Be able to configure and troubleshoot AD Query and other agentless identity sources in SmartConsole, and select the right acquisition method for multi-domain environments. The most important thing: verify gateway-to-domain-controller connectivity and correct domain/credential settings before assuming policy problems.
Start practicing
Identity Awareness — choose a session length
Free · No account required
Domain overview
Identity Awareness on the Check Point Certified Security Expert exam covers how Security Gateways learn user identities and enforce identity-based rules. Questions are scenario-based: diagnosing AD Query failures, choosing acquisition methods for multi-domain environments, and configuring identity sources correctly in SmartConsole. Expect troubleshooting and configuration detail rather than pure theory.
Exam objectives
AD Query identity source configuration in SmartConsole, including domain, credentials, and gateway association
Identity Acquisition methods: AD Query, Identity Agents, Terminal Servers, and Captive Portal without client agents
Multi-domain Active Directory environments and efficient identity retrieval across trusted domains
Troubleshooting identity resolution failures for branch subnets, LDAP connectivity, and gateway-to-DC reachability
Assuming AD Query works across subnets without verifying the gateway can reach the domain controller and that the branch subnet is included in the query scope.
Confusing agentless methods (AD Query, Captive Portal) with agent-based Identity Agent deployments when the question forbids client-side installation.
Mixing up which parameters belong to the AD Query identity source versus gateway object settings, causing misconfigured domain or credentials.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise environment utilizes Identity Awareness with both AD Query and Browser-Based Authentication. Security administrators notice that contractor devices, which are not joined to the Active Directory domain, fail to acquire identity roles and are blocked by internal firewall rules. Which TWO methods can be implemented to correctly identify and authenticate these non-domain-joined contractor machines? (Choose TWO)
2Which core software blade must be enabled on a Check Point Security Gateway to allow the creation of access control rules based on Active Directory user groups and computer objects?
3An administrator is troubleshooting an Identity Awareness deployment where AD Query fails to resolve user identities for workstations located in a newly added branch office subnet. The Security Gateway can successfully ping the Domain Controllers in the branch office. What is the most likely cause of this communication failure?
4An administrator configures Identity Awareness in a Check Point environment using Active Directory Query as the primary identity source. Users suddenly report that access policies based on user groups are randomly failing. What is the most likely root cause of this behavior?
5Which TWO authentication methods are natively supported by Check Point Identity Awareness for acquiring user identities without requiring a client-side agent installation? (Choose TWO)
6Which THREE parameters must be correctly configured when setting up an Active Directory Query identity source in SmartConsole? (Choose THREE)
7An administrator notices that users connecting through a Citrix XenApp published application server are all appearing as a single user in Identity Awareness access logs. What is the appropriate solution to resolve this limitation?
8Refer to the exhibit. An administrator runs a CLI command to test policy evaluation for a specific client IP address. What does the output indicate about the gateway's evaluation process?
9Refer to the exhibit. An administrator is trying to refresh group membership for a user manually using the CLI. What is the most likely cause of this error?
10Which Identity Awareness source is best suited for identifying users connecting from non-Windows devices like mobile phones or tablets?
11Refer to the exhibit. Rule 5 allows the group 'Admins'. Why is the user 'admin' being blocked?
12When using the Identity Agent, what is the 'Shared User' feature used for?
13An administrator needs to implement Identity Awareness in a large environment with multiple Active Directory domains. Which method ensures the most efficient identity retrieval without requiring client-side agent installations on every workstation?
14When utilizing Identity Awareness, what is the primary purpose of the 'Identity Logging' feature in the context of compliance and auditing?
15An administrator has deployed Identity Awareness on a Security Gateway in AD Query mode. Users authenticate to the domain and their identities are learned successfully. However, a security policy rule that should permit access to an internal web server for the group 'Sales' is not matching. The administrator verifies that user 'jsmith' is a member of 'Sales' in Active Directory. The gateway's PDP shows the user identity, but the group is missing. What is the most likely cause?
16An administrator is deploying Identity Awareness on a Security Gateway and wants to ensure that user identities are shared with other gateways in the same domain. The administrator configures the gateway as a PDP and enables Identity Sharing. Which statement describes the primary benefit of this configuration?
17A security administrator is troubleshooting an Identity Awareness issue where users are not being identified on a Security Gateway. The gateway is configured to use AD Query. The administrator runs the command 'pdp monitor all' and sees that no users are listed. Which of the following is the most likely cause?
18A Security Gateway is configured with Identity Awareness using AD Query, and users authenticate to the domain normally. An administrator notices that identities for users who log on to workstations on a remote subnet are not appearing in the Identity Awareness database, while local subnet users are identified correctly. The domain controllers are reachable and audit logging is enabled. Which configuration item should the administrator verify first?
19A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway using the Identity Agents method. The organization wants to avoid installing additional client software on user workstations. Which Check Point component must be deployed to collect identities from the Active Directory domain controllers without requiring a full Identity Agent on each endpoint?
20A company wants users on managed Windows laptops to be identified by the Security Gateway without deploying any additional endpoint software and without prompting for credentials. Users already authenticate to the Active Directory domain at logon. Which Identity Awareness component is required on the Security Gateway to achieve this?
21An administrator is troubleshooting an Identity Awareness deployment where users authenticated through a Captive Portal are shown as unidentified on a different Security Gateway in the same distributed environment. The portal gateway correctly identifies the users, but the second gateway does not. Which action should the administrator take to allow the identity information to reach the second gateway?
22An administrator is troubleshooting Identity Awareness on a Security Gateway. Users authenticated previously, but now the gateway shows them as unidentified and all traffic falls to the default rule. The administrator confirms the gateway can reach the domain controllers and that the Identity Awareness blade is enabled. Which action should the administrator take first to verify whether the gateway is receiving identity information from the PDP?
23An administrator is implementing Identity Awareness using AD Query on a Security Gateway. Before identities can be learned from Active Directory, which two actions must be performed? (Choose two.)
24A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway. The environment uses a Windows Server 2019 domain controller, and the administrator wants the gateway to learn user identities by querying Windows Security Event Logs on the domain controller. The administrator has already configured the Identity Awareness blade and enabled AD Query in SmartConsole. Which additional configuration is required on the domain controller for AD Query to function?
25An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Captive Portal method. The organization wants to ensure that users who authenticate via the portal are correctly identified and that their identities are used in security policies. Which two actions are necessary to enable this? (Choose two.)
26A company wants to enforce identity-based rules for remote users who connect through a VPN. The administrator needs the Security Gateway to learn the user identity during the VPN authentication process without deploying additional agents. Which Identity Awareness feature should the administrator use?
27An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Terminal Server Agent. The environment has multiple users logging into a Citrix terminal server. The administrator wants to ensure that each user's identity is correctly associated with their individual session, not just the terminal server's IP address. Which statement describes how the Terminal Server Agent accomplishes this?
28An administrator has configured Identity Awareness with AD Query. Users are identified correctly during the day, but every morning many users appear unidentified until they generate new domain logon events. The administrator wants to reduce this morning gap without switching acquisition methods. Which configuration should the administrator adjust?
29A Check Point Security Gateway uses Identity Awareness with AD Query. An administrator notices that user identities are not being recognized in firewall rules that reference Active Directory groups. The gateway can identify individual users, but group-based rules do not match. What is the most likely cause?
30A network administrator is configuring Identity Awareness on a Security Gateway using AD Query. The administrator wants to ensure that user identities are correctly associated with IP addresses and that the gateway can resolve user group memberships for policy enforcement. Which component must be installed and configured on the Security Gateway to enable AD Query?
31An administrator is configuring Identity Awareness on a Check Point Security Gateway. The organization wants to identify users based on their login to the Windows domain without installing any software on user computers. Which Identity Awareness method should be used?
32A security administrator is troubleshooting an Identity Awareness deployment that uses Identity Agents. Users report that they can access resources based on their identity, but sometimes they are prompted to authenticate again even though they are already logged in. The administrator checks the gateway and sees that the Identity Agent is running on the users' computers. What is a possible cause for the re-authentication prompts?
Be able to configure and troubleshoot AD Query and other agentless identity sources in SmartConsole, and select the right acquisition method for multi-domain environments. The most important thing: verify gateway-to-domain-controller connectivity and correct domain/credential settings before assuming policy problems.
The Courseiva 156-315.81.20 question bank contains 32 questions in the Identity Awareness domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Identity Awareness domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included