Courseiva
Identity Awareness →mediumMultiple Choice

156-215.81.20 Identity Awareness Practice Question

An administrator is deploying Identity Awareness on a Check Point R81.20 Security Gateway. Users authenticate to a captive portal hosted by the gateway itself, without any external directory service. Which Identity Awareness method is being used?

⚠ Common exam trap

The trap here is assuming that any portal-based login automatically implies a separate identity server, when Browser-Based Authentication actually runs entirely on the gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Browser-Based Authentication

Browser-Based Authentication is the only Identity Awareness method that operates entirely on the Security Gateway without any external directory or identity source. It presents a captive portal, validates credentials against the gateway's local user database, and then maps the source IP to the authenticated user for policy enforcement. All other methods depend on external infrastructure, which the scenario explicitly excludes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RADIUS Accounting

    Why it's wrong here

    RADIUS Accounting learns user identities by parsing accounting packets sent from a RADIUS server after authentication. This requires an external RADIUS infrastructure, which the scenario rules out. It also does not present a portal to users; it passively listens for accounting messages, so it cannot satisfy the requirement of users authenticating directly to the gateway.

  • ✗

    Identity Collector

    Why it's wrong here

    Identity Collector is a separate Windows service that receives identity events from sources such as AD, Cisco ISE, or RADIUS accounting. It still depends on an external identity source to feed it data. With no directory present, Identity Collector has nothing to collect from, making it unsuitable for this standalone captive portal scenario.

  • ✗

    Active Directory Query

    Why it's wrong here

    Active Directory Query requires the gateway to communicate with an AD domain controller to resolve user-to-IP mappings. The scenario explicitly states that no external directory service exists, so this method cannot function. It also does not natively present a login portal; it passively queries AD security event logs to learn identities, which is a fundamentally different acquisition mechanism.

  • ✓

    Browser-Based Authentication

    Why this is correct

    Browser-Based Authentication lets the Security Gateway present a web portal where users enter credentials directly, with no external directory required. The gateway maintains its own local user database, so this matches the scenario exactly. It is the only Identity Awareness acquisition method that relies solely on the gateway's internal authentication rather than an external source such as AD or RADIUS.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.