156-215.81.20 Identity Awareness Practice Question
A security administrator has deployed Identity Awareness with Terminal Server Agent on a Check Point R81.20 gateway. Users report that their identities are correctly identified when they log in, but after disconnecting and reconnecting to a different session on the same terminal server, they are still associated with the old session. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that because initial identification works, the service or license must be fine, overlooking that session change events require separate configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Terminal Server Agent is not configured to monitor session changes.
The Terminal Server Agent must be configured to monitor all session events, including logoff and reconnection, to keep the identity database current. If it only tracks initial logons, the gateway will not update the mapping when a user switches sessions, resulting in stale associations. Ensuring that session change monitoring is enabled resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The gateway's identity database is full and cannot accept new entries.
Why it's wrong here
A full identity database would prevent any new users from being identified, not just those changing sessions. The scenario indicates that users are identified initially, so the database is accepting entries. The problem is specific to session changes, which points to a configuration issue in the Terminal Server Agent rather than a capacity limit.
- ✓
The Terminal Server Agent is not configured to monitor session changes.
Why this is correct
The Terminal Server Agent must be configured to track session events, including logon, logoff, and session changes. If it only monitors initial logons and not reconnections or session switches, the gateway will retain the old session mapping. This leads to stale identity information when users move between sessions on the same terminal server.
- ✗
The gateway is not licensed for Identity Awareness with Terminal Server Agent.
Why it's wrong here
A licensing issue would typically prevent the feature from working entirely or generate explicit error messages. Since initial identification works, the license is valid and the feature is operational. The selective failure on session changes is unrelated to licensing and is more likely a configuration oversight in session tracking.
- ✗
The Terminal Server Agent service is not running on the terminal server.
Why it's wrong here
If the service were not running, no users would be identified at all. The scenario states that users are correctly identified on initial login, which means the service is running and communicating with the gateway. The issue arises only after session changes, so the service is active but not handling those events properly.
Visual reference
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.