Courseiva

156-215.81.20 User and Access Management Practice Question

A Check Point administrator is configuring a new SmartConsole administrator account for a security analyst. The analyst must be able to view all objects and rules but must not be able to modify any security policy or object. The administrator assigns the 'Read-Only All' Permission Profile. However, the analyst reports that they can still edit their own personal settings, such as changing their password. Is this expected behavior?

⚠ Common exam trap

The trap here is assuming that a read-only profile blocks every possible write action, including self-service password changes, when in fact personal settings remain editable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Yes, it is expected; the 'Read-Only All' profile permits users to modify their own personal settings, including password, while restricting changes to security policies and objects.

The 'Read-Only All' Permission Profile is intended to provide view-only access to all security objects and rules. It does not prevent an administrator from managing their own account, such as changing a password or adjusting personal preferences. Therefore, the analyst's ability to edit personal settings is expected and does not violate the read-only restriction on policy and objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Yes, it is expected; the 'Read-Only All' profile permits users to modify their own personal settings, including password, while restricting changes to security policies and objects.

    Why this is correct

    The 'Read-Only All' Permission Profile grants read access to all Security Management Server objects and rules but does not grant write access to those objects. However, it does allow administrators to manage their own personal settings, such as password and session preferences, because these are not considered part of the security policy or shared objects.

  • ✗

    No, the 'Read-Only All' profile should block all write operations, but a known bug in R81 allows password changes; the administrator should open a support ticket.

    Why it's wrong here

    There is no such bug; the behavior is by design. The 'Read-Only All' profile restricts modifications to security policies and objects, not to the administrator's own account settings. Opening a support ticket would be unnecessary and would not change the intended functionality.

  • ✗

    No, the 'Read-Only All' profile should prevent any changes, including personal settings; the administrator must apply an additional restriction.

    Why it's wrong here

    The 'Read-Only All' profile is designed to allow read-only access to all objects and rules, but it does not restrict a user from managing their own account settings. Personal settings like password changes are typically allowed for any authenticated user, so the analyst's ability to edit them is expected and does not indicate a misconfiguration.

  • ✗

    Yes, but only if the administrator also has the 'Super User' profile; otherwise, personal settings are locked.

    Why it's wrong here

    The ability to change personal settings is independent of other profiles. The 'Read-Only All' profile itself allows users to modify their own password and preferences. Having an additional 'Super User' profile is not required and would actually grant full write access, which contradicts the requirement.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.