156-315.81.20 Gateway Deployment and Upgrades Practice Question
An administrator is deploying a new R81.20 Security Gateway and wants to reduce the attack surface by ensuring only required services are reachable on the management interface. After completing the First Time Configuration Wizard, which Gaia action best accomplishes this?
⚠ Common exam trap
Many exam-takers confuse security policy rules that filter transit traffic with Gaia access policies that govern administrative access to the gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the management interface access policy to allow only specific administrative hosts and protocols.
Gaia interface access policies let you define which source networks and protocols may reach an interface for management purposes. Applying a restrictive policy to the management interface ensures only authorized administrative hosts can use SSH, WebUI, or other services, while unrelated traffic is dropped. This is the correct way to minimize exposure on a newly deployed R81.20 gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the management interface to a non-standard port for all services.
Why it's wrong here
Moving services to non-standard ports is security through obscurity and does not actually restrict who can connect. It also complicates administration and support. The requirement is to limit reachable services and hosts, which port changes alone do not accomplish.
- ✗
Enable the default drop rule in the security policy for the management interface.
Why it's wrong here
The security policy governs traffic traversing the gateway, not administrative access to the gateway itself. A drop rule there would not restrict Gaia management services and could disrupt production traffic. It does not address the requirement of limiting reachable services on the management interface.
- ✗
Disable all blades except Firewall on the gateway object in SmartConsole.
Why it's wrong here
Disabling blades changes which security functions enforce traffic, not which administrative services listen on the management interface. It does not restrict SSH, WebUI, or other management access. This action would not achieve the stated attack surface reduction for management access.
- ✓
Configure the management interface access policy to allow only specific administrative hosts and protocols.
Why this is correct
Gaia allows an access policy per interface that restricts which hosts and services can reach it for management. Limiting the management interface to known administrative hosts and required protocols directly reduces the attack surface as described. This is the supported method for controlling management access on a new gateway.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.