156-215.81.20 Identity Awareness Practice Question
A security administrator is configuring Identity Awareness with Terminal Server Agent on a Citrix server. Users report that after logging off and logging back in, they are still associated with their previous session, causing policy inconsistencies. What is the most likely cause of this issue?
⚠ Common exam trap
The trap here is overlooking that Terminal Server Agent needs explicit configuration to monitor logoff events, not just logon events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Terminal Server Agent is not configured to monitor session logoff events.
The Terminal Server Agent must be configured to monitor both logon and logoff events to accurately track user sessions. If logoff events are missed, the gateway retains the user's identity, causing policy inconsistencies when the user logs back in. Ensuring proper event monitoring resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Security Gateway's identity database is full and cannot accept new sessions.
Why it's wrong here
A full identity database would affect all users, not just those re-logging in. The issue described is specific to session logoff not being processed. The database capacity is typically large and not the cause of stale sessions.
- ✗
The user's credentials are cached by the Citrix server, causing automatic re-authentication with the old identity.
Why it's wrong here
Credential caching would cause automatic logon, but the issue is that the old identity persists after logoff. The Terminal Server Agent should detect the logoff and remove the identity. Caching is not the root cause; the agent's logoff monitoring is.
- ✓
The Terminal Server Agent is not configured to monitor session logoff events.
Why this is correct
The Terminal Server Agent must be configured to monitor both logon and logoff events. If logoff events are not monitored, the gateway will not remove the user's identity when they log off, leading to stale sessions. This causes the user to retain their previous identity upon re-login.
- ✗
The Terminal Server Agent requires a reboot after each user logoff to clear the session.
Why it's wrong here
Rebooting the terminal server after each logoff is impractical and not required. The Terminal Server Agent dynamically monitors sessions and should update identities in real time. The problem is likely a configuration issue with event monitoring, not a need for reboots.
Visual reference
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.