156-215.81.20 · domain
User and Access Management
This domain covers how Check Point administrators define users, groups, and permission profiles, and how those identities authenticate to SmartConsole and other management tools. Questions test Permission Profile behavior, internal user password practices, Multi-Admin publish workflow, and the distinction between read-only and full administrative rights.
Focused practice
Practice User and Access Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about User and Access Management
Be able to assign Permission Profiles, create internal users with sound password practices, and manage Multi-Admin sessions. The critical point: know which actions require Publish versus which are view-only, and never assume Read-Only All permits changes.
The Read-Only All Permission Profile grants view access to all objects and rules without edit rights.
Permission Profiles in SmartConsole bundle allowed administrative actions assigned to administrator accounts.
Internal users authenticate to SmartConsole and are managed through SmartConsole user configuration.
In Multi-Admin environments, changes stay in the session until a Publish operation commits them.
Watch out for
Common User and Access Management exam traps
- ▸Assuming Read-Only All can modify rules or objects; it only permits viewing, so edits fail.
- ▸Confusing Permission Profiles with user groups; profiles define allowed actions, not identity membership.
- ▸Forgetting that unsaved Multi-Admin changes are session-local until Publish, causing lost or conflicting edits.
Question index
All User and Access Management questions (31)
Click any question to see the full explanation, or start a practice session above.
A Check Point administrator is configuring user authentication for a Remote Access VPN. The administrator wants to use certificates for authentication but also requires a second factor. The administrator decides to use SecurID tokens as the second factor. Which authentication method should be configured in the user object to achieve this?
Hard2When using LDAP as an external authentication provider for administrators, why must the 'Search Base' be configured correctly?
Hard3What is the purpose of the 'Auditor' role in Check Point management?
Medium4Refer to the exhibit. An administrator reports they can see all objects but cannot push policies. Reviewing the configuration, what is the most likely cause of this restriction?
Hard5A security administrator needs to allow a group of external consultants to access the corporate network via the Remote Access VPN. These consultants are not defined in the internal Active Directory. The administrator wants to minimize administrative overhead and ensure that the consultants can authenticate using their own existing credentials from their home company's LDAP server. Which Check Point object should be used to represent these external consultants?
Medium6An administrator is creating a new user account in the SmartConsole. The user needs to authenticate via a username and password that is stored in the Check Point user database. Which user type should the administrator select?
Easy7An administrator needs to restrict a junior admin's access to only managing security policies within a specific Management Server domain. Which feature should be configured to implement this granular control?
Medium8A security administrator is configuring a Check Point R81 Management Server to authenticate administrators via RADIUS. The RADIUS server is already configured with the necessary user accounts. After creating a RADIUS server object and enabling RADIUS authentication for administrators, the administrator tests login with a RADIUS user but fails. The administrator confirms the RADIUS server is reachable and the shared secret matches. What is the most likely cause of the failure?
Medium9Why is it recommended to use a separate administrative account for policy management versus day-to-day monitoring?
Medium10What is the primary function of the 'Read-Only All' Permission Profile in Check Point?
Medium11When configuring Check Point internal users for SmartConsole authentication, what is the best practice for password management?
Easy12A security administrator needs to allow a group of contractors to access the corporate network via Remote Access VPN. The contractors are already defined in an external LDAP directory. The administrator wants to avoid creating individual user accounts in SmartConsole and wants to apply a specific set of VPN settings to all contractors. Which object should the administrator use to represent the contractors in the VPN community configuration?
Hard13A security administrator at a company with 500 employees needs to grant SmartConsole access to a team of 10 auditors. The auditors must be able to view all security policies and logs but must not be able to modify any objects or rules. The administrator wants to avoid creating 10 separate administrator accounts. What is the most efficient way to achieve this?
Medium14A Check Point administrator is configuring user authentication for a remote access VPN community. The organization uses an external LDAP directory server for user credentials. The administrator wants to avoid creating local user accounts on the Security Management Server. Which Check Point object should be used to represent the external LDAP users for authentication?
Medium15Which action must be performed after updating a Permission Profile to ensure the changes take effect for active sessions?
Medium16An administrator is creating a new user account in SmartConsole. The administrator wants the user to be able to authenticate to the Check Point Mobile Access portal using a username and password stored locally on the Management Server. Which authentication method should be selected for this user?
Easy17A Check Point administrator needs to configure authentication for a group of external users who will access the network via a VPN. The users are stored in an Active Directory domain. The administrator wants to use the AD credentials for authentication and also wants to assign different permissions based on AD group membership. Which two actions must the administrator take to achieve this? (Choose two.)
Medium18A security administrator at a company using Check Point R81 Management Server needs to verify that a newly created administrator account named 'jsmith' has been assigned the correct permission profile before the account is used. The administrator opens SmartConsole and navigates to the Manage & Settings view. Which action should the administrator take to view the permission profile assigned to 'jsmith'?
Medium19A security administrator wants to configure the Check Point Management Server to authenticate administrators using an external LDAP directory. The LDAP server is already defined as an object in SmartConsole. Which of the following is the correct next step to enable LDAP authentication for administrators?
Medium20When configuring an administrator with 'Read/Write' access in a specific domain, what does 'Scope' define?
Hard21An administrator wants to audit all changes made to the security policy by other administrators. Which tool should they use?
Hard22An administrator attempts to add a new user to the Management Server and receives an error indicating the object name is already in use. What is the most likely cause?
Medium23What is the primary function of the 'Permissions Profile' in Check Point SmartConsole?
Easy24A Check Point administrator is configuring a new administrator account in SmartConsole. The administrator wants to grant this account permissions to manage only the Security Policies and objects within a specific Domain, while restricting access to other Domains in a Multi-Domain Management environment. The administrator plans to use a Permission Profile that is scoped to that Domain. Which two statements are true regarding this configuration? (Choose two.)
Hard25An administrator is configuring a new user group in SmartConsole. The group will be used in a rule to allow access to a specific server. The administrator wants to ensure that only users who are members of this group can access the server, and that membership is managed dynamically based on the user's department in the LDAP directory. Which type of user group should the administrator create?
Hard26Which object should an administrator use to define an external user group for authentication purposes?
Medium27Which administrative action requires a 'Publish' operation in a Multi-Admin environment?
Easy28A Check Point administrator is configuring a new SmartConsole administrator account for a security analyst. The analyst must be able to view all objects and rules but must not be able to modify any security policy or object. The administrator assigns the 'Read-Only All' Permission Profile. However, the analyst reports that they can still edit their own personal settings, such as changing their password. Is this expected behavior?
Hard29What is the purpose of the 'SmartConsole Check Point User Center' integration?
Medium30Refer to the exhibit. An administrator receives this message when trying to publish changes. How can the administrator resolve this conflict?
Hard31A security administrator is configuring user authentication for the corporate VPN. Employees must authenticate using their Active Directory credentials via LDAP, but the administrator wants to avoid storing user passwords in the Check Point database. Which Check Point object should be used to integrate the AD server for authentication?
MediumOther domains
All 156-215.81.20 exam domains
Frequently asked questions
- What does the User and Access Management domain cover on the 156-215.81.20 exam?
- Be able to assign Permission Profiles, create internal users with sound password practices, and manage Multi-Admin sessions. The critical point: know which actions require Publish versus which are view-only, and never assume Read-Only All permits changes.
- How many questions are in this domain?
- This page lists all 31 User and Access Management questions in the 156-215.81.20 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only User and Access Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.