156-215.81.20 Identity Awareness Practice Question
An administrator is configuring Identity Awareness on a Check Point R81.20 gateway using the Identity Collector. Users are authenticated via multiple Active Directory domains in a forest. The administrator notices that users from one domain are not being identified. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that a single service account with permissions in one domain automatically has rights in all domains of the forest, but permissions must be explicitly granted per domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Identity Collector service account does not have sufficient permissions to read the Event Log on domain controllers in that domain.
The Identity Collector relies on reading security event logs from domain controllers. When multiple domains exist, the service account must have read permissions on each domain controller. If permissions are missing for one domain, the collector cannot retrieve login events, leaving users unidentified. Ensuring the account has appropriate rights in every domain is essential for full coverage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Identity Collector does not support multiple domains in a single forest.
Why it's wrong here
The Identity Collector fully supports multiple domains in a forest, provided it is configured with the appropriate credentials and the domains are reachable. It can monitor multiple domain controllers across domains. Therefore, lack of support is not the cause; the issue lies in configuration or permissions for that specific domain.
- ✗
The gateway is not configured with a DNS server that can resolve the domain controllers in that domain.
Why it's wrong here
While DNS resolution is important for the Identity Collector to reach domain controllers, the Identity Collector configuration typically uses IP addresses or FQDNs. If DNS were the issue, it would affect all domains equally unless specific DNS forwarding is misconfigured. The more likely cause is permissions, as the collector would fail to read events even if it can reach the domain controllers.
- ✓
The Identity Collector service account does not have sufficient permissions to read the Event Log on domain controllers in that domain.
Why this is correct
The Identity Collector requires a service account with read access to the security event logs on all domain controllers it monitors. If the account lacks permissions on domain controllers in one domain, it cannot collect login events from that domain, resulting in unidentified users. This is a common configuration oversight when multiple domains are involved, as permissions must be granted in each domain.
- ✗
The users in that domain are not members of any groups that are used in Identity Awareness rules.
Why it's wrong here
Group membership affects policy enforcement, not identity collection. Even if users are not in relevant groups, they should still be identified by the collector if events are read. The problem described is that users are not identified at all, which points to a collection failure rather than a policy group mismatch.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.