Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

Exhibit

Error: HTTPS Inspection is not enabled. Application Control cannot inspect encrypted traffic.

Refer to the exhibit. An administrator sees this error in the logs. What is the most effective way to resolve this for better visibility?

⚠ Common exam trap

Candidates often suggest simply creating a new rule, failing to recognize that without HTTPS inspection, the gateway is blind to encrypted traffic and cannot apply application-layer rules effectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable HTTPS Inspection and define appropriate bypass policies.

Without HTTPS inspection, the gateway cannot read the contents of encrypted traffic, limiting its ability to identify applications hidden within HTTPS tunnels. Enabling HTTPS inspection allows the gateway to act as an SSL proxy, decrypting and re-encrypting traffic to perform full inspection. This is critical for modern security, as the vast majority of web traffic is now encrypted, rendering standard packet inspection largely ineffective for application-layer controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable Application Control and rely on URL Filtering.

    Why it's wrong here

    Disabling Application Control reduces security by removing the ability to inspect traffic beyond the domain level. URL filtering alone cannot identify application features or block specific sub-actions, leading to a significant security gap in environments where modern web applications are used for both business and personal tasks.

  • ✓

    Enable HTTPS Inspection and define appropriate bypass policies.

    Why this is correct

    Enabling HTTPS inspection is the required step to allow the security gateway to decrypt traffic for inspection. Defining bypass policies for sensitive sites, such as banking or medical portals, ensures compliance and privacy, while allowing the blade to perform deep inspection on all other traffic for improved security posture.

  • ✗

    Increase the timeout settings on the gateway for encrypted traffic.

    Why it's wrong here

    Modifying timeout settings does not resolve the inability to see inside encrypted packets. Increasing timeouts might keep a session alive longer but will not provide the visibility required for the Application Control blade to identify the application or enforce granular policies on the encrypted content of the session.

  • ✗

    Configure the client browsers to trust the Management Server certificate.

    Why it's wrong here

    While client trust is a part of HTTPS inspection deployment, it is not the configuration step that enables the functionality on the gateway. The blade must first be enabled in the policy and the SSL proxy configured; trusting certificates is a client-side prerequisite to prevent browser warnings, not the solution.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.