Courseiva
Advanced VPN Design →easyMultiple Choice

156-315.81.20 Advanced VPN Design Practice Question

A security administrator is setting up a VPN tunnel between two Check Point Security Gateways. The administrator wants to ensure that only specific services are allowed through the tunnel, while all other traffic is blocked. Which Check Point feature should be used to enforce this?

⚠ Common exam trap

Candidates often confuse the encryption domain, which defines encrypted networks, with the security policy, which defines allowed services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Policy rules that match the VPN community and specify the allowed services.

To allow only specific services through a VPN tunnel, you must create Security Policy rules that match the VPN community as the source and destination, and specify the allowed services. The default rule should block all other traffic. This ensures that only the desired services are permitted. The encryption domain defines which traffic is encrypted, but the security policy defines what is allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security Policy rules that match the VPN community and specify the allowed services.

    Why this is correct

    Security Policy rules are used to control traffic, including VPN traffic. By creating rules that match the VPN community and specify allowed services, you can permit only those services and block the rest. This is the standard way to enforce granular access control within a VPN.

  • ✗

    VPN Community with 'Encryption Domain' set to the specific services.

    Why it's wrong here

    The encryption domain defines which networks are encrypted, not which services are allowed. Setting it to specific services is not possible; it deals with IP addresses and subnets. To restrict services, you need a security policy rule, not the encryption domain.

  • ✗

    VPN Community with 'Disable NAT inside the VPN Community' enabled.

    Why it's wrong here

    Disabling NAT inside the VPN community prevents address translation for VPN traffic, which can be useful for preserving original IPs. It does not restrict services. Service control is achieved through security policy rules, not NAT settings.

  • ✗

    VPN Community with 'Shared Secret' and 'Perfect Forward Secrecy' enabled.

    Why it's wrong here

    Shared Secret and Perfect Forward Secrecy are authentication and key exchange settings, not service restrictions. They enhance security but do not filter traffic based on services. Enabling them does not block or allow specific services; that is the role of the security policy.

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.