156-215.81.20 Identity Awareness Practice Question
An administrator configures Identity Awareness using Active Directory Query to authenticate domain users. After deployment, users report intermittent authentication failures, and logs show that the Security Gateway fails to query the Domain Controllers due to insufficient privileges. Which account permission must be granted to resolve this issue without granting Domain Administrator rights?
⚠ Common exam trap
Candidates often recommend full Domain Administrator rights to fix permission issues, ignoring security best practices and the specific requirement for least-privilege delegation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read permissions on user objects and membership in the Event Log Readers security group.
Identity Awareness Active Directory Query requires specific read permissions on the Active Directory container objects and membership in the Event Log Readers group to parse security event logs successfully. Granting full domain admin privileges violates security best practices, making targeted permission delegation essential for enterprise compliance and least-privilege enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Membership in the Domain Admins group and full control over the root domain partition.
Why it's wrong here
Domain Administrator rights provide excessive privileges that violate the principle of least privilege. While it resolves authentication queries, it unnecessarily exposes the entire Active Directory infrastructure to potential security compromises if the gateway is breached.
- ✗
Membership in the Enterprise Admins group and Schema Admins group.
Why it's wrong here
Enterprise and Schema Administrator privileges are meant strictly for forest-wide schema and configuration management. Using them for standard Identity Awareness queries introduces severe security risks and is completely unnecessary for normal operations.
- ✓
Read permissions on user objects and membership in the Event Log Readers security group.
Why this is correct
Event Log Readers group membership allows the Identity Awareness daemon to query security logs effectively. Combining this with standard read permissions on user and computer objects fulfills all functional requirements while strictly maintaining least-privilege security standards.
- ✗
Full administrative control over the Built-in Administrators local group on the gateway.
Why it's wrong here
Local administrator privileges on the Security Gateway govern appliance management rather than remote Active Directory queries. Modifying local gateway groups does not grant the necessary permissions required to read remote domain controller event logs.
Visual reference
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.