156-315.81.20 Gateway Deployment and Upgrades Practice Question
An administrator is deploying a new R81.20 Security Gateway using the Gaia First Time Configuration Wizard. The organization requires the gateway to obtain its IP address dynamically from the corporate DHCP server, but the administrator also needs to ensure the gateway can be reached at a predictable address for management. Which configuration should the administrator select during the wizard?
⚠ Common exam trap
The trap here is assuming that DHCP alone provides a predictable address, or that DNS dynamic updates are sufficient, when in fact only a DHCP reservation guarantees a consistent IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use DHCP and configure a DHCP reservation on the DHCP server for the gateway's MAC address.
The requirement is twofold: obtain an IP dynamically via DHCP and ensure the gateway remains reachable at a predictable address. A DHCP reservation on the server side achieves both by binding a specific IP to the gateway's MAC address, so the gateway still uses DHCP but always receives the same address. This is the standard method for combining dynamic configuration with stable management access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a static IP address manually on the management interface.
Why it's wrong here
A static IP address would indeed provide a predictable management address, but it contradicts the explicit requirement to obtain the IP dynamically from DHCP. The scenario demands DHCP while still ensuring reachability, so manual static configuration fails to meet the stated need. Static addressing is appropriate when DHCP is unavailable or when fixed addressing is mandated, but here it would violate the dynamic acquisition requirement.
- ✗
Configure a secondary IP address on the management interface using an alias.
Why it's wrong here
Adding a secondary IP alias does not address the primary requirement of obtaining an IP via DHCP. The gateway would still need a primary address, and the alias would be manually configured, which is not dynamic. This approach complicates management and does not ensure that the DHCP-obtained address remains predictable, so it fails to meet the scenario's needs.
- ✗
Use DHCP and rely on DNS dynamic updates to resolve the gateway's hostname.
Why it's wrong here
Dynamic DNS updates can help resolve the gateway's hostname to its current IP, but the IP address itself may change upon lease renewal, making management reachability unpredictable. The requirement is for a predictable address, not just a resolvable name. Relying solely on DNS dynamic updates does not guarantee a fixed IP, so this option does not fully satisfy the scenario.
- ✓
Use DHCP and configure a DHCP reservation on the DHCP server for the gateway's MAC address.
Why this is correct
Using DHCP satisfies the dynamic acquisition requirement, while a DHCP reservation tied to the gateway's MAC address guarantees that the gateway consistently receives the same IP address. This provides predictable reachability for management without manually configuring a static address on the gateway itself. It aligns perfectly with both the dynamic IP requirement and the need for a stable management address.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.