Courseiva
Identity Awareness →easyMultiple Choice

156-215.81.20 Identity Awareness Practice Question

A company wants users on managed Windows endpoints to be identified by Identity Awareness without requiring them to open a browser or wait for an AD event log poll. The endpoints are domain-joined and already managed by the organization. Which acquisition method meets this requirement most directly?

⚠ Common exam trap

The trap here is treating AD Query as instant, when its polling behavior means it cannot guarantee immediate identification after logon.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity Agent installed on each managed endpoint

An endpoint-resident Identity Agent authenticates the logged-in user to the gateway automatically, providing immediate identification with no browser prompt and no dependency on AD event polling. For centrally managed, domain-joined Windows endpoints, this is the most direct way to achieve seamless, prompt-free identity acquisition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Captive Portal with single sign-on enabled

    Why it's wrong here

    Captive Portal identification generally requires the user to interact with a browser redirect to authenticate, which the scenario explicitly wants to avoid. Even with SSO features, the portal flow is browser-centric and can interrupt the user experience. It is better suited to guests or non-domain devices, not to managed domain-joined endpoints where silent identification is desired.

  • ✓

    Identity Agent installed on each managed endpoint

    Why this is correct

    The Identity Agent runs as a client on the endpoint and authenticates the logged-in user to the Security Gateway automatically, with no browser interaction. It reports identity as soon as the user session starts rather than waiting for an AD polling cycle. For domain-joined, centrally managed Windows machines, this provides immediate and reliable identification, satisfying the no-browser, no-poll requirement.

  • ✗

    AD Query configured against the domain controllers

    Why it's wrong here

    AD Query works by reading login events from Active Directory, which introduces a polling delay before the gateway learns who logged in. It requires no endpoint software, but it cannot deliver the immediate identification the scenario asks for and it depends on domain controller event visibility. It is a valid method, but it does not meet the stated no-wait requirement as directly as an endpoint agent.

  • ✗

    RADIUS Accounting configured on the gateway

    Why it's wrong here

    RADIUS Accounting can pass identity information as users authenticate to network devices, but it depends on an external RADIUS infrastructure and is not an endpoint-resident method. It does not silently identify the local Windows logon session on each managed machine, and it adds a dependency the scenario did not mention. It is not the most direct fit for immediate per-endpoint identification.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.