156-215.81.20 User and Access Management Practice Question
A Check Point administrator is configuring user authentication for a Remote Access VPN. The administrator wants to use certificates for authentication but also requires a second factor. The administrator decides to use SecurID tokens as the second factor. Which authentication method should be configured in the user object to achieve this?
⚠ Common exam trap
The trap here is selecting 'SecurID' alone or 'Certificate' alone, missing the requirement for multi-factor authentication combining both.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate + SecurID
To use certificates and SecurID tokens together, the user object must be configured with the 'Certificate + SecurID' authentication method. This method enforces both factors: the user must present a valid certificate and a correct SecurID token code. Other methods either use only one factor or substitute the certificate with a password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User Name and Password + SecurID
Why it's wrong here
This method combines a static username and password with a SecurID token, providing two factors. However, it does not use certificates. The scenario specifies certificates as the first factor, so this method does not meet the requirement even though it provides multi-factor authentication.
- ✗
SecurID
Why it's wrong here
Configuring the user object with SecurID as the authentication method would require the user to provide only the SecurID token code. It does not combine certificate authentication with SecurID. This method alone does not meet the requirement of using certificates as the primary factor and SecurID as the second factor.
- ✓
Certificate + SecurID
Why this is correct
The authentication method 'Certificate + SecurID' is a multi-factor authentication option in Check Point that requires both a valid client certificate and a SecurID token code. This precisely matches the administrator's requirement to use certificates as the primary factor and SecurID as the second factor for Remote Access VPN authentication.
- ✗
Certificate
Why it's wrong here
Setting the authentication method to Certificate would only require a certificate for authentication. It does not include a second factor such as SecurID. While certificates provide strong authentication, the scenario explicitly requires a second factor, so this method alone is insufficient.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.