156-215.81.20 VPN Basics Practice Question
Which TWO of the following are mandatory steps when configuring a new Site-to-Site VPN community?
⚠ Common exam trap
Candidates assume shared secrets or pre-shared keys are mandatory for all VPN communities, forgetting that certificate-based authentication is standard and encryption domains and gateway definitions are the true mandatory steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define the participating gateways in the community.
Setting up a Site-to-Site VPN community requires defining both the participating gateways and the specific networks that will be protected. These steps ensure that the Check Point gateway knows exactly which devices are part of the VPN and which internal traffic must be encrypted, which is essential for consistent security enforcement and preventing sensitive data from accidentally traversing the network in the clear.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define the participating gateways in the community.
Why this is correct
Defining the participating gateways is the first step in creating a VPN community. It establishes the tunnel endpoints and allows the management server to push the necessary configuration to each node, ensuring they understand the peer identity and encryption parameters required for successful tunnel establishment.
- ✓
Configure the encryption domain for each gateway.
Why this is correct
Configuring the encryption domain is mandatory because it tells the gateway which subnets should be routed through the VPN tunnel. Without this, the gateway would not know which internal traffic to encrypt, and all traffic would remain in the clear or be blocked by security policy.
- ✗
Disable all firewall rules on the gateway.
Why it's wrong here
Disabling firewall rules is a critical security vulnerability and is never a part of VPN configuration. VPNs must operate in conjunction with robust firewall rules to ensure that traffic is both encrypted and inspected for threats, maintaining a 'secure by design' posture for the network.
- ✗
Ensure that the peers are in different physical regions.
Why it's wrong here
VPNs do not require geographic separation. They are used to create secure tunnels regardless of where the gateways are located. You can have a Site-to-Site VPN between two gateways sitting in the same rack if you need to enforce encryption for traffic moving between their protected internal network segments.
- ✗
Use only the default IKE proposals provided.
Why it's wrong here
While default proposals can be used, they are not mandatory. Administrators frequently customize proposals to match specific security requirements or to align with third-party vendors. The key is that both sides must share a common, supported proposal, regardless of whether it is a default or a custom one.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.