Courseiva
Identity Awareness →hardMultiple Choice

156-215.81.20 Identity Awareness Practice Question

A security administrator manages a Check Point R81.20 environment with Identity Awareness using Active Directory Query. Users on domain-joined machines are identified correctly, but users who connect through a NAT device are consistently shown as unknown. What is the most likely cause?

⚠ Common exam trap

The trap here is blaming a global failure such as a license or account issue when the symptom is clearly limited to a specific network topology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The AD Query method cannot resolve identities when the source IP is translated by NAT.

Active Directory Query relies on matching the source IP of traffic to the IP recorded in AD security events. NAT rewrites the source IP, so the gateway sees a different address than the one in the AD logs, and the identity lookup fails. To support NATed users, the administrator must use a method that carries identity in the traffic itself, such as Identity Collector or RADIUS Accounting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The AD Query method cannot resolve identities when the source IP is translated by NAT.

    Why this is correct

    Active Directory Query learns identities by correlating AD security event logs with the source IP seen by the gateway. When a NAT device translates the source IP, the IP observed by the gateway no longer matches the IP recorded in the AD logs, so the correlation fails and the user remains unknown. This is a fundamental limitation of the passive AD Query method.

  • ✗

    The gateway is missing a license for Identity Awareness.

    Why it's wrong here

    A missing license would prevent Identity Awareness from functioning for all users, not just those behind NAT. Since domain-joined users without NAT are identified correctly, the license is clearly present and valid. The selective failure pattern points to a correlation issue rather than a licensing problem.

  • ✗

    The AD Query account password has expired.

    Why it's wrong here

    An expired service account password would cause the gateway to lose connectivity to the domain controller, resulting in no users being identified at all. The scenario shows that many users are identified successfully, so the account is working. The problem is isolated to NATed clients, which indicates an IP correlation mismatch rather than an authentication failure.

  • ✗

    The Security Gateway is not configured to read the correct AD security log.

    Why it's wrong here

    If the gateway were reading the wrong security log, no domain users would be identified, not just NATed ones. The fact that non-NAT users are resolved correctly proves the log reading is functioning. The issue is specifically that NAT changes the source IP, breaking the match between the gateway's observed IP and the AD log entry.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.