156-215.81.20 User and Access Management Practice Question
An administrator is creating a new user account in SmartConsole. The administrator wants the user to be able to authenticate to the Check Point Mobile Access portal using a username and password stored locally on the Management Server. Which authentication method should be selected for this user?
⚠ Common exam trap
Watch out — candidates often confuse external authentication methods with local password storage, assuming any method can store passwords locally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check Point Password
For a user to authenticate with a username and password stored locally on the Management Server, the Check Point Password authentication method must be selected. LDAP, RADIUS, and SecurID all rely on external servers for credential verification, which contradicts the requirement for local storage. Check Point Password is the built-in method for local authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LDAP
Why it's wrong here
LDAP authentication delegates credential verification to an external LDAP directory. Since the requirement is to store the password locally on the Management Server, LDAP is not appropriate. Using LDAP would require the user to exist in the external directory and would not use a locally stored password.
- ✗
RADIUS
Why it's wrong here
RADIUS authentication forwards credentials to a RADIUS server. This is an external method and does not store passwords locally on the Management Server. The scenario specifically asks for local password storage, so RADIUS would not meet the requirement and would introduce dependency on an external server.
- ✓
Check Point Password
Why this is correct
The Check Point Password method stores the user's password locally on the Management Server. This is the correct choice when local authentication is desired without relying on external directories. It allows the user to authenticate to services like Mobile Access using credentials managed directly in SmartConsole.
- ✗
SecurID
Why it's wrong here
SecurID is a two-factor authentication method that uses RSA tokens. It requires an external RSA Authentication Manager and does not store passwords locally on the Management Server. This method is for token-based authentication, not for simple username/password stored locally, so it is incorrect here.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.