Courseiva
Identity Awareness →mediumMultiple Choice

156-215.81.20 Identity Awareness Practice Question

An administrator configures Identity Awareness using Active Directory Query to authenticate domain users. After deployment, users report intermittent authentication failures, and logs show that the Security Gateway fails to query the Domain Controllers due to insufficient privileges. Which account permission must be granted to resolve this issue without granting Domain Administrator rights?

⚠ Common exam trap

Candidates often recommend full Domain Administrator rights to fix permission issues, ignoring security best practices and the specific requirement for least-privilege delegation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Read permissions on user objects and membership in the Event Log Readers security group.

Identity Awareness Active Directory Query requires specific read permissions on the Active Directory container objects and membership in the Event Log Readers group to parse security event logs successfully. Granting full domain admin privileges violates security best practices, making targeted permission delegation essential for enterprise compliance and least-privilege enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Membership in the Domain Admins group and full control over the root domain partition.

    Why it's wrong here

    Domain Administrator rights provide excessive privileges that violate the principle of least privilege. While it resolves authentication queries, it unnecessarily exposes the entire Active Directory infrastructure to potential security compromises if the gateway is breached.

  • ✗

    Membership in the Enterprise Admins group and Schema Admins group.

    Why it's wrong here

    Enterprise and Schema Administrator privileges are meant strictly for forest-wide schema and configuration management. Using them for standard Identity Awareness queries introduces severe security risks and is completely unnecessary for normal operations.

  • ✓

    Read permissions on user objects and membership in the Event Log Readers security group.

    Why this is correct

    Event Log Readers group membership allows the Identity Awareness daemon to query security logs effectively. Combining this with standard read permissions on user and computer objects fulfills all functional requirements while strictly maintaining least-privilege security standards.

  • ✗

    Full administrative control over the Built-in Administrators local group on the gateway.

    Why it's wrong here

    Local administrator privileges on the Security Gateway govern appliance management rather than remote Active Directory queries. Modifying local gateway groups does not grant the necessary permissions required to read remote domain controller event logs.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.