156-215.81.20 Identity Awareness Practice Question
An administrator is troubleshooting an issue where users are identified as 'Unknown' despite having Identity Awareness enabled. What is the first logical step to investigate?
⚠ Common exam trap
Candidates often jump to checking the policy or user credentials first, ignoring the 'pdp monitor' command which provides an immediate, high-level overview of the Identity Awareness engine's current state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check 'pdp monitor' output.
The most effective first step is to check if the gateway is correctly receiving identity information from the sources. Using the command 'pdp monitor' allows the administrator to see the current status of all configured identity sources. If the source shows as 'Disconnected' or 'Failed', the problem lies in the connectivity or credentials used for the identity source, rather than a policy-level filtering issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restart the security gateway.
Why it's wrong here
Restarting the gateway is a disruptive action that should not be the first step in troubleshooting. It masks the root cause and does not provide diagnostic information. Systematic troubleshooting, such as checking logs and status commands, must be performed before resorting to drastic measures like a full system reboot.
- ✓
Check 'pdp monitor' output.
Why this is correct
The 'pdp monitor' command provides an immediate overview of the health of all identity sources. It reveals if the gateway is actively receiving data from AD Query or other sources. If a source is down, this command will explicitly indicate the status, guiding further targeted troubleshooting efforts effectively.
- ✗
Review the Access Control policy.
Why it's wrong here
While policy issues can cause access denials, they do not explain why users are identified as 'Unknown'. Identity identification is an infrastructure-level process that occurs before policy enforcement. If the gateway cannot map the user, the policy evaluation will default to 'Unknown', so identifying the source issue is priority.
- ✗
Reinstall the Identity Agent.
Why it's wrong here
Reinstalling the agent is an endpoint-centric approach that ignores the possibility of server-side or network-level configuration issues. If the entire user population is 'Unknown', the problem is likely at the gateway or source side, not on individual client endpoints, making reinstallation an inefficient and likely ineffective troubleshooting step.
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.