156-215.81.20 · domain
Identity Awareness
Identity Awareness on Check Point R81 covers how gateways learn user, machine, and group identity and enforce it in Access Control and Threat Prevention rules. Expect exhibits of CLI output, RADIUS and AD Query error logs, and rule-order questions where an identity-based rule interacts with IP-based rules.
Focused practice
Practice Identity Awareness questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Identity Awareness
Diagnose identity resolution with pdp and Identity Awareness CLI output, then read Access Control rule order correctly. The single most important thing: identity-based rules must sit above broader IP-based rules, or the wrong rule matches and policy never evaluates the user.
Identity Sources: AD Query, Identity Agents, Captive Portal, RADIUS accounting, and Terminal Servers/Session-based identities
Using 'pdp' diagnostics and the Identity Awareness blade CLI to confirm which identity source resolved a user
Building Access Control rules with Access Roles, users, groups, and machines instead of plain IP objects
Configuring RADIUS authentication and accounting, including shared secret and accounting port settings
Watch out for
Common Identity Awareness exam traps
- ▸Placing an identity-based rule below an IP-based rule, so the IP rule matches first and identity is never evaluated
- ▸Assuming AD Query alone covers all users when locked workstations or roaming clients need an Identity Agent or Captive Portal
- ▸Ignoring rule order and implied cleanup rules, then blaming the identity source for a policy that never reaches the identity rule
Question index
All Identity Awareness questions (35)
Click any question to see the full explanation, or start a practice session above.
What is the primary function of the 'Identity Collector' in a distributed Identity Awareness environment?
Medium2A company wants users on managed Windows endpoints to be identified by Identity Awareness without requiring them to open a browser or wait for an AD event log poll. The endpoints are domain-joined and already managed by the organization. Which acquisition method meets this requirement most directly?
Easy3A security administrator is deploying Identity Awareness using the Identity Collector in an environment with multiple domain controllers. The administrator wants to ensure that user identity information is collected from all domain controllers and that the load is distributed. Which configuration should be implemented?
Hard4An administrator is troubleshooting an issue where users are identified as 'Unknown' despite having Identity Awareness enabled. What is the first logical step to investigate?
Hard5A security administrator must let contractors on personally owned, non-domain laptops access internal resources. The contractors cannot install endpoint software, and the organization wants them to authenticate through a web page before access is granted. Which Identity Awareness acquisition method fits these constraints?
Medium6A security administrator manages a Check Point R81.20 environment with a Security Gateway and a separate Identity Collector. Users authenticate through Microsoft Active Directory, and the administrator wants to minimize the number of AD queries sent from the gateway. Which configuration should the administrator use to achieve this?
Medium7Which of the following describes the function of the 'Identity Awareness Gateway' in a load-sharing cluster?
Medium8Which TWO settings are required when configuring the 'Active Directory Query' method in the Identity Awareness blade?
Medium9An administrator is configuring Identity Awareness on a Security Gateway and wants to enable users to authenticate via a web portal before accessing network resources. The administrator wants to minimize user disruption and avoid installing additional software. Which Identity Awareness method should be used?
Easy10An administrator is deploying Identity Awareness on a Check Point R81.20 Security Gateway. Users authenticate to a captive portal hosted by the gateway itself, without any external directory service. Which Identity Awareness method is being used?
Medium11Refer to the exhibit. An administrator reviews the Identity Awareness status of a user workstation using CLI commands on the Security Gateway. What does the 'Identity Source: Identity Agent' field specifically indicate about how this user's identity was acquired?
Medium12An administrator configures Identity Awareness with Active Directory Query on an R81.20 Security Gateway. Users are authenticated via Kerberos, and the gateway has been joined to the domain. However, after login, some users are not being identified. The administrator notices that the gateway's AD Query service account password has expired. What is the most likely cause of the identification failure?
Medium13An administrator configures Identity Awareness in a Check Point environment using Active Directory Query. Users report that access policies based on user groups fail intermittently for workstations after users lock their screens. Which underlying mechanism causes this authentication loss?
Medium14A security administrator has deployed Identity Awareness with Terminal Server Agent on a Check Point R81.20 gateway. Users report that their identities are correctly identified when they log in, but after disconnecting and reconnecting to a different session on the same terminal server, they are still associated with the old session. What is the most likely cause?
Hard15An administrator is configuring Identity Awareness on a Check Point R81.20 gateway using the Identity Collector. Users are authenticated via multiple Active Directory domains in a forest. The administrator notices that users from one domain are not being identified. What is the most likely cause?
Hard16An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway. The company uses a single Active Directory domain and wants to identify users without installing any software on client machines. Which Identity Awareness method should the administrator choose?
Medium17An administrator needs to implement Identity Awareness to control access based on user groups. Which authentication method should be configured to ensure seamless transparency for users already logged into a Windows domain without requiring manual credentials input?
Medium18An administrator configures Identity Awareness using Active Directory Query to authenticate domain users. After deployment, users report intermittent authentication failures, and logs show that the Security Gateway fails to query the Domain Controllers due to insufficient privileges. Which account permission must be granted to resolve this issue without granting Domain Administrator rights?
Medium19An administrator has configured Identity Awareness with Terminal Server Agent on a Terminal Server. Users report that after disconnecting from a Remote Desktop session and reconnecting, they are sometimes identified as the previous user. What is the most likely cause of this issue?
Hard20A security administrator manages a Check Point R81.20 environment with Identity Awareness using Active Directory Query. Users on domain-joined machines are identified correctly, but users who connect through a NAT device are consistently shown as unknown. What is the most likely cause?
Hard21An administrator is troubleshooting an Identity Awareness deployment where some users are intermittently shown as unidentified on the Security Gateway. The environment uses AD Query. Which TWO conditions would cause AD Query to fail to identify a logged-in user? (Choose two.)
Hard22What is the primary benefit of using 'Identity Sharing' between multiple Check Point Security Gateways?
Medium23A security administrator is using Identity Awareness with Identity Agents in 'Browser-Based' mode. Users report they are prompted for authentication twice. What is the most likely cause?
Hard24A security administrator has configured Identity Awareness with AD Query on a Check Point R81.20 Security Gateway. Users report that they can access resources immediately after logging in, but after a password change, some users are still identified with their old group memberships for an extended period. What is the most likely cause of this behavior?
Hard25Which of the following is a recommended best practice when using Identity Awareness for internal network security?
Medium26Which of the following is the primary purpose of the Identity Awareness 'Captive Portal' feature?
Easy27Refer to the exhibit. An administrator is configuring RADIUS authentication for Identity Awareness. What is the cause of this error log?
Hard28An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway using the Identity Collector. The administrator wants to ensure that the Identity Collector can retrieve user identity information from Active Directory. Which two components are required for the Identity Collector to function? (Choose two.)
Medium29Refer to the exhibit. An administrator is troubleshooting an issue where 'bob' is unable to access resources. Based on the CLI output, what is the most likely cause for the connectivity failure?
Medium30When configuring Access Control policies based on Identity Awareness roles, an administrator places an identity-based rule above a traditional IP-based rule. A user authenticated via Identity Awareness attempts to access a blocked server. The rule base evaluates the connection and matches the user against the identity rule. What happens to the connection?
Medium31Refer to the exhibit. Why are users on non-domain machines labeled as 'unknown'?
Hard32Which command is used to clear the user sessions in the Identity Awareness database on a Security Gateway?
Medium33An administrator wants to ensure that mobile devices are correctly identified. Which method is most appropriate for mobile device identity identification in a Wi-Fi environment?
Medium34An administrator configures Identity Awareness to use AD Query and creates an Access Control rule allowing the 'Sales' identity group to reach a CRM server. Users in Sales are identified, yet some still get blocked. Reviewing logs shows their sessions exist but the group membership is missing. Which configuration should the administrator verify first?
Hard35A security administrator is configuring Identity Awareness with Terminal Server Agent on a Citrix server. Users report that after logging off and logging back in, they are still associated with their previous session, causing policy inconsistencies. What is the most likely cause of this issue?
MediumOther domains
All 156-215.81.20 exam domains
Frequently asked questions
- What does the Identity Awareness domain cover on the 156-215.81.20 exam?
- Diagnose identity resolution with pdp and Identity Awareness CLI output, then read Access Control rule order correctly. The single most important thing: identity-based rules must sit above broader IP-based rules, or the wrong rule matches and policy never evaluates the user.
- How many questions are in this domain?
- This page lists all 35 Identity Awareness questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Identity Awareness questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.