Courseiva
User and Access Management →mediumMultiple Choice

156-215.81.20 User and Access Management Practice Question

An administrator needs to restrict a junior admin's access to only managing security policies within a specific Management Server domain. Which feature should be configured to implement this granular control?

⚠ Common exam trap

Candidates frequently confuse 'Permission Profile' with 'Access Role'. While both sound similar, they often fail to realize the profile is specifically for administrative granular control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Custom Permission Profile

Permission Profiles define the specific tasks and scope an administrator can perform within SmartConsole. By creating a custom profile and assigning it to the administrator, you ensure compliance with the principle of least privilege. This is critical in large-scale deployments where duties must be segregated to prevent unauthorized configuration changes or accidental policy deletions across different administrative domains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multi-Domain Server (MDS) licensing configuration

    Why it's wrong here

    Licensing controls the features available on the gateway or management server but does not provide granular administrative authorization. Administrative access is managed through Permission Profiles, not the license keys installed on the appliance, which focus on feature activation rather than internal user role definitions.

  • ✗

    Global Policy assignment in the MDS container

    Why it's wrong here

    Global Policies allow for consistency across domains but do not dictate which individual administrators can modify them. Managing the specific permissions for an administrator requires an association between the user object and a defined Permission Profile within the relevant domain or global context.

  • ✓

    Custom Permission Profile

    Why this is correct

    Permission Profiles are the primary mechanism for defining administrative roles in Check Point. By selecting specific granular rights within the profile, an administrator can be restricted to policy management tasks while being prevented from modifying network objects, software updates, or user accounts, ensuring highly targeted access control.

  • ✗

    Identity Awareness user groups

    Why it's wrong here

    Identity Awareness groups are used to control end-user access to network resources based on authentication against external directories like Active Directory. These groups do not manage administrative access to the Management Server itself, which requires specific administrator accounts linked to internal management-plane authorization policies.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.