Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

When configuring a VPN Community, what is the impact of selecting 'Maintain persistent tunnels' on the gateway?

⚠ Common exam trap

Exam candidates often mistake persistent tunnels for a routing keepalive mechanism or assume it dynamically changes encryption algorithms automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It keeps the tunnel active even when idle.

Selecting 'Maintain persistent tunnels' instructs the Check Point gateway to proactively monitor and keep the VPN tunnel active, even when there is no user traffic passing through it. This ensures that the tunnel is ready immediately when traffic arrives, avoiding the latency penalty of the initial IKE negotiation handshake. This is particularly useful for sensitive or real-time applications where initial connection delays could cause issues for users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It forces the tunnel to use a weaker encryption algorithm.

    Why it's wrong here

    Tunnel persistence has no effect on the cryptographic algorithms chosen. The encryption, integrity, and Diffie-Hellman settings are determined by the VPN community security policy, not by the status of the tunnel's persistence. These settings remain independent and are governed by the established security association properties.

  • ✗

    It eliminates the need for any authentication.

    Why it's wrong here

    Authentication is a mandatory requirement for establishing any VPN tunnel, regardless of its persistent status. The gateway must still perform full peer authentication to verify that the remote gateway is authorized to connect. Persistence simply keeps the established tunnel alive; it does not bypass security procedures.

  • ✓

    It keeps the tunnel active even when idle.

    Why this is correct

    Persistent tunnels are kept alive by the gateway, even when no user data is flowing. This removes the need for an initial IKE negotiation when traffic finally starts, as the tunnel is already fully established and ready for immediate packet transmission, reducing initial latency for users.

  • ✗

    It prevents the gateway from logging VPN events.

    Why it's wrong here

    Logging is a critical function for security monitoring and troubleshooting. Setting a tunnel to be persistent does not change the logging policy. The gateway will continue to log VPN connection attempts, rekeying events, and other tunnel-related activity as defined in the global logging and alert settings.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.