156-215.81.20 Application Control and URL Filtering Practice Question
When would an administrator use a 'Custom Application' instead of a standard application in the Application Control blade?
⚠ Common exam trap
Candidates often assume a custom application is required for blocking encrypted traffic or common web apps, failing to realize it is exclusively for apps missing from the official database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When the application is not present in the Check Point database.
Custom Applications are used when the gateway cannot identify a proprietary, internal, or very niche web application using the standard signature database. By defining a custom application based on URL patterns, domains, or specific header content, administrators can extend the reach of the Application Control blade to include internal corporate apps that are not covered by Check Point's public database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
When the application is blocked by the URL Filtering blade.
Why it's wrong here
Blocking in URL Filtering is a separate function. Creating a custom application does not override a URL filter block; it simply creates a new identifier for a protocol or web tool. If an application is already handled by URL Filtering, a custom application is redundant and adds unnecessary complexity to management.
- ✓
When the application is not present in the Check Point database.
Why this is correct
Custom Applications provide a way to identify and control traffic for applications that are not globally recognized by the Check Point cloud. This is common for custom-developed, internal-only business applications, allowing administrators to apply the same security policies to these proprietary tools as they do to well-known commercial web applications.
- ✗
When the application requires HTTPS Inspection.
Why it's wrong here
HTTPS Inspection is required for all applications that use encrypted traffic, whether they are standard or custom. Creating a custom application does not change the requirement for inspection. The need for inspection is dictated by the protocol, not by whether the application was identified using a pre-defined signature or a custom one.
- ✗
When the administrator wants to bypass the security policy.
Why it's wrong here
Custom applications are used to enforce, not bypass, security policies. They enable the gateway to identify traffic that was previously 'Unknown', allowing for precise policy rules (e.g., Allow, Block, Log). Creating them to bypass security would be counterproductive and violates the principles of a secure, zero-trust network environment.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.