Courseiva

156-215.81.20 User and Access Management Practice Question

A Check Point administrator is configuring user authentication for a Remote Access VPN. The administrator wants to use certificates for authentication but also requires a second factor. The administrator decides to use SecurID tokens as the second factor. Which authentication method should be configured in the user object to achieve this?

⚠ Common exam trap

The trap here is selecting 'SecurID' alone or 'Certificate' alone, missing the requirement for multi-factor authentication combining both.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate + SecurID

To use certificates and SecurID tokens together, the user object must be configured with the 'Certificate + SecurID' authentication method. This method enforces both factors: the user must present a valid certificate and a correct SecurID token code. Other methods either use only one factor or substitute the certificate with a password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User Name and Password + SecurID

    Why it's wrong here

    This method combines a static username and password with a SecurID token, providing two factors. However, it does not use certificates. The scenario specifies certificates as the first factor, so this method does not meet the requirement even though it provides multi-factor authentication.

  • ✗

    SecurID

    Why it's wrong here

    Configuring the user object with SecurID as the authentication method would require the user to provide only the SecurID token code. It does not combine certificate authentication with SecurID. This method alone does not meet the requirement of using certificates as the primary factor and SecurID as the second factor.

  • ✓

    Certificate + SecurID

    Why this is correct

    The authentication method 'Certificate + SecurID' is a multi-factor authentication option in Check Point that requires both a valid client certificate and a SecurID token code. This precisely matches the administrator's requirement to use certificates as the primary factor and SecurID as the second factor for Remote Access VPN authentication.

  • ✗

    Certificate

    Why it's wrong here

    Setting the authentication method to Certificate would only require a certificate for authentication. It does not include a second factor such as SecurID. While certificates provide strong authentication, the scenario explicitly requires a second factor, so this method alone is insufficient.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.