156-215.81.20 Identity Awareness Practice Question
A security administrator is deploying Identity Awareness using the Identity Collector in an environment with multiple domain controllers. The administrator wants to ensure that user identity information is collected from all domain controllers and that the load is distributed. Which configuration should be implemented?
⚠ Common exam trap
The trap here is assuming that a single Identity Collector can connect to multiple domain controllers with load balancing, when in fact multiple collectors are needed for redundancy and distribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy multiple Identity Collector instances, each connecting to a different domain controller, and configure them to share data with the Security Gateway.
To collect identities from multiple domain controllers and distribute load, deploy multiple Identity Collector instances, each assigned to a different domain controller. They all forward data to the Security Gateway, providing redundancy. This is the recommended approach for large environments with multiple domain controllers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Identity Awareness blade on each domain controller to push identities directly to the gateway.
Why it's wrong here
The Identity Awareness blade is a software component on Check Point Security Gateways, not on domain controllers. Domain controllers cannot run this blade. Identities are collected by the Identity Collector or queried by the gateway; domain controllers do not push identities directly.
- ✗
Use a single Identity Collector and configure it to query all domain controllers simultaneously via LDAP.
Why it's wrong here
The Identity Collector does not query domain controllers via LDAP; it uses a proprietary protocol to receive event logs. It cannot query multiple domain controllers simultaneously. A single collector can only connect to one domain controller at a time, so this approach would not provide redundancy or load distribution.
- ✓
Deploy multiple Identity Collector instances, each connecting to a different domain controller, and configure them to share data with the Security Gateway.
Why this is correct
The Identity Collector can be installed on multiple servers, each monitoring a different domain controller. They can all send identity information to the same Security Gateway. This provides redundancy and distributes the load, ensuring that if one collector fails, others continue to provide identities.
- ✗
Configure the Identity Collector to connect to each domain controller individually and enable load balancing.
Why it's wrong here
The Identity Collector does not support connecting to multiple domain controllers individually with built-in load balancing. It is designed to connect to a single domain controller or a list, but load balancing is not a native feature. Instead, multiple Identity Collector instances can be deployed for redundancy and load distribution.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.