rule that blocks all traffic on TCP port 8443.

    Why it's wrong here

    Blocking all traffic on TCP port 8443 is a port-based rule, not application-based. It would block any application using that port, including legitimate ones, and does not provide granular control. Application Control is designed to identify applications regardless of port, so this approach is overly broad and ineffective for the specific requirement.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.