156-215.81.20 Identity Awareness Practice Question
An administrator wants to ensure that mobile devices are correctly identified. Which method is most appropriate for mobile device identity identification in a Wi-Fi environment?
⚠ Common exam trap
Candidates often try to apply AD Query to mobile devices. Since mobile devices do not join Active Directory, they cannot trigger the necessary Windows security events for AD Query.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Captive Portal
Captive Portal or integration with an MDM (Mobile Device Management) system is most appropriate for mobile devices. Unlike Windows PCs that can join a domain and use AD Query, mobile devices are typically not domain-joined. Using Captive Portal ensures that regardless of the device type or OS, the user must authenticate, allowing the firewall to associate their mobile session with a known identity for consistent security policy application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AD Query
Why it's wrong here
Mobile devices rarely support the Windows-specific authentication protocols that AD Query relies on. They do not generate the same type of security event logs on a domain controller, making AD Query ineffective for identifying these devices reliably within a standard corporate Wi-Fi network environment.
- ✓
Captive Portal
Why this is correct
Captive Portal is a device-agnostic method that works at the application layer. It is the most reliable way to enforce identity on mobile devices, as it forces the user to provide credentials through their web browser, ensuring that the identity is captured regardless of the specific device's operating system.
- ✗
Identity Agent
Why it's wrong here
Identity Agents are designed for managed desktop operating systems like Windows, macOS, or Linux. They are generally not available for mobile platforms like iOS or Android, making this an unsuitable choice for mobile device identity identification within the corporate network infrastructure environment.
- ✗
Browser-based transparent authentication
Why it's wrong here
Browser-based transparent authentication (like NTLM or Kerberos SSO) is difficult to implement across diverse mobile devices. It requires specific client-side support that is often inconsistent or unsupported on mobile platforms, making it significantly less reliable than a standard Captive Portal for ensuring consistent user identification across the organization.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.