Courseiva
Identity Awareness →mediumMultiple Choice

156-215.81.20 Identity Awareness Practice Question

An administrator wants to ensure that mobile devices are correctly identified. Which method is most appropriate for mobile device identity identification in a Wi-Fi environment?

⚠ Common exam trap

Candidates often try to apply AD Query to mobile devices. Since mobile devices do not join Active Directory, they cannot trigger the necessary Windows security events for AD Query.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Captive Portal

Captive Portal or integration with an MDM (Mobile Device Management) system is most appropriate for mobile devices. Unlike Windows PCs that can join a domain and use AD Query, mobile devices are typically not domain-joined. Using Captive Portal ensures that regardless of the device type or OS, the user must authenticate, allowing the firewall to associate their mobile session with a known identity for consistent security policy application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AD Query

    Why it's wrong here

    Mobile devices rarely support the Windows-specific authentication protocols that AD Query relies on. They do not generate the same type of security event logs on a domain controller, making AD Query ineffective for identifying these devices reliably within a standard corporate Wi-Fi network environment.

  • ✓

    Captive Portal

    Why this is correct

    Captive Portal is a device-agnostic method that works at the application layer. It is the most reliable way to enforce identity on mobile devices, as it forces the user to provide credentials through their web browser, ensuring that the identity is captured regardless of the specific device's operating system.

  • ✗

    Identity Agent

    Why it's wrong here

    Identity Agents are designed for managed desktop operating systems like Windows, macOS, or Linux. They are generally not available for mobile platforms like iOS or Android, making this an unsuitable choice for mobile device identity identification within the corporate network infrastructure environment.

  • ✗

    Browser-based transparent authentication

    Why it's wrong here

    Browser-based transparent authentication (like NTLM or Kerberos SSO) is difficult to implement across diverse mobile devices. It requires specific client-side support that is often inconsistent or unsupported on mobile platforms, making it significantly less reliable than a standard Captive Portal for ensuring consistent user identification across the organization.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.