156-215.81.20 Security Policy and NAT Practice Question
An administrator needs to ensure that traffic from the internal network (10.10.10.0/24) accessing the Internet is translated to the gateway's external interface IP. Which NAT configuration method is required to achieve this while ensuring that the internal IP addresses are never exposed to the Internet?
⚠ Common exam trap
Candidates often confuse Hide NAT with Static NAT. They fail to select 'Hide' which is specifically required to map multiple internal IPs to a single external interface IP address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hide NAT using the gateway's external interface IP.
Hide NAT, also known as Port Address Translation (PAT), is the optimal method for mapping multiple internal source IP addresses to a single public IP address. By utilizing the gateway's external interface, the administrator effectively masks internal addressing. This is critical for security posture, as it limits reconnaissance opportunities and conserves scarce public IPv4 address space while enabling necessary outbound connectivity for private internal hosts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static NAT mapping for each internal host.
Why it's wrong here
Static NAT creates a one-to-one mapping between an internal and external IP address. This would require an equivalent number of public IP addresses to the internal hosts, which is impractical for a large subnet and fails to hide the internal network structure effectively from external observers.
- ✓
Hide NAT using the gateway's external interface IP.
Why this is correct
Hide NAT allows multiple internal hosts to share a single public IP address by using unique source ports to track individual sessions. This method successfully masks the internal addressing scheme, fulfilling the security requirement to protect the internal topology while maintaining connectivity for the 10.10.10.0/24 subnet.
- ✗
Dynamic NAT without hide enabled.
Why it's wrong here
Dynamic NAT without hide allocates public IP addresses from a pool on a first-come, first-served basis. Once the pool is exhausted, subsequent connections fail. This approach does not hide the internal IP identity effectively and requires a large range of public addresses to sustain active connections.
- ✗
Disable NAT and use proxy ARP on the gateway.
Why it's wrong here
Disabling NAT exposes internal IP addresses directly to the internet, which violates the security requirement. Proxy ARP only helps in resolving MAC addresses for routed subnets and does not perform the address translation necessary to mask private IP ranges behind a single public interface address.
Visual reference
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.