Courseiva

156-215.81.20 User and Access Management Practice Question

An administrator is creating a new user account in SmartConsole. The administrator wants the user to be able to authenticate to the Check Point Mobile Access portal using a username and password stored locally on the Management Server. Which authentication method should be selected for this user?

⚠ Common exam trap

Watch out — candidates often confuse external authentication methods with local password storage, assuming any method can store passwords locally.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check Point Password

For a user to authenticate with a username and password stored locally on the Management Server, the Check Point Password authentication method must be selected. LDAP, RADIUS, and SecurID all rely on external servers for credential verification, which contradicts the requirement for local storage. Check Point Password is the built-in method for local authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LDAP

    Why it's wrong here

    LDAP authentication delegates credential verification to an external LDAP directory. Since the requirement is to store the password locally on the Management Server, LDAP is not appropriate. Using LDAP would require the user to exist in the external directory and would not use a locally stored password.

  • ✗

    RADIUS

    Why it's wrong here

    RADIUS authentication forwards credentials to a RADIUS server. This is an external method and does not store passwords locally on the Management Server. The scenario specifically asks for local password storage, so RADIUS would not meet the requirement and would introduce dependency on an external server.

  • ✓

    Check Point Password

    Why this is correct

    The Check Point Password method stores the user's password locally on the Management Server. This is the correct choice when local authentication is desired without relying on external directories. It allows the user to authenticate to services like Mobile Access using credentials managed directly in SmartConsole.

  • ✗

    SecurID

    Why it's wrong here

    SecurID is a two-factor authentication method that uses RSA tokens. It requires an external RSA Authentication Manager and does not store passwords locally on the Management Server. This method is for token-based authentication, not for simple username/password stored locally, so it is incorrect here.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.