156-315.81.20 Advanced VPN Design Practice Question
A Check Point administrator is designing a hub-and-spoke VPN community where all branch offices must communicate through the central gateway. The administrator wants to ensure that traffic between spokes is routed via the hub without requiring direct tunnels. Which Check Point VPN community configuration achieves this?
⚠ Common exam trap
Test-takers frequently confuse Star topology with Mesh topology, or assuming that setting VPN domains can enforce hub-and-spoke routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the community as 'Star' topology with the central gateway as the center and branch gateways as satellites.
In Check Point VPN community design, a Star topology explicitly defines a central gateway and satellite gateways. Satellites only build tunnels to the center, ensuring all inter-spoke traffic traverses the hub. This is the standard way to implement hub-and-spoke VPNs and centralize security policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Mesh' topology in the VPN community, allowing all gateways to establish direct tunnels with each other.
Why it's wrong here
Mesh topology creates direct tunnels between all participating gateways, which contradicts the requirement to route spoke traffic through the hub. This would allow direct spoke-to-spoke communication, bypassing the central gateway, and may not be desirable for centralized policy enforcement or traffic inspection.
- ✓
Configure the community as 'Star' topology with the central gateway as the center and branch gateways as satellites.
Why this is correct
Star topology in a Check Point VPN community designates one gateway as the center and others as satellites. Satellites establish tunnels only to the center, so spoke-to-spoke traffic is forced through the hub. This matches the requirement for centralized routing and policy enforcement without direct spoke tunnels.
- ✗
Set the VPN domain of each branch gateway to include all other branch networks, enabling direct tunnels.
Why it's wrong here
Including all branch networks in each gateway's VPN domain would cause the gateways to attempt direct tunnels to each other, effectively creating a mesh. This bypasses the hub and may lead to unsupported topologies or policy conflicts. It does not enforce hub-and-spoke routing.
- ✗
Use 'Remote Access' community type, which automatically routes all inter-branch traffic through the central gateway.
Why it's wrong here
Remote Access communities are designed for client-to-site connections, not site-to-site branch office connectivity. They do not provide the same topology controls and are not intended for routing traffic between branch gateways. Using this community type would not meet the requirement and could introduce unnecessary complexity.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.