156-315.81.20 Advanced VPN Design Practice Question
An administrator is configuring a VPN tunnel between a Check Point Security Gateway and a third-party gateway. The third-party gateway uses a certificate signed by an internal CA. The administrator wants to use certificate-based authentication. Which step is required on the Check Point gateway to trust the third-party certificate?
⚠ Common exam trap
Many candidates confuse certificate trust with other trust mechanisms like IP-based trust or pre-shared secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Import the third-party root CA certificate into the Check Point gateway's trusted CA list.
Certificate-based VPN authentication requires that each peer trusts the CA that signed the other's certificate. On the Check Point gateway, you must import the third-party root CA certificate into the trusted CA list. This allows the gateway to validate the certificate presented by the third-party during IKE. Without this trust, the negotiation fails. The process is done via SmartConsole or the command line, and the CA certificate must be in PEM or DER format.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the VPN community to use 'Pre-Shared Secret' and manually enter the third-party's certificate fingerprint.
Why it's wrong here
Using a pre-shared secret is an alternative authentication method, not compatible with certificate-based authentication. Manually entering a fingerprint is not a standard Check Point procedure for trusting a CA. This option mixes authentication methods and would not achieve the goal of using certificates.
- ✓
Import the third-party root CA certificate into the Check Point gateway's trusted CA list.
Why this is correct
For certificate-based authentication, the Check Point gateway must trust the CA that signed the third-party's certificate. Importing the root CA certificate into the trusted CA list allows the gateway to validate the third-party certificate during IKE negotiation. This is a standard requirement for PKI-based VPNs.
- ✗
Add the third-party gateway's IP address to the 'Trusted Clients' list in SmartConsole.
Why it's wrong here
The 'Trusted Clients' list is used for Secure Internal Communication (SIC) between Check Point components, not for third-party VPN peers. Adding an IP address there does not enable certificate trust. Certificate validation relies on CA trust, not IP-based trust lists.
- ✗
Enable 'Certificate Authority' on the Check Point gateway and issue a certificate to the third-party gateway.
Why it's wrong here
The third-party gateway already has a certificate from its internal CA. Enabling CA on the Check Point gateway would make it a CA, but it cannot issue certificates for the third-party's internal CA. The Check Point gateway needs to trust the third-party's CA, not become a CA itself.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.