Courseiva

156-215.81.20 Application Control and URL Filtering Practice Question

Which blade must be active to perform HTTPS Inspection on traffic?

⚠ Common exam trap

Candidates often assume that enabling Application Control or URL Filtering is sufficient. They fail to realize that without HTTPS Inspection, the gateway cannot see the encrypted traffic to apply those policies effectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HTTPS Inspection

HTTPS Inspection is a prerequisite for several other blades, including Application Control, URL Filtering, and Threat Prevention. It is managed via a dedicated policy area in the SmartConsole. The inspection engine decrypts SSL/TLS traffic, inspects the plaintext, and then re-encrypts it, allowing the security blades to see the content that would otherwise be hidden from the gateway, which is essential for modern security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Threat Emulation

    Why it's wrong here

    Threat Emulation is used to sandboxing files to detect malicious behavior. While it can receive decrypted traffic from the HTTPS Inspection engine, it does not manage the inspection process itself. HTTPS Inspection is a separate, foundational blade that handles the decryption and re-encryption of traffic for all other security blades.

  • ✗

    Application Control

    Why it's wrong here

    Application Control uses the results of HTTPS Inspection to identify applications, but it does not perform the inspection itself. The HTTPS Inspection policy is configured separately, and it provides the decrypted stream to Application Control, which then performs the deep packet inspection required to identify specific applications and sub-features.

  • ✓

    HTTPS Inspection

    Why this is correct

    HTTPS Inspection is the primary blade responsible for decrypting encrypted traffic. It acts as a man-in-the-middle to provide visibility to other security blades. Without this blade enabled and properly configured with the necessary certificates, the gateway cannot inspect encrypted traffic, rendering Application Control and URL Filtering blind to most web traffic.

  • ✗

    Identity Awareness

    Why it's wrong here

    Identity Awareness is used for user identification and access control based on identities. It has no role in the decryption of SSL/TLS traffic. HTTPS Inspection is a separate process that is entirely independent of the user-mapping logic, focusing on the payload integrity and visibility rather than the source or destination user.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.