156-215.81.20 Application Control and URL Filtering Practice Question
Exhibit
log_entry: { 'action': 'drop', 'blade': 'Application Control', 'reason': 'Application identified as P2P' }Refer to the exhibit. The log shows a drop. What does this indicate about the rule base?
⚠ Common exam trap
Examinees often misinterpret application drops as routing failures or generic firewall rule blocks, ignoring the explicit log details identifying specific application categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A rule exists that blocks the P2P application category.
The log entry explicitly states the action was a drop due to the Application Control blade identifying P2P traffic. This implies that there is an active security rule in the policy configured to block the P2P application category. The gateway is functioning correctly by identifying the traffic type and enforcing the defined security policy, demonstrating that the blade is successfully integrated and operational within the existing security policy infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The gateway is failing to identify the application correctly.
Why it's wrong here
The log explicitly states the reason is 'Application identified as P2P', which confirms that the identification process was successful. If identification had failed, the log would typically show 'unknown' or a different status, whereas here it correctly recognized the P2P nature of the traffic and dropped it as intended.
- ✓
A rule exists that blocks the P2P application category.
Why this is correct
When a rule is configured to block a specific application or category, the engine generates this specific log entry when it encounters matching traffic. This log confirms that the policy is active, the application is recognized, and the enforcement action (Drop) is being applied according to the security policy guidelines.
- ✗
The packet was blocked by a standard Firewall rule, not Application Control.
Why it's wrong here
The log explicitly cites the 'blade' as 'Application Control'. If a standard firewall rule had blocked the packet, the blade field would indicate 'Firewall' or a similar base component. This log clearly points to the application-layer inspection engine as the source of the drop action for this traffic flow.
- ✗
The P2P application is allowed, but the traffic was dropped by HTTPS inspection.
Why it's wrong here
If HTTPS inspection had dropped the traffic, the 'blade' field would indicate 'HTTPS Inspection'. Because the blade is explicitly listed as 'Application Control', the action was taken by that specific component, confirming that the policy rule applied at the application level is what triggered the drop.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.