156-315.81.20 Advanced VPN Design Practice Question
A Check Point administrator is configuring a VPN community and wants to ensure that only specific services are allowed through the VPN tunnel. The administrator wants to enforce this at the community level, affecting all gateways in the community. Which Check Point feature should be used?
⚠ Common exam trap
A common mix-up: candidates confuse the VPN Domain with service restrictions; the VPN Domain defines which networks are encrypted, not which services are permitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPN Community Advanced Settings - Excluded Services
The VPN Community Advanced Settings include an option to exclude specific services from the VPN tunnel. This setting is applied at the community level and affects all gateways, making it the correct choice. The VPN Domain defines encrypted networks, the rulebase is global, and the shared secret is for authentication, so none of these enforce service restrictions at the community level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPN Domain
Why it's wrong here
The VPN Domain defines which networks are encrypted, not which services are allowed. It specifies the source and destination networks that will be part of the VPN. While it is a critical setting, it does not restrict the types of traffic or services that can traverse the tunnel. To enforce service restrictions, a different feature is required.
- ✓
VPN Community Advanced Settings - Excluded Services
Why this is correct
In the VPN Community's Advanced Settings, there is an option to define 'Excluded Services' (or 'Services with Excluded Traffic'). This allows the administrator to specify services that should not be encrypted or allowed through the VPN tunnel. It is a community-level setting that applies to all gateways in the community, precisely matching the requirement to enforce service restrictions at the community level.
- ✗
VPN Community Advanced Settings - Shared Secret
Why it's wrong here
The Shared Secret is used for authentication during IKE negotiation. It does not control which services are allowed through the tunnel. Configuring a shared secret is necessary for VPN establishment but has no impact on traffic filtering. Therefore, it cannot fulfill the requirement to restrict services at the community level.
- ✗
Security Policy Rulebase
Why it's wrong here
The Security Policy Rulebase controls traffic based on source, destination, service, and action. While it can restrict services, it is not a community-level setting. Changes to the rulebase affect all traffic, not just VPN traffic, and are not specific to a VPN community. The requirement is to enforce service restrictions at the community level, which is not achieved through the general rulebase.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.