156-215.81.20 User and Access Management Practice Question
A Check Point administrator needs to configure authentication for a group of external users who will access the network via a VPN. The users are stored in an Active Directory domain. The administrator wants to use the AD credentials for authentication and also wants to assign different permissions based on AD group membership. Which two actions must the administrator take to achieve this? (Choose two.)
⚠ Common exam trap
The trap here is thinking that manually creating a local user group or using RADIUS is sufficient, when the requirement specifically demands leveraging AD group membership for permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an LDAP account unit that points to the Active Directory domain.
To authenticate external users against Active Directory and assign permissions based on AD groups, the administrator must first create an LDAP account unit that defines the AD connection. Then, an LDAP group object must be created to map the AD group and assign the necessary permissions. These two steps enable both authentication and group-based authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define a new user group object and manually add each AD user to it.
Why it's wrong here
Manually adding each AD user to a local group is impractical and does not leverage AD group membership. The requirement is to assign permissions based on AD group membership, so the correct approach is to use an LDAP group object that references the AD group, not a static local group.
- ✓
Create an LDAP account unit that points to the Active Directory domain.
Why this is correct
An LDAP account unit is required to define the connection to the Active Directory domain. It specifies the server IP, port, and credentials for querying the directory. Without this account unit, the Security Management Server cannot authenticate users against AD or retrieve group memberships.
- ✗
Configure a RADIUS server for authentication and use its group attributes.
Why it's wrong here
RADIUS does not natively provide group membership information for authorization in Check Point. While RADIUS can authenticate, it does not integrate with AD groups for permission assignment. The scenario requires AD group-based permissions, which LDAP supports directly.
- ✓
Create an LDAP group object that references the AD group and assign permissions to that group.
Why this is correct
An LDAP group object in Check Point maps to an AD group. By creating such an object and assigning it permissions, the administrator ensures that users inherit permissions based on their AD group membership. This satisfies the need for group-based authorization without manual user management.
- ✗
Enable User Directory authentication in Global Properties and select Active Directory.
Why it's wrong here
Enabling User Directory authentication in Global Properties is not a valid configuration step for LDAP integration. The correct method is to create an LDAP account unit and objects. Global Properties do not contain a simple toggle for Active Directory authentication; it requires account unit configuration.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.