156-215.81.20 Application Control and URL Filtering Practice Question
An administrator needs to ensure that employees cannot access known malicious websites. The company uses Check Point URL Filtering with ThreatCloud. Which action should the administrator take to block access to these sites?
⚠ Common exam trap
Many candidates confuse Threat Prevention with URL Filtering; Threat Prevention blocks malicious payloads but does not block access to websites based on URL category.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Malicious Sites' category in a URL Filtering rule with a 'Block' action.
Using the 'Malicious Sites' category in URL Filtering is the most efficient way to block access to known malicious websites. This category is maintained by Check Point's ThreatCloud, which continuously updates its database with new threats. Other methods either do not target URLs or are too broad, making them unsuitable for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the malicious sites to a custom group and apply a 'Block' action in the URL Filtering policy.
Why it's wrong here
Manually adding malicious sites to a custom group is impractical because new malicious sites appear constantly. The built-in 'Malicious Sites' category is automatically updated via ThreatCloud, providing dynamic protection. Custom groups require manual maintenance and would quickly become outdated.
- ✗
Configure a Threat Prevention profile with a 'Block' action for malicious sites.
Why it's wrong here
Threat Prevention profiles handle malware, viruses, and intrusions at the network level, not URL categorization. While they can block malicious content, they do not specifically block access to websites based on URL categories. URL Filtering is the correct feature for blocking access to categorized websites.
- ✓
Enable the 'Malicious Sites' category in a URL Filtering rule with a 'Block' action.
Why this is correct
The 'Malicious Sites' category is specifically designed to block websites known to distribute malware or phishing content. Enabling it with a Block action in a URL Filtering rule will prevent users from accessing these dangerous sites. This leverages Check Point's ThreatCloud intelligence, which continuously updates the category.
- ✗
Create an Application Control rule to block the 'Web Browsing' application.
Why it's wrong here
Blocking the 'Web Browsing' application would prevent all web access, not just malicious sites. This is overly restrictive and would disrupt legitimate business activities. Application Control is not designed to categorize websites by risk; it identifies applications regardless of the website's reputation.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.