156-315.81.20 Gateway Deployment and Upgrades Practice Question
Which TWO requirements must be met before a Security Gateway can be successfully provisioned using the Zero Touch Provisioning (ZTP) service?
⚠ Common exam trap
Candidates often forget the necessity of internet connectivity, assuming the ZTP process is strictly local or only requires management server access. The appliance must reach the Check Point Cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The appliance must have internet access to reach the Check Point Cloud.
Zero Touch Provisioning relies on the appliance being able to reach the Check Point Cloud to fetch its configuration. This requires the device to have a serial number registered in the Zero Touch portal and a valid path to the internet, usually via DHCP on the designated management or first interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The appliance must have internet access to reach the Check Point Cloud.
Why this is correct
Since ZTP configurations are stored in the Check Point Cloud portal, the appliance must be able to resolve DNS and communicate over HTTPS to download its specific settings. Without an internet connection, the device cannot retrieve the instructions needed to complete the automated setup and configuration process.
- ✗
The administrator must manually run the 'cpconfig' command on the CLI first.
Why it's wrong here
Manual intervention such as running 'cpconfig' contradicts the purpose of Zero Touch Provisioning. The goal of ZTP is to allow an unconfigured device to be plugged in and automatically receive its configuration without any local CLI interaction from an administrator or technician at the site.
- ✗
A console cable must be connected to the appliance during the boot sequence.
Why it's wrong here
Zero Touch Provisioning is designed to work without any physical console connection. The process is triggered automatically when the device boots and detects it has no configuration, prompting it to seek its settings from the cloud via its network interface rather than requiring manual console input.
- ✗
The Security Management Server must be in the same Layer 2 network segment.
Why it's wrong here
The Management Server does not need to be on the same Layer 2 segment; it only needs to be reachable via Layer 3 once the initial ZTP configuration is applied. ZTP focuses on the initial Gaia setup and SIC establishment, which can occur over any routed network path.
- ✓
The appliance's MAC address or Serial Number must be registered in the ZTP portal.
Why this is correct
The Check Point Cloud identifies which configuration belongs to which physical unit using the unique hardware Serial Number or MAC address. If the device is not registered in the administrator's ZTP portal account, the cloud service will not provide any configuration details to the gateway.
Visual reference
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.