156-215.81.20 User and Access Management Practice Question
A security administrator is configuring a Check Point R81 Management Server to authenticate administrators via RADIUS. The RADIUS server is already configured with the necessary user accounts. After creating a RADIUS server object and enabling RADIUS authentication for administrators, the administrator tests login with a RADIUS user but fails. The administrator confirms the RADIUS server is reachable and the shared secret matches. What is the most likely cause of the failure?
⚠ Common exam trap
The trap here is assuming that successful RADIUS authentication alone grants administrative access, overlooking the need for a corresponding administrator object with a Permission Profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RADIUS user must be added as a Check Point administrator with a matching username and a Permission Profile.
Check Point separates authentication from authorization. Even if RADIUS authenticates the user, the Management Server must have a local administrator object with the same username and an assigned Permission Profile to grant access. Without this object, the login fails because the system cannot determine the user's permissions. This is a common pitfall when integrating external authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The RADIUS server's shared secret must be configured with a minimum length of 16 characters.
Why it's wrong here
There is no such minimum length requirement for RADIUS shared secrets in Check Point. The shared secret must match on both sides, but length is not a cause of failure here. The actual issue is the missing administrator object mapping. This option invents a non-existent constraint.
- ✗
The administrator must enable 'LDAP' authentication on the Management Server in addition to RADIUS.
Why it's wrong here
Enabling LDAP is unnecessary and irrelevant when using RADIUS. Check Point supports multiple authentication methods independently; mixing them is not required. The failure is due to missing administrator object, not the absence of LDAP. This distractor confuses authentication protocols.
- ✗
The RADIUS server object must be configured with the 'Use for administrator authentication' option and the user must be added to a RADIUS group.
Why it's wrong here
While the RADIUS server object must be enabled for administrator authentication, simply adding the user to a RADIUS group does not grant Check Point administrative access. The Management Server still requires a corresponding administrator object for authorization. This option misses the critical step of creating the administrator account.
- ✓
The RADIUS user must be added as a Check Point administrator with a matching username and a Permission Profile.
Why this is correct
Check Point requires that each RADIUS-authenticated administrator have a corresponding administrator object with the same username and an assigned Permission Profile. Without this, authentication succeeds at RADIUS but authorization fails because the Management Server cannot map the user to a profile. This is the most common oversight when configuring external authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.