Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

An administrator needs to restrict access to social media applications while allowing access to specific professional features. Which feature in the Application Control blade provides this granularity?

⚠ Common exam trap

Candidates frequently assume that blocking the entire application is the only option, overlooking the 'Application Features' tab which allows for granular control like permitting LinkedIn browsing but blocking LinkedIn messaging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application Features

Application Control includes granular controls for many major web applications, known as 'Application Widgets' or 'Features.' By selecting an application, administrators can choose to block or allow specific sub-functions like 'Chat' or 'Post' instead of the entire site. This allows organizations to maintain productivity while still permitting necessary business communication, which is a critical balance for modern enterprise network security policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTPS Inspection

    Why it's wrong here

    HTTPS Inspection is responsible for decrypting traffic to allow for inspection, but it does not provide granular application feature control. It acts as a prerequisite for inspecting encrypted traffic, ensuring that the Application Control blade can see the payloads necessary to identify specific sub-features within a website.

  • ✓

    Application Features

    Why this is correct

    Application Features allow administrators to control specific sub-functions of an application, such as allowing LinkedIn browsing but blocking the ability to send messages. This granular control is essential for managing web usage without completely disabling useful business tools that employees rely on for daily professional networking.

  • ✗

    URL Filtering Category

    Why it's wrong here

    URL Filtering categories classify entire domains based on their general content type, such as 'Social Networking'. While this can block the entire domain, it lacks the technical capability to distinguish between specific features like uploading files versus reading content, which is required for granular policy enforcement.

  • ✗

    Identity Awareness

    Why it's wrong here

    Identity Awareness identifies users and groups, providing the 'who' in the policy rule. While it is useful to apply rules to specific departments, it does not provide the capability to manipulate or restrict sub-features within a single application like Facebook or LinkedIn for those specific users.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.