Courseiva
Advanced VPN Design →easyMultiple Choice

156-315.81.20 Advanced VPN Design Practice Question

A Check Point administrator is configuring a VPN community and wants to ensure that only specific services are allowed through the VPN tunnel. The administrator wants to enforce this at the community level, affecting all gateways in the community. Which Check Point feature should be used?

⚠ Common exam trap

A common mix-up: candidates confuse the VPN Domain with service restrictions; the VPN Domain defines which networks are encrypted, not which services are permitted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN Community Advanced Settings - Excluded Services

The VPN Community Advanced Settings include an option to exclude specific services from the VPN tunnel. This setting is applied at the community level and affects all gateways, making it the correct choice. The VPN Domain defines encrypted networks, the rulebase is global, and the shared secret is for authentication, so none of these enforce service restrictions at the community level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPN Domain

    Why it's wrong here

    The VPN Domain defines which networks are encrypted, not which services are allowed. It specifies the source and destination networks that will be part of the VPN. While it is a critical setting, it does not restrict the types of traffic or services that can traverse the tunnel. To enforce service restrictions, a different feature is required.

  • ✓

    VPN Community Advanced Settings - Excluded Services

    Why this is correct

    In the VPN Community's Advanced Settings, there is an option to define 'Excluded Services' (or 'Services with Excluded Traffic'). This allows the administrator to specify services that should not be encrypted or allowed through the VPN tunnel. It is a community-level setting that applies to all gateways in the community, precisely matching the requirement to enforce service restrictions at the community level.

  • ✗

    VPN Community Advanced Settings - Shared Secret

    Why it's wrong here

    The Shared Secret is used for authentication during IKE negotiation. It does not control which services are allowed through the tunnel. Configuring a shared secret is necessary for VPN establishment but has no impact on traffic filtering. Therefore, it cannot fulfill the requirement to restrict services at the community level.

  • ✗

    Security Policy Rulebase

    Why it's wrong here

    The Security Policy Rulebase controls traffic based on source, destination, service, and action. While it can restrict services, it is not a community-level setting. Changes to the rulebase affect all traffic, not just VPN traffic, and are not specific to a VPN community. The requirement is to enforce service restrictions at the community level, which is not achieved through the general rulebase.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.