156-215.81.20 VPN Basics Practice Question
When configuring a VPN Community, what is the impact of selecting 'Maintain persistent tunnels' on the gateway?
⚠ Common exam trap
Exam candidates often mistake persistent tunnels for a routing keepalive mechanism or assume it dynamically changes encryption algorithms automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It keeps the tunnel active even when idle.
Selecting 'Maintain persistent tunnels' instructs the Check Point gateway to proactively monitor and keep the VPN tunnel active, even when there is no user traffic passing through it. This ensures that the tunnel is ready immediately when traffic arrives, avoiding the latency penalty of the initial IKE negotiation handshake. This is particularly useful for sensitive or real-time applications where initial connection delays could cause issues for users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It forces the tunnel to use a weaker encryption algorithm.
Why it's wrong here
Tunnel persistence has no effect on the cryptographic algorithms chosen. The encryption, integrity, and Diffie-Hellman settings are determined by the VPN community security policy, not by the status of the tunnel's persistence. These settings remain independent and are governed by the established security association properties.
- ✗
It eliminates the need for any authentication.
Why it's wrong here
Authentication is a mandatory requirement for establishing any VPN tunnel, regardless of its persistent status. The gateway must still perform full peer authentication to verify that the remote gateway is authorized to connect. Persistence simply keeps the established tunnel alive; it does not bypass security procedures.
- ✓
It keeps the tunnel active even when idle.
Why this is correct
Persistent tunnels are kept alive by the gateway, even when no user data is flowing. This removes the need for an initial IKE negotiation when traffic finally starts, as the tunnel is already fully established and ready for immediate packet transmission, reducing initial latency for users.
- ✗
It prevents the gateway from logging VPN events.
Why it's wrong here
Logging is a critical function for security monitoring and troubleshooting. Setting a tunnel to be persistent does not change the logging policy. The gateway will continue to log VPN connection attempts, rekeying events, and other tunnel-related activity as defined in the global logging and alert settings.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.