Courseiva
Security Policy and NAT →mediumMultiple Choice

156-215.81.20 Security Policy and NAT Practice Question

An administrator needs to ensure that traffic from the internal network (10.10.10.0/24) accessing the Internet is translated to the gateway's external interface IP. Which NAT configuration method is required to achieve this while ensuring that the internal IP addresses are never exposed to the Internet?

⚠ Common exam trap

Candidates often confuse Hide NAT with Static NAT. They fail to select 'Hide' which is specifically required to map multiple internal IPs to a single external interface IP address.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hide NAT using the gateway's external interface IP.

Hide NAT, also known as Port Address Translation (PAT), is the optimal method for mapping multiple internal source IP addresses to a single public IP address. By utilizing the gateway's external interface, the administrator effectively masks internal addressing. This is critical for security posture, as it limits reconnaissance opportunities and conserves scarce public IPv4 address space while enabling necessary outbound connectivity for private internal hosts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Static NAT mapping for each internal host.

    Why it's wrong here

    Static NAT creates a one-to-one mapping between an internal and external IP address. This would require an equivalent number of public IP addresses to the internal hosts, which is impractical for a large subnet and fails to hide the internal network structure effectively from external observers.

  • ✓

    Hide NAT using the gateway's external interface IP.

    Why this is correct

    Hide NAT allows multiple internal hosts to share a single public IP address by using unique source ports to track individual sessions. This method successfully masks the internal addressing scheme, fulfilling the security requirement to protect the internal topology while maintaining connectivity for the 10.10.10.0/24 subnet.

  • ✗

    Dynamic NAT without hide enabled.

    Why it's wrong here

    Dynamic NAT without hide allocates public IP addresses from a pool on a first-come, first-served basis. Once the pool is exhausted, subsequent connections fail. This approach does not hide the internal IP identity effectively and requires a large range of public addresses to sustain active connections.

  • ✗

    Disable NAT and use proxy ARP on the gateway.

    Why it's wrong here

    Disabling NAT exposes internal IP addresses directly to the internet, which violates the security requirement. Proxy ARP only helps in resolving MAC addresses for routed subnets and does not perform the address translation necessary to mask private IP ranges behind a single public interface address.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.