156-215.81.20 · domain
Application Control and URL Filtering
This domain covers Check Point's Application Control and URL Filtering blades on R80.x gateways and management. You must know how AppWiki categorization works, how to verify a URL's category, when to build Custom Applications, and how to apply granular application and URL filtering rules in policy.
Focused practice
Practice Application Control and URL Filtering questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Application Control and URL Filtering
Be able to verify a URL's category, explain AppWiki, decide when a Custom Application is needed, and configure granular Application Control rules. The key is matching the right blade and object type to the requirement, not just blocking broadly.
Using the URL categorization tool to verify a specific URL's category
AppWiki's role as the application signature and categorization database
Creating Custom Applications for traffic not covered by standard signatures
Granular application control, such as allowing specific features within social media apps
Watch out for
Common Application Control and URL Filtering exam traps
- ▸Confusing URL Filtering category checks with Application Control signatures; they are separate blades with different matching logic.
- ▸Assuming Custom Applications replace standard ones; they supplement signatures for unsupported or internal applications.
- ▸Believing application control blocks an entire app only; granular per-feature or per-category actions are configurable.
Question index
All Application Control and URL Filtering questions (31)
Click any question to see the full explanation, or start a practice session above.
A security administrator at a financial firm needs to block all peer-to-peer file-sharing applications for the entire company, but must allow legitimate business use of instant messaging. The administrator wants the least administrative effort and automatic updates of new application signatures. What should the administrator do?
Medium2An administrator notices that a user is able to access a website categorized as 'Social Networking' even though the URL Filtering policy blocks that category. The administrator confirms the policy is installed and the user's traffic is inspected. What is the most likely cause?
Hard3An administrator notices that Application Control is not identifying a popular cloud-based application even though it is listed in the Application Control database. The gateway is running R81.10 and the database is up to date. What could be the cause?
Hard4A security administrator needs to allow access to a specific website that is categorized as 'Social Networking' while blocking all other social networking sites. The administrator wants to ensure that only that particular URL is allowed. What is the most efficient way to achieve this in the URL Filtering policy?
Easy5An administrator wants to enforce a policy that blocks access to websites categorized as 'Hacking' but allows access to 'Computer Security' sites. The administrator creates a URL Filtering rule with the action 'Block' for the 'Hacking' category and places it above a rule that allows 'Computer Security'. However, users report that they can still access some hacking-related sites. Upon investigation, the administrator finds that these sites are categorized as 'Computer Security' by the Check Point URL Filtering database. What should the administrator do to ensure these sites are blocked?
Hard6Which blade must be active to perform HTTPS Inspection on traffic?
Medium7Refer to the exhibit. The log shows a drop. What does this indicate about the rule base?
Hard8A security administrator needs to block access to a specific unknown application that uses HTTP but does not match any signature in the current Application Control database. The administrator wants to ensure the application is blocked immediately without waiting for a database update. What is the most efficient way to achieve this?
Medium9A security administrator notices that users are accessing a newly registered domain that is not yet categorized by Check Point. The administrator wants to block access to uncategorized sites until they are reviewed. Which URL Filtering action should be configured?
Easy10A security administrator is configuring a rule in the Application Control policy to block all peer-to-peer file sharing applications. After enabling the rule, users report that they can still use uTorrent to download files. The administrator checks the logs and sees that the uTorrent traffic is being matched by a different rule that allows all allowed applications. What is the most likely cause of this issue?
Medium11A security administrator has configured a URL Filtering rule to block the 'Gambling' category. Users report that they can still access some gambling sites. The administrator checks the logs and sees that the traffic is being allowed by a rule that allows 'Any' application and 'Any' URL. The administrator verifies that the block rule is above the allow rule. What is the most likely reason for the issue?
Hard12A security administrator at a financial firm wants to allow access to the corporate banking portal at 'secure.bank.com' but block all other online banking sites for a specific user group. The policy already includes a rule that blocks the 'Financial Services' category. How should the administrator configure the policy to meet this requirement?
Medium13A security policy requires that users are presented with a warning page before accessing sites categorized as 'High Risk'. After the warning, they can choose to proceed. Which URL Filtering action should be configured in the rule?
Easy14Which object type should an administrator use to block access to a wide range of websites deemed inappropriate, such as adult content?
Medium15What is the primary benefit of the 'ThreatCloud' service for URL Filtering?
Medium16A security administrator notices that users are accessing a gambling website that is not being blocked, even though the 'Gambling' category is set to Block in the URL Filtering policy. The administrator verifies that the policy is installed and the site is indeed categorized as 'Gambling'. What is the most likely reason for this issue?
Hard17An administrator is configuring Application Control and URL Filtering on a new Security Gateway. The administrator wants to ensure that the gateway can identify applications and enforce policy correctly. Which two actions are required to enable Application Control and URL Filtering? (Choose two.)
Medium18What happens when the URL Filtering database is unreachable by the gateway?
Medium19Refer to the exhibit. An administrator is troubleshooting Application Control traffic. What does the CLI output verify regarding the traffic flow?
Hard20An administrator needs to block a specific web application that is not recognized by the default Application Control signature database. The application uses a custom protocol on TCP port 8443. What is the most appropriate method to achieve this?
Medium21An administrator has configured a rule to block the 'File Storage and Sharing' category. Users report that they can still access 'Dropbox' via the web interface, but the log shows the connection as allowed. The administrator verifies that the rule is correctly placed and the Application Control blade is enabled. Which action should the administrator take to ensure 'Dropbox' is blocked?
Hard22A company wants to prevent employees from uploading files to cloud storage sites. Which action should the administrator take in the Application Control rule?
Medium23An administrator wants to ensure that users are warned before accessing a potentially high-risk website. Which feature should be used?
Medium24What is the primary function of the 'Application Wiki' (AppWiki) in Check Point?
Easy25When would an administrator use a 'Custom Application' instead of a standard application in the Application Control blade?
Hard26An administrator needs to restrict access to social media applications while allowing access to specific professional features. Which feature in the Application Control blade provides this granularity?
Medium27An administrator needs to ensure that employees cannot access known malicious websites. The company uses Check Point URL Filtering with ThreatCloud. Which action should the administrator take to block access to these sites?
Easy28An administrator wants to ensure that all URLs are categorized correctly. Which tool is used to verify the category of a specific URL?
Medium29Refer to the exhibit. An administrator sees the following debug output while troubleshooting a blocked connection. What is the most likely cause for this traffic being dropped?
Hard30A security administrator needs to create a rule that matches HTTP traffic based on the specific web application 'LinkedIn' rather than the entire 'Social Networking' category. The administrator has already enabled Application Control and URL Filtering on the Security Gateway. In SmartConsole, which object type should be used in the Source or Destination column of the security rule to match the application directly?
Medium31Refer to the exhibit. An administrator sees this error in the logs. What is the most effective way to resolve this for better visibility?
HardOther domains
All 156-215.81.20 exam domains
Frequently asked questions
- What does the Application Control and URL Filtering domain cover on the 156-215.81.20 exam?
- Be able to verify a URL's category, explain AppWiki, decide when a Custom Application is needed, and configure granular Application Control rules. The key is matching the right blade and object type to the requirement, not just blocking broadly.
- How many questions are in this domain?
- This page lists all 31 Application Control and URL Filtering questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Application Control and URL Filtering questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.