156-215.81.20 Identity Awareness Practice Question
Exhibit
id_api -d User: bob IP: 10.0.0.5 Status: Active Source: AD_Query Timeout: 300s
Refer to the exhibit. An administrator is troubleshooting an issue where 'bob' is unable to access resources. Based on the CLI output, what is the most likely cause for the connectivity failure?
⚠ Common exam trap
Candidates often blame the Identity Awareness blade for the failure, failing to notice that the user was successfully identified, meaning the issue must be in the security policy rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The security policy is blocking the traffic.
The CLI output confirms that 'bob' is actively mapped to IP 10.0.0.5 via AD Query with a timeout remaining. Since the identity mapping is confirmed, the issue is not with the Identity Awareness blade itself but rather with the security policy rules. The gateway correctly identifies the user, so the administrator should focus on firewall policy rule matching and the specific network permissions defined for bob's group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AD Query source is failing to communicate.
Why it's wrong here
The output explicitly shows 'Source: AD_Query' and 'Status: Active'. This confirms that the identity information has been successfully received and processed by the gateway. If communication were failing, the status would be inactive or the entry would be missing entirely from the gateway's identity table.
- ✓
The security policy is blocking the traffic.
Why this is correct
Since the identity mapping is verified as active in the gateway's cache, the gateway correctly identifies the user. If the user still cannot access the resource, the traffic is likely being dropped or rejected by a specific rule in the Security Policy base, not due to identity acquisition.
- ✗
The user session has timed out.
Why it's wrong here
The output indicates 'Timeout: 300s', which represents the remaining time before the current entry expires. Since a valid timeout is listed and the status is active, the session is still valid and has not yet expired, so timeout is not the root cause of the connectivity issue.
- ✗
The Identity Awareness blade is disabled.
Why it's wrong here
If the Identity Awareness blade were disabled, the gateway would not be able to produce the identity mapping output shown in the exhibit. The presence of valid user-to-IP mapping entries proves the Identity Awareness blade is active and functioning correctly on the gateway to manage identity data.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.