Courseiva
Identity Awareness →mediumMultiple Choice

156-215.81.20 Identity Awareness Practice Question

A security administrator must let contractors on personally owned, non-domain laptops access internal resources. The contractors cannot install endpoint software, and the organization wants them to authenticate through a web page before access is granted. Which Identity Awareness acquisition method fits these constraints?

⚠ Common exam trap

The trap here is assuming domain-based methods can serve non-domain contractors, when those methods require domain authentication events or endpoint agents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Captive Portal configured on the Security Gateway

Captive Portal is designed for users who cannot run endpoint agents and are not in the domain. It presents a browser-based login before granting access, satisfying both the no-install and web-authentication requirements. The gateway then maps the authenticated user to the source address for identity-based enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Captive Portal configured on the Security Gateway

    Why this is correct

    Captive Portal redirects unauthenticated users to a web page where they can log in before access is permitted. It requires no endpoint software and works for non-domain devices, matching both constraints. Contractors authenticate through the browser, and the gateway creates an identity session tied to their source address, enabling identity-based policy for their traffic.

  • ✗

    AD Query against the corporate domain controllers

    Why it's wrong here

    AD Query identifies users by reading domain logon events, which requires the user to authenticate to Active Directory. Contractors on personally owned, non-domain laptops do not generate domain logon events on the corporate DCs, so AD Query would never see them. This method cannot satisfy the requirement and leaves the contractors unidentified.

  • ✗

    Identity Agent installed by each contractor

    Why it's wrong here

    The Identity Agent requires installation on the endpoint, and the scenario states contractors cannot install endpoint software. Even though the agent would provide silent identification, the deployment constraint rules it out. It is therefore not a viable acquisition method here, regardless of its technical strengths in managed environments.

  • ✗

    RADIUS Accounting from a third-party network access server

    Why it's wrong here

    RADIUS Accounting can convey user identity from a network device, but it depends on an external NAS and RADIUS infrastructure that the scenario does not describe. It also does not present a web authentication page to the contractor as required. Without additional components, it does not meet the browser-authentication and no-install constraints.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.