156-215.81.20 Application Control and URL Filtering Practice Question
An administrator wants to ensure that users are warned before accessing a potentially high-risk website. Which feature should be used?
⚠ Common exam trap
Candidates frequently confuse the 'Ask' action with standard blocking or logging actions, missing its unique interactive UserCheck capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'Ask' action.
The 'Ask' action in UserCheck is the standard way to implement a warning mechanism. Instead of outright blocking, it prompts the user to acknowledge the risk before proceeding. This is an effective balance for productivity, allowing access to useful but potentially risky sites while ensuring users are aware of the risks, thereby meeting compliance requirements while minimizing business disruption for necessary web-based tasks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'Drop' action.
Why it's wrong here
The 'Drop' action is a hard block that prevents all access, leaving the user with no option to proceed. If the administrator wants to allow access after a warning, the 'Ask' action is required instead, as 'Drop' does not provide an interactive path for user acknowledgment or justification.
- ✓
The 'Ask' action.
Why this is correct
The 'Ask' action provides a UserCheck portal page that informs the user about the risks of the site and requires them to click to continue. This satisfies the requirement of warning users while providing them with the flexibility to access the site if it is required for their job.
- ✗
The 'Reject' action.
Why it's wrong here
The 'Reject' action is similar to 'Drop' but sends an explicit TCP reset or ICMP unreachable back to the client. It is not an interactive feature and provides no warning page to the user, making it unsuitable for requirements where user notification and acknowledgment are the desired security outcomes.
- ✗
The 'Accept' action.
Why it's wrong here
The 'Accept' action permits traffic without any user interaction or notification. It provides no means to warn the user about the risks associated with the website, which fails to meet the compliance or educational goals of the administrator who needs to ensure users are aware of the potential risks.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.