156-215.81.20 Identity Awareness Practice Question
A security administrator has configured Identity Awareness with AD Query on a Check Point R81.20 Security Gateway. Users report that they can access resources immediately after logging in, but after a password change, some users are still identified with their old group memberships for an extended period. What is the most likely cause of this behavior?
⚠ Common exam trap
The trap here is assuming that AD Query provides real-time updates, when in fact it relies on periodic queries and caching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AD Query cache has not expired, and the gateway is using cached group information.
The correct answer is that the AD Query cache has not expired, and the gateway is using cached group information. AD Query periodically queries Active Directory and caches the results to reduce load. When group memberships change, the gateway may not reflect the changes until the cache is refreshed, causing users to retain old group memberships for an extended period.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Identity Awareness blade is not configured to synchronize group memberships.
Why it's wrong here
Identity Awareness with AD Query automatically retrieves group memberships as part of its queries. There is no separate configuration to synchronize group memberships; it is inherent in the query process. The issue is more likely due to caching, not a missing configuration option.
- ✗
The user's session on the Security Gateway has not been refreshed, and the old session is still active.
Why it's wrong here
While session refresh can affect identity, the described behavior is about group memberships after a password change. If the session were stale, the user might be identified as unknown or with old identity, but the specific mention of group memberships points to cached group data from AD Query. Session refresh is not the primary cause here.
- ✗
The Security Gateway is not receiving real-time login events from the domain controllers.
Why it's wrong here
AD Query does not rely on real-time login events; it periodically queries Active Directory. The issue described is about stale group information after a password change, not about login events. While lack of real-time events could cause delays in identifying users, it would not specifically cause old group memberships to persist after a password change.
- ✓
The AD Query cache has not expired, and the gateway is using cached group information.
Why this is correct
AD Query periodically queries Active Directory for user and group information and caches the results. When a user's group membership changes, such as after a password change that triggers a group update, the gateway may continue to use the cached information until the cache expires or is refreshed. This can cause a delay in reflecting the new group memberships, leading to the observed behavior.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.